{"id":12702,"date":"2025-12-20T12:01:20","date_gmt":"2025-12-20T06:31:20","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=12702"},"modified":"2026-09-07T11:10:29","modified_gmt":"2026-09-07T05:40:29","slug":"what-is-nginx-on-linux-server","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/what-is-nginx-on-linux-server\/","title":{"rendered":"What is Nginx on Linux Server? Complete Linux Web Server Guide"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Nginx on a Linux server<\/strong> is a high\u2011performance, event\u2011driven web server and reverse proxy that efficiently serves static files, balances load, terminates SSL\/TLS, and accelerates dynamic apps <strong>(PHP, Node.js, Python)<\/strong> behind it. It\u2019s lean, scalable, and reliable, making it ideal for modern websites, APIs, and microservices in production environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re trying to understand Nginx on Linux server environments from scratch, this guide delivers a practical, step\u2011by\u2011step overview. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019ll learn how Nginx works, how to install and configure it, how to enable HTTPS, and how to tune performance and security using real\u2011world best practices I\u2019ve applied for 12+ years <a href=\"https:\/\/www.youstable.com\/blog\/benefits-of-web-hosting-control-panel-for-managed-hosting\/\">managing hosting<\/a> stacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-is-nginx-and-why-use-it-on-linux\"><strong>What is Nginx and Why Use it on Linux?<\/strong><\/h2>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\"><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Nginx (pronounced \u201cengine\u2011x\u201d) is an open\u2011source web server and reverse proxy built to handle massive concurrency with low resource usage. On Linux, Nginx thrives thanks to the kernel\u2019s efficient networking stack and tools like systemd, iptables\/nftables, SELinux\/AppArmor, and package managers for easy updates.<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1168\" height=\"784\" src=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-Nginx-and-Why-Use-It-on-Linux.png\" alt=\"What Is Nginx and Why Use It on Linux?\" class=\"wp-image-13177 size-full\" srcset=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-Nginx-and-Why-Use-It-on-Linux.png 1168w, https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/What-Is-Nginx-and-Why-Use-It-on-Linux-150x101.png 150w\" sizes=\"auto, (max-width: 1168px) 100vw, 1168px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key advantages include:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Event-driven, non\u2011blocking architecture for high throughput.<\/li>\n\n\n\n<li>Great at serving static assets (images, CSS, JS) from memory\/disk efficiently.<\/li>\n\n\n\n<li>Reverse proxy and <a href=\"https:\/\/www.youstable.com\/blog\/install-load-balancer-on-linux\/\">load balancer<\/a> for upstream apps (PHP\u2011FPM, Node.js, Python, Go).<\/li>\n\n\n\n<li>First\u2011class TLS\/HTTP\/2 support, caching, rate limiting, and request routing.<\/li>\n\n\n\n<li>Simple, readable configuration using \u201cserver\u201d and \u201clocation\u201d blocks.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-nginx-works-in-plain-english\"><strong>How Nginx Works (In Plain English)<\/strong>?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nginx uses a master process that spawns worker processes. Each worker handles many connections asynchronously. Instead of creating a new thread per connection (like older models), Nginx multiplexes thousands of sockets in a single process using Linux epoll, keeping CPU and memory usage low under heavy load.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"install-nginx-on-popular-linux-distributions\"><strong>Install Nginx on Popular Linux Distributions<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use your distro\u2019s package manager. These commands <a href=\"https:\/\/www.youstable.com\/blog\/install-nginx-on-linux\/\">install Nginx<\/a>, enable auto\u2011start, and open the firewall.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ubuntu-debian\"><strong>Ubuntu \/ Debian<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt install -y nginx\nsudo systemctl enable --now nginx\nsudo ufw allow 'Nginx Full'  # or: sudo ufw allow 80,443\/tcp<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"rhel-rocky-linux-almalinux-centos-stream\"><strong>RHEL \/ Rocky Linux \/ AlmaLinux \/ CentOS Stream<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo dnf install -y nginx\nsudo systemctl enable --now nginx\n# Firewalld\nsudo firewall-cmd --permanent --add-service=http\nsudo firewall-cmd --permanent --add-service=https\nsudo firewall-cmd --reload<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Verify Nginx is serving the default page:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl -I http:\/\/your_server_ip\n# or visit http:\/\/server_ip in a browser<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"nginx-configuration-basics\"><strong>Nginx Configuration Basics<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.youstable.com\/blog\/configure-nginx-on-linux\/\">Nginx configuration<\/a> lives in \/etc\/nginx\/nginx.conf and includes site files from \/etc\/nginx\/sites-available (Debian\/Ubuntu) or server blocks defined in \/etc\/nginx\/conf.d (RHEL\u2011family). Always test your config before reloading.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nginx -t\nsudo systemctl reload nginx<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"static-website-server-block\"><strong>Static Website Server Block<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n    listen 80;\n    server_name example.com www.example.com;\n\n    root \/var\/www\/example.com\/public;\n    index index.html;\n\n    access_log \/var\/log\/nginx\/example.access.log;\n    error_log  \/var\/log\/nginx\/example.error.log warn;\n\n    location \/ {\n        try_files $uri $uri\/ =404;\n    }\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Enable the site on Debian\/Ubuntu:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ln -s \/etc\/nginx\/sites-available\/example.conf \/etc\/nginx\/sites-enabled\/\nsudo nginx -t &amp;&amp; sudo systemctl reload nginx<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"reverse-proxy-to-an-app-node-js-python-go\"><strong>Reverse Proxy to an App (Node.js, Python, Go)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>upstream app_backend {\n    server 127.0.0.1:3000 keepalive=32;\n}\n\nserver {\n    listen 80;\n    server_name app.example.com;\n\n    location \/ {\n        proxy_pass http:\/\/app_backend;\n        proxy_http_version 1.1;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n    }\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"php-with-php-fpm-fastcgi\"><strong>PHP with PHP\u2011FPM (FastCGI)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n    listen 80;\n    server_name php.example.com;\n    root \/var\/www\/php.example.com\/public;\n\n    location \/ {\n        try_files $uri $uri\/ \/index.php$is_args$args;\n    }\n\n    location ~ .php$ {\n        include fastcgi_params;\n        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;\n        fastcgi_pass unix:\/run\/php\/php8.2-fpm.sock; # adjust version\/socket\n    }\n}<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"enable-https-with-lets-encrypt-free-ssl-tls\"><strong>Enable HTTPS with Let\u2019s Encrypt (Free SSL\/TLS)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use Certbot to provision and auto\u2011renew certificates. This adds <a href=\"https:\/\/www.youstable.com\/blog\/how-to-enable-ssl-in-cpanel\/\">SSL and can enable<\/a> HTTP\/2.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Ubuntu\/Debian\nsudo apt install -y certbot python3-certbot-nginx\n# RHEL\/Rocky\/Alma\nsudo dnf install -y certbot python3-certbot-nginx\n\n# Issue and auto-configure\nsudo certbot --nginx -d example.com -d www.example.com\n\n# Test renewal\nsudo certbot renew --dry-run<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"recommended-tls-settings\"><strong>Recommended TLS Settings<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n    listen 443 ssl http2;\n    server_name example.com;\n\n    ssl_certificate     \/etc\/letsencrypt\/live\/example.com\/fullchain.pem;\n    ssl_certificate_key \/etc\/letsencrypt\/live\/example.com\/privkey.pem;\n\n    ssl_protocols TLSv1.2 TLSv1.3;\n    ssl_ciphers 'ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:TLS_AES_128_GCM_SHA256';\n    ssl_prefer_server_ciphers off;\n\n    add_header Strict-Transport-Security \"max-age=31536000; includeSubDomains\" always;\n    add_header X-Content-Type-Options nosniff;\n    add_header X-Frame-Options SAMEORIGIN;\n\n    # ... rest of config\n}<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"performance-tuning-nginx-on-linux\"><strong>Performance Tuning Nginx on Linux<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Start with sensible defaults and adjust after measuring. Focus on CPU, memory, and disk I\/O.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"core-tuning-in-nginx-conf\"><strong>Core Tuning in nginx.conf<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>worker_processes auto;\nevents {\n    worker_connections  4096;\n    multi_accept on;\n}\nhttp {\n    sendfile on;\n    tcp_nopush on;\n    tcp_nodelay on;\n    keepalive_timeout  65;\n\n    gzip on;\n    gzip_types text\/plain text\/css application\/javascript application\/json image\/svg+xml;\n\n    # Optional micro-caching for dynamic content\n    proxy_cache_path \/var\/cache\/nginx levels=1:2 keys_zone=STATIC:100m max_size=1g inactive=30m use_temp_path=off;\n\n    # Include your sites\n    include \/etc\/nginx\/conf.d\/*.conf;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Tips that move the needle:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use worker_processes auto to match CPU cores.<\/li>\n\n\n\n<li>Enable HTTP\/2 over TLS for multiplexing and header compression.<\/li>\n\n\n\n<li>Serve static assets with long cache <a href=\"https:\/\/www.youstable.com\/blog\/how-to-add-expires-headers\/\">headers and far\u2011future expires<\/a>.<\/li>\n\n\n\n<li>Offload static to a CDN when global latency matters.<\/li>\n\n\n\n<li>Enable proxy_cache for cacheable API responses and CMS pages (short TTLs).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"security-hardening-essentials\"><strong>Security Hardening Essentials<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keep Nginx and OpenSSL updated via apt\/dnf and schedule unattended upgrades.<\/li>\n\n\n\n<li><strong>Disable version exposure: <\/strong>server_tokens off; in http block.<\/li>\n\n\n\n<li>Use strong TLS, enable HSTS, and <a href=\"https:\/\/www.youstable.com\/blog\/redirect-http-to-https\/\">redirect HTTP<\/a> to HTTPS.<\/li>\n\n\n\n<li>Rate-limit abusive endpoints (e.g., login):<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>http {\n    limit_req_zone $binary_remote_addr zone=logins:10m rate=10r\/m;\n    server {\n        location = \/wp-login.php {\n            limit_req zone=logins burst=20 nodelay;\n            proxy_pass http:\/\/php_backend;\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Harden request sizes: <\/strong>client_max_body_size 10m; and timeouts.<\/li>\n\n\n\n<li>Use a WAF (e.g., Nginx App Protect, ModSecurity) if exposure is high.<\/li>\n\n\n\n<li>Protect admin panels by IP allowlists or HTTP auth.<\/li>\n\n\n\n<li>On SELinux systems, set proper contexts for web roots and sockets.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"troubleshooting-nginx-like-a-pro\"><strong>Troubleshooting Nginx Like a Pro<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Validate config:<\/strong> sudo nginx -t then sudo systemctl reload nginx<\/li>\n\n\n\n<li><strong>Check logs:<\/strong> tail -f \/var\/log\/nginx\/error.log and access.log<\/li>\n\n\n\n<li><strong>Service health: <\/strong>systemctl status nginx; journalctl -u nginx<\/li>\n\n\n\n<li><strong>Port binding:<\/strong> ss -tulpen | grep -E &#8216;:80|:443&#8217;<\/li>\n\n\n\n<li><strong>SELinux denials:<\/strong> ausearch -m avc -ts recent; restorecon -Rv \/var\/www\/site<\/li>\n\n\n\n<li><strong>Upstream reachability:<\/strong> curl -I http:\/\/127.0.0.1:3000\/<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"nginx-vs-apache-which-should-you-choose\"><strong>Nginx vs. Apache: Which Should You Choose?<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Nginx shines with concurrency and static content, using less memory under load.<\/li>\n\n\n\n<li>Apache offers rich .htaccess flexibility and deep module ecosystem.<\/li>\n\n\n\n<li><strong>Many stacks use both:<\/strong> Nginx as reverse proxy\/front proxy, Apache\/PHP\u2011FPM behind.<\/li>\n\n\n\n<li>For high\u2011traffic sites and APIs, Nginx is often the default front end.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"common-use-cases-on-linux-servers\"><strong>Common Use Cases on Linux Servers<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.youstable.com\/blog\/how-to-choose-the-best-wordpress-hostings\/\">Host WordPress<\/a> or CMS sites via Nginx + PHP\u2011FPM with full\u2011page caching.<\/li>\n\n\n\n<li>Reverse proxy to Node.js\/Express, Django, Flask, Laravel, or Go services.<\/li>\n\n\n\n<li>Microservices gateway with path\u2011based routing and JWT\u2011aware upstreams.<\/li>\n\n\n\n<li>Static site hosting with gzip\/Brotli and immutable cache headers.<\/li>\n\n\n\n<li>SSL termination and HTTP\/2 multiplexing in front of legacy apps.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"logs-metrics-and-observability\"><strong>Logs, Metrics, and Observability<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access\/Error logs: analyze with GoAccess or ship to ELK\/Graylog.<\/li>\n\n\n\n<li>Status metrics: nginx stub_status or the Nginx Prometheus exporter.<\/li>\n\n\n\n<li>Log rotation: ensure logrotate is configured to prevent disk fill.<\/li>\n\n\n\n<li>SLOs: track p95\/p99 latency, error rates, and active connections.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"real-world-configuration-snippets-youll-reuse\"><strong>Real World Configuration Snippets You\u2019ll Reuse<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"force-https-and-non-www\"><strong>Force HTTPS and Non\u2011WWW<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>server {\n    listen 80;\n    server_name www.example.com example.com;\n    return 301 https:\/\/example.com$request_uri;\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"static-caching-headers\"><strong>Static Caching Headers<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>location ~* .(css|js|jpg|jpeg|png|gif|svg|webp|ico)$ {\n    expires 30d;\n    add_header Cache-Control \"public, immutable\";\n    access_log off;\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"micro-caching-dynamic-pages-short-ttl\"><strong>Micro\u2011Caching Dynamic Pages (Short TTL)<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>proxy_cache_path \/var\/cache\/nginx\/micro levels=1 keys_zone=MICRO:50m max_size=500m inactive=10m;\n\nserver {\n    location \/ {\n        proxy_cache MICRO;\n        proxy_cache_valid 200 301 302 5s;\n        proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504;\n        add_header X-Cache $upstream_cache_status;\n        proxy_pass http:\/\/php_backend;\n    }\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"cost-effective-hosting-tip\"><strong>Cost\u2011Effective Hosting Tip<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you prefer a ready\u2011to\u2011go environment, YouStable offers Linux hosting plans where Nginx is optimized for HTTP\/2, TLS, caching, and PHP\u2011FPM out of the box. Our team can provision server blocks, SSL, and monitoring so you can focus on your application while we handle the stack.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"best-practices-checklist-quick-reference\"><strong>Best Practices Checklist (Quick Reference)<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use latest LTS Linux and keep Nginx updated.<\/li>\n\n\n\n<li>Enable HTTPS with Let\u2019s Encrypt and HTTP\/2.<\/li>\n\n\n\n<li>Serve static assets via Nginx, cache aggressively.<\/li>\n\n\n\n<li>Reverse proxy dynamic apps; keep upstreams healthy.<\/li>\n\n\n\n<li>Tune workers, keepalives, and gzip; measure results.<\/li>\n\n\n\n<li>Harden TLS, rate limit, and restrict admin access.<\/li>\n\n\n\n<li>Monitor logs and expose metrics for capacity planning.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs\"><strong>FAQs: <\/strong><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765773482878\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ewhat-is-nginx-used-for-on-a-linux-serveru003c-strongu003e\">u003cstrongu003eWhat is Nginx used for on a Linux server?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Nginx serves static files, acts as a reverse proxy to app servers, load balances traffic, and terminates SSL\/TLS. It\u2019s preferred for high\u2011traffic sites due to its event\u2011driven architecture and low memory footprint.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765773505509\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-do-i-install-and-start-nginx-on-ubuntuu003c-strongu003e\">u003cstrongu003eHow do I install and start Nginx on Ubuntu?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Run: sudo apt update u0026amp;u0026amp; sudo apt install -y nginx, then sudo systemctl enable u002du002dnow nginx. Allow ports with sudo ufw allow &#8216;Nginx Full&#8217;. Visit your server IP to confirm it\u2019s running.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765773521641\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003enginx-vs-apache-which-is-fasteru003c-strongu003e\">u003cstrongu003eNginx vs Apache: which is faster?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Nginx typically handles concurrent connections more efficiently and serves static content faster. Apache offers flexible .htaccess and powerful modules. Many production stacks use Nginx in front of Apache\/PHP\u2011FPM for the best of both.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765773538470\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-do-i-enable-https-with-lets-encrypt-on-nginxu003c-strongu003e\">u003cstrongu003eHow do I enable HTTPS with Let\u2019s Encrypt on Nginx?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Install Certbot and its Nginx plugin, then run sudo certbot u002du002dnginx -d yourdomain -d www.yourdomain. Certbot configures SSL\/TLS and sets up auto\u2011renewal. Test with sudo certbot renew u002du002ddry-run.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765773553916\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"u003cstrongu003ehow-can-i-speed-up-nginxu003c-strongu003e\">u003cstrongu003eHow can I speed up Nginx?u003c\/strongu003e<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Use worker_processes auto; tune worker_connections; enable gzip; serve static files directly; enable HTTP\/2; add micro\u2011caching for dynamic pages; and place a CDN in front for global traffic. Measure improvements with logs and metrics.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Nginx on a Linux server is a high\u2011performance, event\u2011driven web server and reverse proxy that efficiently serves static files, balances [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":15598,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":81,"footnotes":""},"categories":[350,1195,2260],"tags":[],"class_list":["post-12702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-blogging","category-kb-web-servers"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/12702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=12702"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/12702\/revisions"}],"predecessor-version":[{"id":23171,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/12702\/revisions\/23171"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/15598"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=12702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=12702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=12702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}