The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

502 and 503: the proxy is telling the truth

Updated

Network switch with fiber cables plugged in

Bad gateway means the proxy is fine and upstream is not: check upstream health, then the proxy config, in that order.

A 502 page feels like the proxy broke. It is the opposite: the proxy works fine and is reporting that upstream failed it. Restarting the proxy for a 502 is like replacing the messenger for bad news.

Upstream first, config second

Ask upstream directly. Bypass the proxy and query the backend on its own address. Connection refused means the backend is down; a slow answer means it is sick; a good answer means the proxy path is the suspect.

Then read the proxy config. Upstream address, port, timeouts and health checks. Most 502s are a wrong port after a deploy, a timeout shorter than the backend needs, or a health check nobody wired.

Worked example: a fictional checkout proxy

The context below is fictional. Fictional proxy in front of BrightCart checkout (fictional) starts serving 502 on every payment call after a backend deploy. The proxy logs name the upstream address and the refused connection.

Direct query to the backend refuses too: the new version listens on a different port than the proxy config names. The fix is one port number in the proxy config, proven by backend-healthy then proxy-200. The prevention is a deploy checklist line: confirm the listening port before routing traffic.

Decision table: gateway errors

CodeMeaningFirst move
502Upstream bad or unreachableQuery upstream directly
503Something unavailableCheck who marked it down and why
504Upstream too slowCompare backend latency with proxy timeout

Straight answers

Frequently asked questions

502 or 503, which is worse?

Neither by itself. 502 says upstream answered badly or not at all; 503 says something is unavailable, often on purpose. The next step is the same: look upstream.

Should I restart the proxy first?

No. The proxy produced the error page, so it works. Restarting it destroys evidence and rarely helps.

What proves the fix?

Upstream healthy by its own check, then the same request through the proxy returning 200.

Bu sayfanın Türkçesi

Turn reading into a credential

This post is a free field note. Exams run at dated sittings in 15-seat classes; one price covers one attempt. All lessons are free.