Nginx config pro
The largest community-driven library of Agent Skills (SKILL.md + scripts/references/examples) for Claude, Codex, Gemini CLI, Cursor and friends.
npx -y skills add JayRHa/AgentSkills --skill nginx-config-proAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Generates and hardens production nginx configurations for reverse proxying with TLS termination, HTTP/2, response caching, rate limiting, gzip/brotli compression, and security headers. Use this skill when the user asks to "set up nginx as a reverse proxy", "add TLS/SSL to nginx", "configure nginx caching or rate limiting", "harden an nginx config", "proxy an app behind nginx", "fix nginx 502/504 errors", or write/review nginx.conf and server blocks.
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
9.1 KB, ~2.2k tokens by cl100k_base, as published. Nobody here has run it
nginx-config-pro
Overview
Authoritative guidance for writing secure, performant nginx reverse-proxy configurations. Produces server blocks that terminate TLS, speak HTTP/2, proxy to upstream applications, cache responses, throttle abusive clients, and compress payloads — without the footguns that cause 502s, header leaks, or weak ciphers.
Keywords: nginx, reverse proxy, TLS, SSL, HTTPS, HTTP/2, HTTP/3, certbot, Let's Encrypt, upstream, proxy_pass, gzip, brotli, rate limiting, limit_req, proxy_cache, security headers, HSTS, CSP, OCSP stapling, websocket, load balancing, 502 bad gateway, 504 gateway timeout.
This skill targets nginx 1.18+ (most directives work on 1.10+). HTTP/3 notes assume 1.25+.
When to use
- Standing up nginx in front of an app server (Node, Django/gunicorn, Rails/puma, PHP-FPM, a container).
- Adding or fixing TLS, redirects, or HSTS.
- Diagnosing 502/504, header duplication, or caching misses.
- Reviewing an existing
nginx.conffor security and performance.
Workflow
Follow these steps in order. Each builds on the previous.
- Gather inputs. Determine: domain name(s), upstream address (host:port or socket), app protocol (http/https/grpc/websocket), whether TLS certs exist or need Let's Encrypt, expected traffic profile (for rate limits and cache), and static asset paths.
- Choose a topology. Single upstream vs. load-balanced pool; HTTP/1.1 keepalive to upstream vs. fresh connections; whether caching is safe (idempotent GET responses with sane cache headers).
- Scaffold the file. Use
templates/reverse-proxy.conf.tmplas the starting point. Place site configs in/etc/nginx/sites-available/<name>.confand symlink intosites-enabled/(Debian/Ubuntu), or/etc/nginx/conf.d/<name>.conf(RHEL). - Configure TLS. Apply the cipher suite, protocols, and OCSP stapling from
references/tls-hardening.md. Always serve a port 80 → 443 redirect. Add HSTS only once you are certain HTTPS is permanent. - Set proxy headers correctly. Forward
Host,X-Forwarded-For,X-Forwarded-Proto, andX-Real-IP. Set sane timeouts. For websockets, add theUpgrade/Connectionmap. See the "Proxy headers" checklist below. - Add performance layers. Enable gzip (and brotli if the module is present), HTTP/2, upstream keepalive, and
proxy_cachewhere appropriate. - Add protection layers. Define
limit_req_zone/limit_conn_zoneinhttp {}and apply them inlocation/server. Add the security-header bundle. - Validate. Run
scripts/nginx_check.sh <conf>to lint for the most common mistakes, thennginx -tand reload. Verify externally perreferences/troubleshooting.md.
Proxy headers checklist (the #1 source of bugs)
Put shared proxy settings in a snippet (e.g. /etc/nginx/snippets/proxy.conf) and include it:
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header Connection ""; # enables upstream keepalive
proxy_read_timeout 60s;
proxy_connect_timeout 5s;
proxy_send_timeout 60s;
proxy_buffering on;
Rules:
- Use
$host(not$http_host) so a missing Host header degrades gracefully toserver_name. $proxy_add_x_forwarded_forappends; never hard-setX-Forwarded-For $remote_addrbehind another proxy.- Set
Connection ""only when paired with anupstream { keepalive N; }block andproxy_http_version 1.1. - Your app must trust these headers ONLY when nginx is the edge. Behind a load balancer/CDN, validate the real client IP via
set_real_ip_from+real_ip_header.
Worked decision: should I cache this?
| Condition | Cache? |
|---|---|
Response is GET/HEAD, no Set-Cookie, no Authorization | Yes |
Upstream sends Cache-Control: private/no-store | No (respect it) |
| Per-user/personalized HTML | No, or vary by a cache key that includes the session |
| Static assets (js/css/img with hashed names) | Yes, long expires, immutable |
| API JSON that changes every request | No |
When caching, always add a X-Cache-Status $upstream_cache_status header so you can confirm HIT/MISS/BYPASS. See references/caching-and-compression.md.
Rate limiting quick reference
Define zones in http {}, apply in server/location:
# http {} context
limit_req_zone $binary_remote_addr zone=req_per_ip:10m rate=10r/s;
limit_conn_zone $binary_remote_addr zone=conn_per_ip:10m;
# location {} context
limit_req zone=req_per_ip burst=20 nodelay;
limit_conn conn_per_ip 20;
limit_req_status 429;
burstabsorbs short spikes;nodelayserves the burst immediately instead of queuing.$binary_remote_addris compact (16 bytes/IPv6); a 10m zone holds ~160k unique IPs.- For login endpoints use a tighter zone (e.g.
rate=5r/m) to slow credential stuffing. - Behind a CDN, key on the real client IP (after
real_ip), not the CDN edge IP.
Security headers bundle
Apply at server scope (see references/tls-hardening.md for full rationale and CSP guidance):
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Content-Security-Policy "default-src 'self'" always;
server_tokens off;
The always flag is mandatory — without it headers are dropped on 4xx/5xx responses.
Best Practices
- One server block per concern. Keep a dedicated port-80 redirect block separate from the TLS block.
- Always
server_tokens off;to hide the nginx version. - Use snippets/includes for
proxy.conf,ssl.conf, andsecurity-headers.confso every site stays consistent. - Pin
ssl_protocols TLSv1.2 TLSv1.3;and a modern cipher list; disable TLS 1.0/1.1. - Test before reload:
nginx -t && nginx -s reload. Never reload a config that fails the test. - Set explicit timeouts. Defaults (60s read) can hang clients on a slow upstream.
- Define a default
server_name _;block that returns 444 to drop requests for unknown hosts. - Log to structured/JSON format when shipping to a log pipeline (see template).
- Reload, don't restart, for config changes — reload is zero-downtime.
Common Pitfalls
- Missing
Connection ""+ keepalive mismatch → upstream connections not reused, or502storms. Pairproxy_http_version 1.1,Connection "", andupstream { keepalive }. add_headerwithoutalways→ security headers silently disappear on errors.add_headerinheritance trap → defining ANYadd_headerin alocationdiscards ALLadd_headerfrom the parentserver. Re-include the full bundle or use a snippet in every location that needs it.proxy_passtrailing-slash semantics →proxy_pass http://up/;(with slash) strips the matched location prefix; without the slash it passes the full URI. Mixing these breaks routing.- HSTS too early /
preloadbefore submission → can lock users out of HTTP formax-age. Start with a smallmax-age, droppreloaduntil you have submitted to hstspreload.org. 502 Bad Gateway→ upstream down, wrong port, or SELinux blocking the connection (setsebool -P httpd_can_network_connect 1). Seereferences/troubleshooting.md.504 Gateway Timeout→ slow upstream; raiseproxy_read_timeoutand fix the app, don't just mask it.413 Request Entity Too Large→ raiseclient_max_body_size(default 1m) for uploads.- Caching authenticated responses → leaks one user's data to another. Add
proxy_cache_bypass/proxy_no_cachefor cookies/Authorization. - Worker/file-descriptor limits → high-traffic sites need
worker_connectionsandworker_rlimit_nofileraised together.
Bundled files
templates/reverse-proxy.conf.tmpl— complete, fill-in server config with TLS, caching, rate limiting, gzip, websockets, and security headers.references/tls-hardening.md— cipher suites, protocols, OCSP stapling, HSTS, CSP, Let's Encrypt/certbot, real-IP behind CDN.references/caching-and-compression.md— proxy_cache zones, cache keys, bypass rules, gzip/brotli tuning, static asset strategy.references/troubleshooting.md— 502/504/413/444 diagnosis, header debugging, validation commands.scripts/nginx_check.sh— stdlib (bash/grep) linter for the most common nginx config mistakes.examples/node-app-proxy.md— worked example: proxying a Node app on :3000 to https://app.example.com.
What ships with it: 6 files
26.0 KB alongside SKILL.md, 1 of them executable
examples/
- node-app-proxy.md4.1 KB
references/
- caching-and-compression.md3.9 KB
- tls-hardening.md4.3 KB
- troubleshooting.md3.5 KB
scripts/
- nginx_check.shruns4.1 KB
templates/
- reverse-proxy.conf.tmpl6.2 KB
Gives 0 of the 12 instructions most project setup skills give in ~2.2k tokens
Counted across 999 of the 1,637 authors here whose files we hold, read 2026-08-07
- Ask one question at a timein 29 of 999, across 28 files
- Detect the package manager from lockfilesin 28 of 999, across 9 files
- Present findings to the userin 26 of 999, across 5 files
- Explore current repo statein 24 of 999, across 3 files
- Update the agent skills block in place if it existsin 24 of 999, across 3 files
- Install husky lint-staged and prettierin 23 of 999, across 4 files
- Create the lintstagedrc filein 22 of 999, across 3 files
- Commit all changed filesin 22 of 999, across 3 files
- Run lint-staged to verify it worksin 22 of 999, across 3 files
- Create the husky pre-commit filein 21 of 999, across 2 files
- Create a prettierrc file if missingin 21 of 999, across 2 files
- Initialize huskyin 21 of 999, across 2 files
Said here and by no other author read
- gather inputs before generating the configuration
- redirect all port 80 traffic to port 443
- disable tls 1.0 and tls 1.1
- use a shared snippet for proxy headers
- enable gzip http2 and upstream keepalive
- apply rate limiting zones to server and location blocks
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.