agentsclimarketplace

Nginx config pro

Skill JayRHa/AgentSkills/nginx-config-pro

The largest community-driven library of Agent Skills (SKILL.md + scripts/references/examples) for Claude, Codex, Gemini CLI, Cursor and friends.

Install
npx -y skills add JayRHa/AgentSkills --skill nginx-config-pro

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Generates and hardens production nginx configurations for reverse proxying with TLS termination, HTTP/2, response caching, rate limiting, gzip/brotli compression, and security headers. Use this skill when the user asks to "set up nginx as a reverse proxy", "add TLS/SSL to nginx", "configure nginx caching or rate limiting", "harden an nginx config", "proxy an app behind nginx", "fix nginx 502/504 errors", or write/review nginx.conf and server blocks.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

9.1 KB, ~2.2k tokens by cl100k_base, as published. Nobody here has run it

nginx-config-pro

Overview

Authoritative guidance for writing secure, performant nginx reverse-proxy configurations. Produces server blocks that terminate TLS, speak HTTP/2, proxy to upstream applications, cache responses, throttle abusive clients, and compress payloads — without the footguns that cause 502s, header leaks, or weak ciphers.

Keywords: nginx, reverse proxy, TLS, SSL, HTTPS, HTTP/2, HTTP/3, certbot, Let's Encrypt, upstream, proxy_pass, gzip, brotli, rate limiting, limit_req, proxy_cache, security headers, HSTS, CSP, OCSP stapling, websocket, load balancing, 502 bad gateway, 504 gateway timeout.

This skill targets nginx 1.18+ (most directives work on 1.10+). HTTP/3 notes assume 1.25+.

When to use

  • Standing up nginx in front of an app server (Node, Django/gunicorn, Rails/puma, PHP-FPM, a container).
  • Adding or fixing TLS, redirects, or HSTS.
  • Diagnosing 502/504, header duplication, or caching misses.
  • Reviewing an existing nginx.conf for security and performance.

Workflow

Follow these steps in order. Each builds on the previous.

  1. Gather inputs. Determine: domain name(s), upstream address (host:port or socket), app protocol (http/https/grpc/websocket), whether TLS certs exist or need Let's Encrypt, expected traffic profile (for rate limits and cache), and static asset paths.
  2. Choose a topology. Single upstream vs. load-balanced pool; HTTP/1.1 keepalive to upstream vs. fresh connections; whether caching is safe (idempotent GET responses with sane cache headers).
  3. Scaffold the file. Use templates/reverse-proxy.conf.tmpl as the starting point. Place site configs in /etc/nginx/sites-available/<name>.conf and symlink into sites-enabled/ (Debian/Ubuntu), or /etc/nginx/conf.d/<name>.conf (RHEL).
  4. Configure TLS. Apply the cipher suite, protocols, and OCSP stapling from references/tls-hardening.md. Always serve a port 80 → 443 redirect. Add HSTS only once you are certain HTTPS is permanent.
  5. Set proxy headers correctly. Forward Host, X-Forwarded-For, X-Forwarded-Proto, and X-Real-IP. Set sane timeouts. For websockets, add the Upgrade/Connection map. See the "Proxy headers" checklist below.
  6. Add performance layers. Enable gzip (and brotli if the module is present), HTTP/2, upstream keepalive, and proxy_cache where appropriate.
  7. Add protection layers. Define limit_req_zone / limit_conn_zone in http {} and apply them in location/server. Add the security-header bundle.
  8. Validate. Run scripts/nginx_check.sh <conf> to lint for the most common mistakes, then nginx -t and reload. Verify externally per references/troubleshooting.md.

Proxy headers checklist (the #1 source of bugs)

Put shared proxy settings in a snippet (e.g. /etc/nginx/snippets/proxy.conf) and include it:

proxy_http_version 1.1;
proxy_set_header Host              $host;
proxy_set_header X-Real-IP         $remote_addr;
proxy_set_header X-Forwarded-For   $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host  $host;
proxy_set_header Connection        "";          # enables upstream keepalive
proxy_read_timeout    60s;
proxy_connect_timeout 5s;
proxy_send_timeout    60s;
proxy_buffering on;

Rules:

  • Use $host (not $http_host) so a missing Host header degrades gracefully to server_name.
  • $proxy_add_x_forwarded_for appends; never hard-set X-Forwarded-For $remote_addr behind another proxy.
  • Set Connection "" only when paired with an upstream { keepalive N; } block and proxy_http_version 1.1.
  • Your app must trust these headers ONLY when nginx is the edge. Behind a load balancer/CDN, validate the real client IP via set_real_ip_from + real_ip_header.

Worked decision: should I cache this?

ConditionCache?
Response is GET/HEAD, no Set-Cookie, no AuthorizationYes
Upstream sends Cache-Control: private/no-storeNo (respect it)
Per-user/personalized HTMLNo, or vary by a cache key that includes the session
Static assets (js/css/img with hashed names)Yes, long expires, immutable
API JSON that changes every requestNo

When caching, always add a X-Cache-Status $upstream_cache_status header so you can confirm HIT/MISS/BYPASS. See references/caching-and-compression.md.

Rate limiting quick reference

Define zones in http {}, apply in server/location:

# http {} context
limit_req_zone  $binary_remote_addr zone=req_per_ip:10m rate=10r/s;
limit_conn_zone $binary_remote_addr zone=conn_per_ip:10m;

# location {} context
limit_req  zone=req_per_ip burst=20 nodelay;
limit_conn conn_per_ip 20;
limit_req_status 429;
  • burst absorbs short spikes; nodelay serves the burst immediately instead of queuing.
  • $binary_remote_addr is compact (16 bytes/IPv6); a 10m zone holds ~160k unique IPs.
  • For login endpoints use a tighter zone (e.g. rate=5r/m) to slow credential stuffing.
  • Behind a CDN, key on the real client IP (after real_ip), not the CDN edge IP.

Security headers bundle

Apply at server scope (see references/tls-hardening.md for full rationale and CSP guidance):

add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
add_header X-Content-Type-Options    "nosniff" always;
add_header X-Frame-Options           "SAMEORIGIN" always;
add_header Referrer-Policy           "strict-origin-when-cross-origin" always;
add_header Content-Security-Policy    "default-src 'self'" always;
server_tokens off;

The always flag is mandatory — without it headers are dropped on 4xx/5xx responses.

Best Practices

  • One server block per concern. Keep a dedicated port-80 redirect block separate from the TLS block.
  • Always server_tokens off; to hide the nginx version.
  • Use snippets/includes for proxy.conf, ssl.conf, and security-headers.conf so every site stays consistent.
  • Pin ssl_protocols TLSv1.2 TLSv1.3; and a modern cipher list; disable TLS 1.0/1.1.
  • Test before reload: nginx -t && nginx -s reload. Never reload a config that fails the test.
  • Set explicit timeouts. Defaults (60s read) can hang clients on a slow upstream.
  • Define a default server_name _; block that returns 444 to drop requests for unknown hosts.
  • Log to structured/JSON format when shipping to a log pipeline (see template).
  • Reload, don't restart, for config changes — reload is zero-downtime.

Common Pitfalls

  • Missing Connection "" + keepalive mismatch → upstream connections not reused, or 502 storms. Pair proxy_http_version 1.1, Connection "", and upstream { keepalive }.
  • add_header without always → security headers silently disappear on errors.
  • add_header inheritance trap → defining ANY add_header in a location discards ALL add_header from the parent server. Re-include the full bundle or use a snippet in every location that needs it.
  • proxy_pass trailing-slash semanticsproxy_pass http://up/; (with slash) strips the matched location prefix; without the slash it passes the full URI. Mixing these breaks routing.
  • HSTS too early / preload before submission → can lock users out of HTTP for max-age. Start with a small max-age, drop preload until you have submitted to hstspreload.org.
  • 502 Bad Gateway → upstream down, wrong port, or SELinux blocking the connection (setsebool -P httpd_can_network_connect 1). See references/troubleshooting.md.
  • 504 Gateway Timeout → slow upstream; raise proxy_read_timeout and fix the app, don't just mask it.
  • 413 Request Entity Too Large → raise client_max_body_size (default 1m) for uploads.
  • Caching authenticated responses → leaks one user's data to another. Add proxy_cache_bypass/proxy_no_cache for cookies/Authorization.
  • Worker/file-descriptor limits → high-traffic sites need worker_connections and worker_rlimit_nofile raised together.

Bundled files

  • templates/reverse-proxy.conf.tmpl — complete, fill-in server config with TLS, caching, rate limiting, gzip, websockets, and security headers.
  • references/tls-hardening.md — cipher suites, protocols, OCSP stapling, HSTS, CSP, Let's Encrypt/certbot, real-IP behind CDN.
  • references/caching-and-compression.md — proxy_cache zones, cache keys, bypass rules, gzip/brotli tuning, static asset strategy.
  • references/troubleshooting.md — 502/504/413/444 diagnosis, header debugging, validation commands.
  • scripts/nginx_check.sh — stdlib (bash/grep) linter for the most common nginx config mistakes.
  • examples/node-app-proxy.md — worked example: proxying a Node app on :3000 to https://app.example.com.

What ships with it: 6 files

26.0 KB alongside SKILL.md, 1 of them executable

examples/

scripts/

templates/

Gives 0 of the 12 instructions most project setup skills give in ~2.2k tokens

Counted across 999 of the 1,637 authors here whose files we hold, read 2026-08-07

  • Ask one question at a timein 29 of 999, across 28 files
  • Detect the package manager from lockfilesin 28 of 999, across 9 files
  • Present findings to the userin 26 of 999, across 5 files
  • Explore current repo statein 24 of 999, across 3 files
  • Update the agent skills block in place if it existsin 24 of 999, across 3 files
  • Install husky lint-staged and prettierin 23 of 999, across 4 files
  • Create the lintstagedrc filein 22 of 999, across 3 files
  • Commit all changed filesin 22 of 999, across 3 files
  • Run lint-staged to verify it worksin 22 of 999, across 3 files
  • Create the husky pre-commit filein 21 of 999, across 2 files
  • Create a prettierrc file if missingin 21 of 999, across 2 files
  • Initialize huskyin 21 of 999, across 2 files

Said here and by no other author read

  • gather inputs before generating the configuration
  • redirect all port 80 traffic to port 443
  • disable tls 1.0 and tls 1.1
  • use a shared snippet for proxy headers
  • enable gzip http2 and upstream keepalive
  • apply rate limiting zones to server and location blocks

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 327,132. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.