Nginx Reverse Proxy Config
Nginx in front of an app on a local port, passing the real host and client address. Enter your domain below for a ready server block.
- Free
- No Sign-Up
- Runs in Your Browser
Site Type
Server Block
# /etc/nginx/sites-available/example.com, generated at frabs.net/tools/nginx-config-generator/
server {
listen 80;
listen [::]:80;
server_name example.com;
return 301 https://example.com$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
http2 on;
server_name example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
# add_header Strict-Transport-Security "max-age=31536000" always; # once HTTPS works everywhere
client_max_body_size 10M;
gzip on;
gzip_types text/css application/javascript application/json image/svg+xml;
add_header X-Content-Type-Options nosniff always;
add_header Referrer-Policy strict-origin-when-cross-origin always;
add_header X-Frame-Options SAMEORIGIN always;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
Install It
sudo certbot certonly --nginx -d example.com # get the certificate first sudo nano /etc/nginx/sites-available/example.com # paste the config sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/ sudo nginx -t && sudo systemctl reload nginx
Nginx Config Generator
Configuration
TypeReverse Proxy
Upstreamhttp://127.0.0.1:3000
HTTPSLet's Encrypt with an HTTP redirect
Test Before Reloadnginx -t
Nginx in front of an app on a local port, passing the real host and client address.
Always run nginx -t before reloading: a bad file then leaves the old configuration serving instead of taking every site down.
Configurations
Questions
How do I set up an Nginx reverse proxy?
Save the generated server block in /etc/nginx/sites-available/, link it into sites-enabled, run nginx -t and reload.
Free Tools
More tools
Nginx Config GeneratorServer blocks for reverse proxies, static sites and PHP, with HTTPS.Docker Compose GeneratorStarter compose.yaml files for common stacks, with safe defaults.SSL Certificate CheckerExpiry, issuer, chain, names and TLS version for any HTTPS site.Firewall Rule GeneratorGenerate iptables, nftables and UFW rules for common server set-ups.
Run VMs for other people?
Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.