Nginx Static Site Config

Serving files from a folder, with long caching for assets. Enter your domain below for a ready server block.

  • Free
  • No Sign-Up
  • Runs in Your Browser
Site Type

Server Block

# /etc/nginx/sites-available/example.com, generated at frabs.net/tools/nginx-config-generator/
server {
    listen 80;
    listen [::]:80;
    server_name example.com;
    return 301 https://example.com$request_uri;
}

server {
    listen 443 ssl;
    listen [::]:443 ssl;
    http2 on;
    server_name example.com;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
    # add_header Strict-Transport-Security "max-age=31536000" always;  # once HTTPS works everywhere

    client_max_body_size 10M;
    gzip on;
    gzip_types text/css application/javascript application/json image/svg+xml;
    add_header X-Content-Type-Options nosniff always;
    add_header Referrer-Policy strict-origin-when-cross-origin always;
    add_header X-Frame-Options SAMEORIGIN always;

    root /var/www/example.com;
    index index.html;

    location / {
        try_files $uri $uri/ =404;
    }
    location ~* \.(css|js|png|jpg|jpeg|gif|svg|webp|woff2?)$ {
        expires 30d;
        access_log off;
    }
}

Install It

sudo certbot certonly --nginx -d example.com   # get the certificate first
sudo nano /etc/nginx/sites-available/example.com   # paste the config
sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx

Nginx Config Generator

Configuration

TypeStatic Site
HTTPSLet's Encrypt with an HTTP redirect
Test Before Reloadnginx -t

Serving files from a folder, with long caching for assets.

Always run nginx -t before reloading: a bad file then leaves the old configuration serving instead of taking every site down.

Questions

How do I set up an Nginx static site?
Save the generated server block in /etc/nginx/sites-available/, link it into sites-enabled, run nginx -t and reload.

Run VMs for other people?

Frabs stops spam, scans and floods leaving your customers' VMs, before the abuse report lands.