nginx server block generator for WordPress
Answer a few questions and get an nginx server block for a WordPress site, built on the rules in WordPress's own nginx documentation. Built in your browser.
# Give the site's domain to see its server block.
What this file is
nginx does not read .htaccess. Everything it does for a site is written in a server block, in a file the server loads when it starts. The file built here is a server block for one WordPress site. Its bones are the per-site rules in WordPress's own nginx documentation: a file that exists is served as it is, and every other address is handed to WordPress, which is what makes permalinks work.
How to use it
This is for a server you run yourself, with access as an administrator. On managed hosting, the host writes this file.
- Save the file into the folder your nginx loads site files from. On Debian and Ubuntu that is
/etc/nginx/sites-available/, with a link to it in/etc/nginx/sites-enabled/. - Test the configuration before you load it:
sudo nginx -t. It names the file and the line of anything it cannot read, and changes nothing. - If the test passes, reload:
sudo nginx -s reload. - Open the site, a post, and the login page, in a private window.
A page that answers 502 Bad Gateway means nginx could not reach PHP: the socket or address in the file is not where your PHP-FPM listens. Its pool file has a line beginning listen = that says where.
https
If the site has no certificate yet, leave the first choice as it is. The file is then a plain http block, and Certbot, the tool Let's Encrypt recommends, adds the https lines and the redirect to it and renews the certificate afterwards. How to move a site to https has the steps. If the certificate is already on the server, the second choice writes the https blocks with its two files.
What the rules do
- Closed addresses. Hidden files,
wp-config.php, the debug log, and any PHP file in the uploads folder are refused. The folder a certificate is renewed through stays open. - The login page can be limited to addresses you name. That block hands the file to PHP itself, which is the part people leave out when they write it by hand. How to protect WordPress from brute force attacks says when this is the right measure.
- Headers and compression are the rules from how to add security headers and how to enable gzip and Brotli.
On Apache, use the .htaccess generator instead. Nothing you type here is sent to us. The file is built in your browser.
Common questions
Does this work for a network of sites (multisite)?
Which PHP socket do I choose?
Why is there no line that turns on HTTP/2?
Can I paste this into a file that already has a server block for the site?
Would you rather not run the server yourself?
Tell us what the site is on and what it should do. We reply with the cause, or the plan, and a fixed quote. The diagnosis is free.
Get a free diagnosis
