What does this mean?
A gateway or proxy could not obtain a usable response from an upstream server. Your browser may be reaching the CDN successfully while the origin application is failing. A 502 page does not, by itself, establish whether the fault belongs to the CDN, host or application.
What should I check first?
Record the time, affected URL and any request or trace identifier shown on the page. Check the host and CDN status pages, then compare a static asset with an application page. If only dynamic pages fail, that helps distinguish application workers from general network access.
How can I diagnose the cause?
Look for upstream connection failures, worker crashes or invalid responses in the proxy and application logs. Compare the onset with a deployment, PHP change, DNS change or firewall change. If the origin hostname recently moved, confirm its public A and AAAA records point to the intended service.
How do I fix it safely?
Restore the identified failed service or roll back the change associated with the error using the host’s documented controls. Verify that the origin accepts the expected proxy connections and that its TLS configuration matches the upstream hostname. Do not disable certificate validation or expose a private origin simply to hide the symptom.
Verify the fix and know when to contact your provider
Save current proxy and firewall settings before editing. After recovery, test a normal page and a critical form once without repeatedly submitting transactions. Contact the host or CDN when you cannot inspect upstream logs; provide the trace identifier, timestamps, affected paths and which static or dynamic requests succeeded.
Work through these checks in order
- Check one existing image URL and one normal application page. Record whether both fail. Keep any CDN request ID so the provider can connect your test to its proxy logs.
- In the hosting panel, compare the error time with application-worker or PHP failures. Ask for upstream connection logs if the panel exposes only access logs; those are different evidence sources.
- After restoring the identified service, repeat the same two URLs. If only the proxy path still fails, ask the CDN or host to check its origin hostname, port and TLS arrangement.
Which tool can help?
DNS lookup · Uptime & downtime calculator
DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.