Nginx
Checking and reloading config, logs, reverse proxy, HTTPS with Let's Encrypt.
Management
Test the config
sudo nginx -tApply config without downtime
sudo nginx -t && sudo systemctl reload nginxShow the full effective configadvanced
sudo nginx -TVersion and build options
nginx -VLogs
Follow the access log
sudo tail -f /var/log/nginx/access.logFollow the error log
sudo tail -f /var/log/nginx/error.logCount responses by status codeadvanced
awk '{print $9}' /var/log/nginx/access.log | sort | uniq -c | sort -rnMost requested URLsadvanced
awk '{print $7}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head -20Sites
Enable a site (Debian/Ubuntu layout)
sudo ln -s /etc/nginx/sites-available/<site> /etc/nginx/sites-enabled/
Reverse proxy to an appadvanced
server { listen 80; server_name <domain>; location / { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } }
WebSocket proxyingadvanced
location /ws/ {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}Redirect HTTP to HTTPSadvanced
server { listen 80; server_name <domain>; return 301 https://$host$request_uri; }
HTTPS (Let's Encrypt)
Get a certificate and configure nginx
sudo certbot --nginx -d <domain>
Test certificate renewal
sudo certbot renew --dry-runList certificates and expiry dates
sudo certbot certificates