Manage accounts via cloud phones and web profiles. Automate posts and engage with your audience in one dashboard with Multilogin. See Details

Nginx Config Generator: nginx.conf for PHP, Proxy and SSL

5 of 1 ratings

This tool is based on the open source project nginxconfig.io by DigitalOcean, published under the MIT license (license text). The ads and the menu of the original site are removed. The config is made in your browser, nothing is sent to a server.

Nginx Config Generator: Set Up nginx.conf Online

Choose what your site needs, and the generator writes the configuration files of NGINX: the server blocks for your domains, HTTPS with the recommended TLS profile, a reverse proxy, PHP-FPM, Node.js or Python, caching, compression and security headers. You get the files as an archive or as one command to paste into the terminal of your server. Everything is calculated in your browser, so your domain names and paths are not sent anywhere.

How to use the generator

  1. Pick a preset for the kind of site (PHP, WordPress, Node.js, Django, a single page application, Drupal, Magento, Joomla or a plain frontend) and enter the domain and the path to the site on the server.
  2. Open the tabs of the site: HTTPS, PHP, Python, Reverse proxy, Routing, Logging and Restrict. The number in brackets after the domain shows how many settings you changed.
  3. Set the global options for all sites: the SSL profile, security headers, performance (gzip, caching), logging and the NGINX main settings. A Docker tab gives the files for a container.
  4. In the Setup section download the archive or copy the Base64 command, then follow the steps under it.
  5. Check the result with nginx -t and reload NGINX (see below).

Where the NGINX config files are

  • Debian and Ubuntu: the main file is /etc/nginx/nginx.conf. The sites live in /etc/nginx/sites-available/ and are switched on by a link in /etc/nginx/sites-enabled/; extra files are in /etc/nginx/conf.d/.
  • CentOS, RHEL and the packages of nginx.org: /etc/nginx/nginx.conf and the files /etc/nginx/conf.d/*.conf (there is no sites-available folder).
  • Docker: the official image reads /etc/nginx/conf.d/default.conf; mount your own file or folder as a volume.
  • Windows: the conf folder next to nginx.exe, the main file is conf\nginx.conf.
  • To see the whole configuration that NGINX really uses, with all the included files, run sudo nginx -T.

How to check the config and reload NGINX

Never reload NGINX before the test. Run sudo nginx -t: the answer syntax is ok and test is successful means the files are correct. An error such as unknown directive or unexpected "}" names the file and the line, so you can find the mistake at once. Then apply the new config without breaking the open connections: sudo systemctl reload nginx or sudo nginx -s reload. On Windows run nginx -s reload in the folder of NGINX. A restart is needed only when the reload does not help.

PHP with NGINX (php-fpm)

NGINX does not run PHP itself, it passes the request to PHP-FPM with fastcgi_pass: to a socket such as /run/php/php8.3-fpm.sock or to 127.0.0.1:9000. The name of the socket depends on the PHP version, look in the folder /run/php/. The preset PHP sets this up together with try_files, so that the requests of a CMS go to index.php.

Reverse proxy, WebSockets and SSE

A reverse proxy takes the requests on ports 80 and 443 and passes them to an application with proxy_pass, for example http://127.0.0.1:3000. The generator adds the headers Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto, so that the application knows the real address and the protocol of the visitor. For WebSockets NGINX needs proxy_http_version 1.1 and the headers Upgrade and Connection. For server-sent events (SSE) turn the buffering off with proxy_buffering off. NGINX Proxy Manager is another product: a Docker application with its own web interface. This tool writes an ordinary config that you keep in files.

HTTPS and certificates

A free certificate is issued by Let's Encrypt, for example with certbot; the files fullchain.pem and privkey.pem are in /etc/letsencrypt/live/your-domain/. The generator writes the paths, the redirect from http to https and the TLS settings of the Mozilla profile: Modern, Intermediate (the default) or Old for old clients. Turn on HSTS only after you make sure that https works on all subdomains: browsers then refuse to open the site over http.

How NGINX chooses a location

The exact match location = /path wins first. Then the longest prefix is found, and if it has the modifier ^~ the search stops. Otherwise the regular expressions (~ and ~*) are checked in the order of the file, and the first match is used. If no regular expression fits, the longest prefix is used.

NGINX together with Apache, and fail2ban

A common scheme: NGINX listens on 80 and 443, serves the static files and passes the dynamic requests to Apache on another port, for example 127.0.0.1:8080. To block the bots that try the passwords and scan the site, fail2ban has ready filters for NGINX: nginx-http-auth, nginx-botsearch and nginx-limit-req. Switch them on in jail.local and check that the log paths there match the ones in the generated config.

Limits of a generated config

The result is a good starting point, not a guarantee for every server. Check it with nginx -t, keep a backup of the old files (the instructions of the generator show the command), and for applications such as 1C-Bitrix, Nextcloud or Zabbix compare it with the config from their documentation. The directives available depend on the version of NGINX and on the modules of your build.

Related tools

To measure how fast the server answers use the TTFB checker, to see the status codes and the redirects after you set up https the HTTP status code checker, to check the DNS records and the certificate of a domain the DNS lookup.

Similar tools

TTFB Checker: Test Time to First Byte Online

Free TTFB checker: measure the time to first byte of any website with DNS, connect, TLS and server wait times, from 1 to 5 runs and a median result.

294
HTTP Status Code & Redirect Checker

Check the HTTP status code and response headers of any URL and follow the whole redirect chain (301, 302, 307, 308) step by step, with server IP and timings.

43
DNS Lookup: Check DNS Records and the SSL Certificate

Free DNS lookup online: check A, AAAA, CNAME, MX, NS, TXT, SOA and CAA records of any domain, plus its SSL certificate. Find out why a DNS lookup fails.

350
Website Hosting Checker: Who Hosts a Site, IP and Hoster

Check who hosts a website: the IP address, the hosting company (ASN), the country and the city of the server. Free hosting checker for any domain.

440

Popular tools