Hey everyone,
I'm trying to figure out the right production setup for my app:
- Next.js + SSR on Vercel
- NestJS API on Railway
- S3 for storage
- Domain registered on Spaceship, DNS currently managed by Vercel
- Frontend calls
/api/*, which is rewritten bynext.config.jsto Railway
Basically:
Browser → Vercel → Railway/NestJS → DB/S3
The main thing I'm concerned about is DDoS protection and rate limiting.
I already have rate limiting in NestJS, but I don't want to rely on X-Forwarded-For because someone can bypass Vercel and hit the Railway URL directly, spoofing the header and bypassing IP-based rate limits.
I'm considering either:
1. HMAC between Vercel and Railway
Have a Next.js proxy sign requests with a shared secret, then have NestJS verify them. This would prevent direct requests to Railway, but I'm not sure if this is a good production pattern. That would require using nextjs middleware (im on nextjs 14).
I'm also concerned about large file uploads since some files need to go through NestJS for processing/compression before being uploaded to S3.
2. Cloudflare in front of Railway
Something like:
example.com → Vercel api.example.com → Cloudflare → Railway
Cloudflare would handle DDoS/WAF/rate limiting, while NestJS handles auth, authorization and application-level limits. I'd potentially use Authenticated Origin Pulls to prevent bypassing Cloudflare and hitting Railway directly.
So what would you consider the normal production approach here?
Is Cloudflare worth adding for this, or am I overcomplicating things? Currently we only pay 5$ a month for hosting so i wouldn't pay 20$ for the cloudflare tier unless necessary. And would you use a separate api.example.com domain or keep the /api/* Vercel rewrite?
Also interested in how others handle large uploads that need to be processed by the backend before going to S3.
Source: r/nextjs · by /u/thrwy69696