Generate optimized, production-ready Nginx server block configurations for Next.js, Node.js, PHP-FPM (WordPress/Laravel), and static apps. Includes Let's Encrypt SSL/TLS, HTTP/2 & HTTP/3, security headers, rate limiting, and Gzip compression with zero server logging.
Choose a pre-configured architecture baseline or customize options manually.
# =============================================================================
# Nginx Server Configuration - Generated by HiMat Technology
# Domain: example.com
# Architecture: NEXTJS
# Generated: 2026-10-03
# =============================================================================
# Global Rate Limiting Zone
limit_req_zone $binary_remote_addr zone=example_com_req_limit:10m rate=10r/s;
# HTTP to HTTPS Redirect
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name example.com www.example.com;
# Security & Privacy Hardening
server_tokens off;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer-when-downgrade" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
# SSL / TLS Certificates
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
# Gzip Compression
gzip on;
gzip_vary on;
gzip_proxied any;
gzip_comp_level 6;
gzip_types text/plain text/css text/xml application/json application/javascript application/rss+xml application/atom+xml image/svg+xml;
# Rate Limiting Guardrail
limit_req zone=example_com_req_limit burst=20 nodelay;
# Reverse Proxy to Backend Application
location / {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 60s;
proxy_connect_timeout 60s;
}
# Static Asset Caching
location ~* \.(?:css|js|png|jpg|jpeg|gif|ico|svg|webp|avif|woff2?)$ {
expires 30d;
add_header Cache-Control "public, no-transform";
access_log off;
}
# Block Sensitive Hidden Files
location ~ /\. {
deny all;
access_log off;
log_not_found off;
}
}
Select an architecture preset (Next.js Reverse Proxy, PHP-FPM, or Static), enter your domain name, and configure upstream backend ports.
Toggle Certbot SSL paths, HSTS preloading, Content Security Policy, X-Frame-Options, server_tokens off, and rate limiting parameters.
Download the generated file to `/etc/nginx/sites-available/`, create a symlink, test with `sudo nginx -t`, and reload with `sudo systemctl reload nginx`.
Zero network transmission. Your domain names, backend ports, SSL file paths, and custom server rules are generated 100% in local browser memory.
One-click templates for Next.js / Node.js Reverse Proxy, Static Websites, PHP-FPM (WordPress/Laravel), High-Security Hardened, and SPAs.
Integrates Certbot Let's Encrypt paths, TLS 1.2 / TLS 1.3 protocol limits, Mozilla Intermediate cipher suites, and HSTS preloading.
Embeds Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, server_tokens off, and limit_req rate limiting.
Configures Gzip and Brotli compression alongside long-term static asset caching headers (Cache-Control max-age=31536000) and keepalive timeouts.
Copy formatted Nginx server block code or download ready-to-deploy `.conf` files directly to your server machine with one click.
Unlike remote configuration tools that harvest server domains, internal IP addresses, and backend port maps, HiMat's Nginx Config Generator operates strictly in local browser memory. Zero network calls, zero log storage, and 100% data privacy.
An Nginx Config Generator simplifies creating web server directives by generating syntactically correct, optimized, and secure server block configuration files for hosting websites, reverse proxying Node.js/Next.js apps, or serving PHP applications.
No. The HiMat Nginx Config Generator operates 100% locally in your web browser. Neither your domain names, internal IP addresses, ports, nor security settings leave your device.
Download the `.conf` file (or copy the text) and save it to `/etc/nginx/sites-available/yourdomain.conf`. Create a symlink to `/etc/nginx/sites-enabled/`, test syntax with `sudo nginx -t`, and reload Nginx with `sudo systemctl reload nginx`.
Yes! You can toggle Let's Encrypt SSL paths to automatically generate `ssl_certificate` and `ssl_certificate_key` blocks compatible with Certbot.
Yes, 100% free with no registration required, no usage caps, and zero advertisements.
HiMat Technology designs high-availability cloud infrastructure, automated CI/CD pipelines, Nginx/HAProxy load balancing, and zero-downtime deployment workflows for scaling tech enterprises.
Continue with related utilities, services, and guides from HiMat.