Skip to content

nginx server block generator for WordPress

Answer a few questions and get an nginx server block for a WordPress site, built on the rules in WordPress's own nginx documentation. Built in your browser.

The site

With www or without, whichever the site uses.

It gets a block of its own that sends visitors to the name above.

PHP

The sockets listed are where the common Debian and Ubuntu packages put them. Your pool's own listen setting has the last word.

nginx refuses a larger request before PHP sees it. PHP's own two limits have to allow as much.

https

Certbot adds the https lines and the redirect to a plain block by itself, and renews the certificate afterwards.

Rules

X-Content-Type-Options, Referrer-Policy and X-Frame-Options.

The rule from WordPress's own nginx documentation.

Only if nothing uses it. Jetpack and the WordPress mobile apps do.

IP addresses that do not change, separated by spaces. Not for a site where customers or members log in.

example.com.conf
# Give the site's domain to see its server block.
Built in your browser.

What this file is

nginx does not read .htaccess. Everything it does for a site is written in a server block, in a file the server loads when it starts. The file built here is a server block for one WordPress site. Its bones are the per-site rules in WordPress's own nginx documentation: a file that exists is served as it is, and every other address is handed to WordPress, which is what makes permalinks work.

How to use it

This is for a server you run yourself, with access as an administrator. On managed hosting, the host writes this file.

  1. Save the file into the folder your nginx loads site files from. On Debian and Ubuntu that is /etc/nginx/sites-available/, with a link to it in /etc/nginx/sites-enabled/.
  2. Test the configuration before you load it: sudo nginx -t. It names the file and the line of anything it cannot read, and changes nothing.
  3. If the test passes, reload: sudo nginx -s reload.
  4. Open the site, a post, and the login page, in a private window.

A page that answers 502 Bad Gateway means nginx could not reach PHP: the socket or address in the file is not where your PHP-FPM listens. Its pool file has a line beginning listen = that says where.

https

If the site has no certificate yet, leave the first choice as it is. The file is then a plain http block, and Certbot, the tool Let's Encrypt recommends, adds the https lines and the redirect to it and renews the certificate afterwards. How to move a site to https has the steps. If the certificate is already on the server, the second choice writes the https blocks with its two files.

What the rules do

On Apache, use the .htaccess generator instead. Nothing you type here is sent to us. The file is built in your browser.

Common questions

Does this work for a network of sites (multisite)?
No. A network needs further rules, which WordPress's nginx documentation gives for each kind of network. This writes the block for a single site.
Which PHP socket do I choose?
The one your PHP-FPM pool listens on. The list holds the paths the common Debian and Ubuntu packages use for each PHP version. If yours is somewhere else, choose the last entry and type it: the pool's own file says where, on the line beginning listen =.
Why is there no line that turns on HTTP/2?
How it is written changed between nginx versions, and a line from one is an error or a warning on the other. Add it yourself in the form your version's documentation gives.
Can I paste this into a file that already has a server block for the site?
Replace the old block with it. Two blocks that claim the same name on the same port make nginx warn and ignore one of them.

Would you rather not run the server yourself?

Tell us what the site is on and what it should do. We reply with the cause, or the plan, and a fixed quote. The diagnosis is free.

Get a free diagnosis