CmdKeys LogoCommand Quiz

Nginx Command Practice

nginx is the web server and reverse proxy you configure by writing directives into server blocks. This track drills what you actually type and look up: the CLI (nginx -t, nginx -s reload), server block directives (listen, server_name, root), location matching operators (=, ^~, ~*), proxy_pass headers, security hardening (server_tokens off, deny all), and performance tuning (gzip, expires, keepalive_timeout) — not the full multi-line block, just the one directive that matters.

Command Reference

server

CommandDescription
root /var/www/example/public;Set the document root directory for request path resolution.
listen 80;Configure the server block to listen for plain HTTP traffic on port 80.
server_name example.com www.example.com;Set virtual host domain names for a server block.
index index.html index.htm;Specify the order of default index files to check when directory requests are made.
return 301 https://$host$request_uri;Return an HTTP 301 permanent redirect to HTTPS for all incoming requests.
try_files $uri $uri/ =404;Check for existence of file then directory, falling back to an HTTP 404 error if neither exists.
try_files $uri /index.html;Check for existence of requested file, falling back to index.html for Single Page Applications (SPA).
listen 443 ssl http2;Configure the server block to listen for HTTPS traffic on port 443 with SSL and HTTP/2 enabled.

cli

CommandDescription
sudo nginx -s reloadSend a graceful reload signal to the master nginx process to reload configuration without dropping connections.
sudo systemctl status nginxCheck the runtime status and recent log output of the nginx systemd service.
sudo systemctl reload nginxReload the nginx systemd service configuration gracefully via systemd.
sudo systemctl restart nginxStop and start the nginx systemd service.
sudo nginx -tTest the nginx configuration files for syntax errors and check if referenced files exist.
sudo nginx -s stopSend a fast shutdown signal to the master nginx process to stop immediately.
nginx -VDisplay nginx version, compiler version, and configure script parameters including compiled-in modules.

location

CommandDescription
location /Define a default fallback prefix location block matching all URIs.
return 204;Return an HTTP 204 No Content status directly without serving a body.
location = /healthzDefine an exact match location block that matches only the specific URI path.
location ~* \.(png|jpg|css|js)$Define a case-insensitive regular expression location block for matching static asset extensions.
rewrite ^/old/(.*)$ /new/$1 permanent;Perform an HTTP 301 permanent redirect using regex pattern rewrite.
location ~ /\. { deny all; }Deny access to all hidden files and directories starting with a dot.
location ^~ /static/Define a preferential prefix match location block that skips regex location matching if matched.

proxy

CommandDescription
proxy_pass http://127.0.0.1:3000;Forward incoming requests to a proxy backend application server.
proxy_set_header Host $host;Set the Host header sent to the proxied server to match the request Host header.
proxy_set_header X-Real-IP $remote_addr;Pass the true client IP address to the proxied server via X-Real-IP header.
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;Append the client IP address to the X-Forwarded-For request header chain.
proxy_set_header X-Forwarded-Proto $scheme;Pass the original protocol (http or https) to the proxied backend server.
proxy_connect_timeout 5s;Set a timeout for establishing a connection with a proxied server.
proxy_read_timeout 60s;Set a timeout for reading a response from the proxied server.

security

CommandDescription
server_tokens off;Disable emitting nginx version information in error pages and Server response header.
deny all;Deny access to all IP addresses not explicitly allowed.
add_header X-Frame-Options "SAMEORIGIN" always;Add HTTP header to prevent clickjacking by allowing framing only from the same origin.
add_header X-Content-Type-Options "nosniff" always;Add HTTP header to prevent MIME-type sniffing by browsers.
allow 192.168.0.0/16;Allow access to the specified IP address range or subnet.
client_max_body_size 25m;Set maximum allowed size of the client request body.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;Enforce HTTP Strict Transport Security (HSTS) for one year including subdomains.
limit_req_zone $binary_remote_addr zone=reqs:10m rate=10r/s;Configure a shared memory zone for rate limiting requests by IP address.

performance

CommandDescription
gzip on;Enable gzip compression for responses.
gzip_comp_level 5;Set gzip compression level from 1 (fastest) to 9 (highest compression).
keepalive_timeout 65s;Set timeout during which a keep-alive client connection will stay open on the server.
expires 7d;Set the Expires and Cache-Control headers for static file responses.
add_header Cache-Control "public, max-age=604800, immutable";Add Cache-Control header for static asset caching.
worker_processes auto;Set the number of worker processes automatically based on available CPU cores.
gzip_types text/plain text/css application/javascript application/json;Specify MIME types to compress with gzip in addition to text/html.
proxy_cache micro;Specify shared memory zone name to use for caching responses from proxied servers.
proxy_cache_valid 200 301 302 10s;Set caching time for specific HTTP status codes.

Key Use Cases

  • Test a modified nginx.conf before reloading with nginx -t
  • Redirect all HTTP traffic to HTTPS with a return 301 in a server block
  • Forward requests to a backend app with proxy_pass and set the correct headers
  • Match exact paths with = and prefix paths with ^~ before regex locations
  • Harden a server by disabling the version header and adding security headers
  • Enable gzip compression with correct MIME types and minimum size threshold

Frequently Asked Questions

What is the difference between root and alias in a location block?

root appends the location path to the document root. alias replaces the location path entirely with the specified directory. Example: root /var/www with location /images/ serves /var/www/images/file.jpg; alias /var/www/assets/ serves /var/www/assets/file.jpg.

What is the nginx location match priority order?

Exact match (=) first, then prefix modifier (^~) which stops regex matching, then regex (~, ~*) in file order, then the longest prefix match. A ^~ match prevents any regex from being tested.

Why is proxy_set_header Host $host needed behind a proxy?

Without it, nginx forwards its own host to the backend, not the client's Host header. The backend would not know which virtual host or domain the client requested, breaking name-based virtual hosting and redirects.

What is the difference between nginx -s reload and systemctl reload nginx?

nginx -s reload sends the HUP signal directly to the master nginx process. systemctl reload nginx uses systemd to send the same signal via the service unit. Both achieve a graceful config reload without dropping connections; prefer systemctl on systemd hosts.

Ready to master Nginx commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →