All tools

nginx Config Generator

Build nginx server blocks

Generate nginx configs for static sites, SPAs, reverse proxies and redirects, with HTTPS, gzip, caching and security headers.

How to use nginx Config Generator

  1. Choose a preset: Static site, SPA (unknown paths fall back to index.html), Reverse proxy, PHP-FPM, or Redirect.
  2. Fill in the server_name, the document root or upstreams, and switch the options you want: HTTPS with HTTP/2 or HTTP/3, HSTS, gzip, asset caching, security headers, rate limiting, WebSocket headers and logs.
  3. Read any warnings under the output, then copy the config or download it as nginx.conf.
  4. Put it in /etc/nginx/conf.d/ (or sites-available), run nginx -t to check it, then nginx -s reload.

How it works

The config is built as plain text from your options by a small function in the page, so it updates as you type. Each preset has its own location blocks: static sites use try_files $uri $uri/ =404, SPAs fall back to /index.html, PHP passes .php to fastcgi_pass, and the reverse proxy writes an upstream block (round robin, least_conn or ip_hash) and the usual Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto headers. With HTTPS on, a separate port-80 server keeps the ACME challenge path open and redirects everything else with a 301. TLS is limited to TLSv1.2 and TLSv1.3. Values you type are checked before they are written, so a quote, semicolon or brace cannot end a directive or open a new block.

Limits

  • The config is generated, not tested: nginx is never run here. Always check it with nginx -t on your server.
  • Output is one server block (plus an optional upstream, map and limit_req_zone in the http context), meant for conf.d, not a complete nginx.conf with events and http.
  • Brotli needs the ngx_brotli module, so only a comment is written. HTTP/3 needs nginx 1.25 or newer built with QUIC, and UDP port 443 open.
  • http2 on; needs nginx 1.25.1 or newer; on older versions put http2 after ssl on the listen line.
  • Values containing spaces or characters nginx treats as syntax (quotes, ;, {, }, $) are refused with a warning. A Content-Security-Policy is not generated; use the CSP Builder.

Privacy

Everything is generated in your browser. Nothing you type is uploaded or stored. Share copies a link that holds your options in the URL’s # fragment, which browsers don’t send to servers.

Frequently asked questions

Why is there a second server block on port 80?

With HTTPS on, port 80 only serves the Let’s Encrypt challenge path and sends everything else to HTTPS with a 301 redirect.

Why are security headers missing inside my asset location?

In nginx, add_header in a location replaces the ones inherited from the server block. Repeat the headers there if you need them on cached assets.

Should I turn HSTS on?

Only once HTTPS works for the whole site. Browsers remember HSTS for a year (the generated max-age), so a broken certificate cannot be bypassed.

How do WebSocket headers work?

The proxy sends Upgrade and a Connection value from a map block, so normal requests keep their connection handling and WebSocket requests are upgraded. The read timeout is raised to one hour.

More tools