Web Servers (Apache, Nginx, Caddy)

Load Balancing, Web Servers, and Database Configuration

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (5 sections)

A high-traffic website usually outgrows one server in the same way: a load balancer in front, two or more identical web servers behind it, and a separate database server. This page gives you the short version of that architecture and sends you to the full, current guides for each part. Everything here runs on servers you control, such as your own VPSes, not on shared hosting.

For the full guide, see the multi-server cluster article

The complete, step-by-step walkthrough, with firewall rules, private networking, HAProxy, stateless app servers, MySQL and PostgreSQL replication and failover, is in setting up a multi-server VPS cluster. This page is a summary.

Key takeaways

Put a load balancer such as HAProxy on its own server, run two or more identical web servers behind it with health checks, and move the database to a separate server with a replica. Connect the servers over an encrypted private network, keep sessions and uploads off the web servers, and use Let's Encrypt for HTTPS. On Domain India, each role is a self-managed KVM VPS with root access; shared hosting cannot run this setup.

1. The architecture in one picture

Load balancer
One server running HAProxy (or nginx). It holds the public IP and the HTTPS certificate and sends each request to a healthy web server.
Web servers
Two or more identical servers running nginx or Apache and your application, reachable only from the load balancer.
Database
A primary server that takes writes and a replica that stays in sync, reachable only from the web servers.

Point your domain's A record at the load balancer's IP address. Visitors never talk to the web or database servers directly.

2. The steps, and where each one is covered

  1. Decide whether you need it.
    A cluster adds cost and work. A bigger single server, page caching or faster queries often solves the problem first; see tuning Apache and nginx for high-traffic websites.
  2. Prepare every server.
    Use a current Linux release, such as an Ubuntu LTS, Debian, AlmaLinux or Rocky Linux. Log in with SSH keys, apply updates and enable a firewall on each node.
  3. Connect them privately.
    Run WireGuard between the servers so database and internal traffic never crosses the internet in the clear.
  4. Set up the load balancer.
    Install HAProxy from your distribution's packages, add a health check to each backend and terminate HTTPS there. See mastering load balancing with HAProxy.
  5. Make the web servers stateless.
    Store sessions in Redis or the database and uploads in shared or object storage, so any server can answer any request.
  6. Separate and replicate the database.
    Use MySQL 8.4 source–replica replication with GTIDs, or PostgreSQL streaming replication. A replica is not a backup; keep scheduled backups off the cluster.
  7. Add monitoring and test failover.
    Watch every node and stop one on purpose in a quiet hour to prove the setup survives it.

3. HTTPS with Let's Encrypt

Older tutorials add a Certbot PPA and install python-certbot-nginx. That PPA is retired. Today, install Certbot from your distribution (sudo apt install certbot python3-certbot-nginx on Ubuntu or Debian) or with snap, as the Certbot site recommends, and run sudo certbot --nginx.

When HAProxy terminates HTTPS, the certificate lives on the load balancer, not on the web servers. HAProxy expects the certificate and private key combined in one .pem file, so add a renewal hook that rebuilds that file and reloads HAProxy after each renewal.

4. What about the mail server?

The original version of this guide added a Postfix and Dovecot server to the cluster. Running your own mail server is a separate job with its own risks: deliverability, spam filtering and blocklists. If you want to do it, follow setting up a complete mail server on a VPS, and ask support first whether outgoing port 25 and reverse DNS are available for your VPS. Most businesses are better served by a hosted mailbox such as Domain India Business Email, so the cluster only has to serve the website.

5. Running this on Domain India

Every Domain India VPS is a KVM server with full root access, so you can run HAProxy, nginx, WireGuard, MySQL or PostgreSQL. VPS hosting is self-managed: you install, secure, update and back up the servers yourself. Ask support whether private networking or a movable IP between your VPSes is available before you design around them; WireGuard over the public IPs works either way.

A small cluster might use a smaller plan for the load balancer and larger ones for the web and database servers:

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
VPS Standard
₹2,210.60/mo + GST
  • 4 vCPU
  • 8 GB DDR4 RAM
  • 256 GB NVMe SSD Storage
  • 5 TB Monthly Bandwidth
See plan details

Prices on the cards are Domain India list prices and exclude 18% GST.

How many servers do I need for a load-balanced website?

A common starting point is four: one load balancer, two web servers and one database server, plus a database replica for failover. The load balancer stays a single point of failure until you add a second one.

Can I set up load balancing on shared hosting?

No. Shared hosting is a single managed environment and you cannot change its server configuration. A load-balanced setup needs servers you control, such as several VPSes with root access.

Should I use HAProxy or nginx as the load balancer?

Both work. HAProxy actively health-checks each backend and removes a failed server within seconds. nginx is convenient if you already use it, but its open-source version notices a failed server only when real requests to it fail.

Where should the SSL certificate go in a load-balanced setup?

Usually on the load balancer, which terminates HTTPS and talks to the web servers over a private network. HAProxy needs the certificate and key combined in one file, rebuilt after each renewal.

Is a Domain India VPS managed?

A Domain India VPS is self-managed by default. You get root access and are responsible for the operating system, updates, firewall and software. Support covers provisioning, access and the network and hardware it runs on.

Ready to plan it? Read the multi-server cluster guide, compare VPS plans for each role, or open a support ticket to ask about networking before you build.

Build your cluster on KVM VPS

Full root access on every node, so you choose the load balancer, web server and database design.

See VPS plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app