Something I've wanted to do is run less trusted services on a private network but still have the reverse proxy connect to them. This way I can be sure that they only way to get to them from the outside is via the reverse proxy (which adds authentication). However I haven't found a decent way to manage that no network access paired with a loopback or similar that can be accessed by the reverse proxy.