Nginx Config Generator

Pick the kind of site and get a commented nginx config — HTTP to HTTPS and www redirects, SSL, reverse proxy with WebSockets, PHP-FPM, SPA fallback, gzip, caching and security headers.

Loading tool…

About the Nginx Config Generator

The generator writes complete server blocks: one on port 80 that answers Let's Encrypt challenges and redirects everything else to HTTPS, one that sends the non-canonical host (www or non-www) to the canonical one, and the main HTTPS site. Each visitor gets a single 301 hop. Certificate paths default to the layout certbot creates in /etc/letsencrypt/live/<domain>.

In reverse proxy mode requests are forwarded with Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto, so the app can see the real client and scheme. WebSocket support adds a map on $http_upgrade that must live in the http context — keeping it in the same file under sites-enabled does exactly that. PHP mode passes .php files to PHP-FPM with $realpath_root, which works with symlinked deploy directories.

nginx only inherits add_header lines into a location that has none of its own, so the security headers are repeated inside the caching and SPA locations. Long cache lifetimes are only safe with versioned asset names; the SPA's index.html is always served with Cache-Control: no-cache. Enable HSTS only after HTTPS works on every subdomain.

How to use it

  1. Choose the site type: static files, single-page app, reverse proxy or PHP-FPM.
  2. Enter the domain, www behaviour and the document root, upstream or PHP-FPM socket.
  3. Tick HTTPS, compression, caching, security headers and access rules; add any 301 redirects.
  4. Download the file to /etc/nginx/sites-available/ and link it into sites-enabled.
  5. Run sudo nginx -t, then sudo systemctl reload nginx.

Frequently asked questions

How do I get the SSL certificate?
Start with HTTPS unticked, reload nginx, then run certbot certonly --webroot -w /var/www/letsencrypt -d example.com -d www.example.com. Once the files exist, tick HTTPS and reload again.
Why do I get 502 Bad Gateway?
nginx cannot reach the upstream. Check the app is running and listening on the address in proxy_pass, or that the PHP-FPM socket path matches your PHP version.
Why are my add_header lines missing on some responses?
A location with its own add_header replaces all inherited ones. Repeat the headers in that location, as this generator does for cached assets.
Why does my SPA return 404 on refresh?
nginx looks for a file matching the URL. try_files $uri $uri/ /index.html sends unknown paths to the app so its router can handle them.

Related tools