Build a reverse proxy nginx server block with SSL and caching.
# Nginx reverse proxy configuration for example.com
# Generated by ToolHub Nginx Config Generator
# Install: save this file to /etc/nginx/sites-available/example.com.conf, then:
# sudo ln -s /etc/nginx/sites-available/example.com.conf /etc/nginx/sites-enabled/
# sudo nginx -t && sudo systemctl reload nginx
# Redirect all plain HTTP traffic to HTTPS
server {
listen 80;
server_name example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
http2 on;
server_name example.com;
# Let's Encrypt certificate (certbot)
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
# Maximum request body size (uploads)
client_max_body_size 10m;
# Gzip compression for text-based responses
gzip on;
gzip_vary on;
gzip_proxied any;
gzip_comp_level 6;
gzip_min_length 1024;
gzip_types text/plain text/css application/json application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript image/svg+xml;
# Reverse proxy to the application server
location / {
proxy_pass http://127.0.0.1:3000;
proxy_http_version 1.1;
# Forward the original client information
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
📁 Place the file in /etc/nginx/sites-available/ and symlink it into /etc/nginx/sites-enabled/, then run sudo nginx -t && sudo systemctl reload nginx. 🔒 Generated 100% client-side — nothing is sent anywhere.
Setting up nginx as a reverse proxy — in front of a Node.js app, a Python API, or any local service — means remembering a dozen directives: which headers to forward, how to terminate SSL, how WebSocket upgrades work. This generator builds a complete, commented sites-available config from a simple form, live as you type. Everything runs in your browser, and the result downloads as a .conf file ready for your server.
Every config forwards the headers your app needs to see real clients: Host, X-Real-IP, X-Forwarded-For, and X-Forwarded-Proto, plus proxy_http_version 1.1. Enable SSL to get a 443 ssl http2 listener with Let's Encrypt certificate paths and an HTTP→HTTPS redirect block; enable WebSocket support for the Upgrade/Connection headers and the required map block. Optional gzip and static asset caching (expires 30d) round out a production-ready setup.
Save the file to /etc/nginx/sites-available/your-domain.conf, symlink it with sudo ln -s /etc/nginx/sites-available/your-domain.conf /etc/nginx/sites-enabled/, then run sudo nginx -t to validate and sudo systemctl reload nginx to apply. If you use SSL, obtain the certificate first with sudo certbot --nginx -d your-domain.com, or start with SSL off and add it later.
Three mistakes cause most reverse-proxy bugs. First, a missing or wrong Host header breaks apps that route by domain — the generated config always sets it. Second, WebSocket apps hang silently without the Upgrade headers and the map $http_upgrade $connection_upgrade block. Third, uploads fail with 413 Request Entity Too Large until client_max_body_size is raised — pick the value that matches your largest expected upload. Also make sure your app binds to the proxy target port (127.0.0.1 is safest) and that the firewall allows ports 80/443.
The Nginx Config Generator creates nginx config generator on demand, right in your browser. Set the options you need, click generate, and the result is ready to copy. Because everything runs locally, nothing you enter or produce leaves your device.
Generators like this are useful when you need a specific output (a password, a UUID, a QR code, placeholder text) and don't want to install an app or trust an unknown website with your data. This tool is free, has no usage limits, and works the same on phone and desktop.
Common uses: people reach for this tool when they need to use a nginx reverse proxy config generator, nginx config for node js app, nginx websocket proxy config, or letsencrypt nginx ssl config template.
Browser-based tools like this one have a few real advantages over installed software or manual methods:
More tools you might find useful