Nginx Command Practice
nginx is the web server and reverse proxy you configure by writing directives into server blocks. This track drills what you actually type and look up: the CLI (nginx -t, nginx -s reload), server block directives (listen, server_name, root), location matching operators (=, ^~, ~*), proxy_pass headers, security hardening (server_tokens off, deny all), and performance tuning (gzip, expires, keepalive_timeout) — not the full multi-line block, just the one directive that matters.
Command Reference
server
| Command | Description |
|---|---|
root /var/www/example/public; | Set the document root directory for request path resolution. |
listen 80; | Configure the server block to listen for plain HTTP traffic on port 80. |
server_name example.com www.example.com; | Set virtual host domain names for a server block. |
index index.html index.htm; | Specify the order of default index files to check when directory requests are made. |
return 301 https://$host$request_uri; | Return an HTTP 301 permanent redirect to HTTPS for all incoming requests. |
try_files $uri $uri/ =404; | Check for existence of file then directory, falling back to an HTTP 404 error if neither exists. |
try_files $uri /index.html; | Check for existence of requested file, falling back to index.html for Single Page Applications (SPA). |
listen 443 ssl http2; | Configure the server block to listen for HTTPS traffic on port 443 with SSL and HTTP/2 enabled. |
cli
| Command | Description |
|---|---|
sudo nginx -s reload | Send a graceful reload signal to the master nginx process to reload configuration without dropping connections. |
sudo systemctl status nginx | Check the runtime status and recent log output of the nginx systemd service. |
sudo systemctl reload nginx | Reload the nginx systemd service configuration gracefully via systemd. |
sudo systemctl restart nginx | Stop and start the nginx systemd service. |
sudo nginx -t | Test the nginx configuration files for syntax errors and check if referenced files exist. |
sudo nginx -s stop | Send a fast shutdown signal to the master nginx process to stop immediately. |
nginx -V | Display nginx version, compiler version, and configure script parameters including compiled-in modules. |
location
| Command | Description |
|---|---|
location / | Define a default fallback prefix location block matching all URIs. |
return 204; | Return an HTTP 204 No Content status directly without serving a body. |
location = /healthz | Define an exact match location block that matches only the specific URI path. |
location ~* \.(png|jpg|css|js)$ | Define a case-insensitive regular expression location block for matching static asset extensions. |
rewrite ^/old/(.*)$ /new/$1 permanent; | Perform an HTTP 301 permanent redirect using regex pattern rewrite. |
location ~ /\. { deny all; } | Deny access to all hidden files and directories starting with a dot. |
location ^~ /static/ | Define a preferential prefix match location block that skips regex location matching if matched. |
proxy
| Command | Description |
|---|---|
proxy_pass http://127.0.0.1:3000; | Forward incoming requests to a proxy backend application server. |
proxy_set_header Host $host; | Set the Host header sent to the proxied server to match the request Host header. |
proxy_set_header X-Real-IP $remote_addr; | Pass the true client IP address to the proxied server via X-Real-IP header. |
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; | Append the client IP address to the X-Forwarded-For request header chain. |
proxy_set_header X-Forwarded-Proto $scheme; | Pass the original protocol (http or https) to the proxied backend server. |
proxy_connect_timeout 5s; | Set a timeout for establishing a connection with a proxied server. |
proxy_read_timeout 60s; | Set a timeout for reading a response from the proxied server. |
security
| Command | Description |
|---|---|
server_tokens off; | Disable emitting nginx version information in error pages and Server response header. |
deny all; | Deny access to all IP addresses not explicitly allowed. |
add_header X-Frame-Options "SAMEORIGIN" always; | Add HTTP header to prevent clickjacking by allowing framing only from the same origin. |
add_header X-Content-Type-Options "nosniff" always; | Add HTTP header to prevent MIME-type sniffing by browsers. |
allow 192.168.0.0/16; | Allow access to the specified IP address range or subnet. |
client_max_body_size 25m; | Set maximum allowed size of the client request body. |
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; | Enforce HTTP Strict Transport Security (HSTS) for one year including subdomains. |
limit_req_zone $binary_remote_addr zone=reqs:10m rate=10r/s; | Configure a shared memory zone for rate limiting requests by IP address. |
performance
| Command | Description |
|---|---|
gzip on; | Enable gzip compression for responses. |
gzip_comp_level 5; | Set gzip compression level from 1 (fastest) to 9 (highest compression). |
keepalive_timeout 65s; | Set timeout during which a keep-alive client connection will stay open on the server. |
expires 7d; | Set the Expires and Cache-Control headers for static file responses. |
add_header Cache-Control "public, max-age=604800, immutable"; | Add Cache-Control header for static asset caching. |
worker_processes auto; | Set the number of worker processes automatically based on available CPU cores. |
gzip_types text/plain text/css application/javascript application/json; | Specify MIME types to compress with gzip in addition to text/html. |
proxy_cache micro; | Specify shared memory zone name to use for caching responses from proxied servers. |
proxy_cache_valid 200 301 302 10s; | Set caching time for specific HTTP status codes. |
Key Use Cases
- Test a modified nginx.conf before reloading with nginx -t
- Redirect all HTTP traffic to HTTPS with a return 301 in a server block
- Forward requests to a backend app with proxy_pass and set the correct headers
- Match exact paths with = and prefix paths with ^~ before regex locations
- Harden a server by disabling the version header and adding security headers
- Enable gzip compression with correct MIME types and minimum size threshold
Frequently Asked Questions
What is the difference between root and alias in a location block?
root appends the location path to the document root. alias replaces the location path entirely with the specified directory. Example: root /var/www with location /images/ serves /var/www/images/file.jpg; alias /var/www/assets/ serves /var/www/assets/file.jpg.
What is the nginx location match priority order?
Exact match (=) first, then prefix modifier (^~) which stops regex matching, then regex (~, ~*) in file order, then the longest prefix match. A ^~ match prevents any regex from being tested.
Why is proxy_set_header Host $host needed behind a proxy?
Without it, nginx forwards its own host to the backend, not the client's Host header. The backend would not know which virtual host or domain the client requested, breaking name-based virtual hosting and redirects.
What is the difference between nginx -s reload and systemctl reload nginx?
nginx -s reload sends the HUP signal directly to the master nginx process. systemctl reload nginx uses systemd to send the same signal via the service unit. Both achieve a graceful config reload without dropping connections; prefer systemctl on systemd hosts.
Ready to master Nginx commands?
Test your muscle memory with our spaced-repetition quiz system. Free forever.
