About the Nginx Config Generator
The generator writes complete server blocks: one on port 80 that answers Let's Encrypt challenges and redirects everything else to HTTPS, one that sends the non-canonical host (www or non-www) to the canonical one, and the main HTTPS site. Each visitor gets a single 301 hop. Certificate paths default to the layout certbot creates in /etc/letsencrypt/live/<domain>.
In reverse proxy mode requests are forwarded with Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto, so the app can see the real client and scheme. WebSocket support adds a map on $http_upgrade that must live in the http context — keeping it in the same file under sites-enabled does exactly that. PHP mode passes .php files to PHP-FPM with $realpath_root, which works with symlinked deploy directories.
nginx only inherits add_header lines into a location that has none of its own, so the security headers are repeated inside the caching and SPA locations. Long cache lifetimes are only safe with versioned asset names; the SPA's index.html is always served with Cache-Control: no-cache. Enable HSTS only after HTTPS works on every subdomain.
How to use it
- Choose the site type: static files, single-page app, reverse proxy or PHP-FPM.
- Enter the domain, www behaviour and the document root, upstream or PHP-FPM socket.
- Tick HTTPS, compression, caching, security headers and access rules; add any 301 redirects.
- Download the file to /etc/nginx/sites-available/ and link it into sites-enabled.
- Run sudo nginx -t, then sudo systemctl reload nginx.