You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

190 lines
4.2 KiB

  1. user www-data;
  2. worker_processes auto;
  3. worker_cpu_affinity auto;
  4. worker_rlimit_nofile 100000;
  5. pid /run/nginx.pid;
  6. events
  7. {
  8. worker_connections 16384;
  9. multi_accept on;
  10. use epoll;
  11. }
  12. http
  13. {
  14. ##
  15. # EasyEngine Settings
  16. ##
  17. sendfile on;
  18. sendfile_max_chunk 512k;
  19. tcp_nopush on;
  20. tcp_nodelay on;
  21. keepalive_timeout 8;
  22. keepalive_requests 500;
  23. lingering_time 20s;
  24. lingering_timeout 5s;
  25. server_tokens off;
  26. reset_timedout_connection on;
  27. add_header X-Powered-By "EasyEngine v3.8.1 - Optimized by VirtuBox";
  28. add_header rt-Fastcgi-Cache $upstream_cache_status;
  29. # Limit Request
  30. limit_req_status 403;
  31. limit_req_zone $remote_addr_ipscrub zone=one:10m rate=1r/s;
  32. #Simple DOS mitigation
  33. ##Max c/s by ip
  34. #limit_conn_zone $binary_remote_addr zone=limit_per_ip:10m;
  35. #limit_conn limit_per_ip 80;
  36. ##Max rq/s by ip
  37. #limit_req_zone $binary_remote_addr zone=allips:10m rate=400r/s;
  38. #limit_req zone=allips burst=400 nodelay;
  39. # Proxy Settings
  40. # set_real_ip_from proxy-server-ip;
  41. # real_ip_header X-Forwarded-For;
  42. fastcgi_read_timeout 120s;
  43. client_max_body_size 100m;
  44. #See - https://www.nginx.com/blog/thread-pools-boost-performance-9x/
  45. aio threads;
  46. # tls dynamic records patch directive
  47. ssl_dyn_rec_enable on;
  48. ssl_dyn_rec_size_hi 4229;
  49. ssl_dyn_rec_size_lo 1369;
  50. ssl_dyn_rec_threshold 40;
  51. ssl_dyn_rec_timeout 1000;
  52. # nginx-vts-status module
  53. vhost_traffic_status_zone;
  54. resolver 8.8.8.8 1.1.1.1 valid=300s;
  55. resolver_timeout 10;
  56. ##
  57. # GeoIP module configuration, before removing comments
  58. # read the tutorial : https://gist.github.com/VirtuBox/9ed03c9bd9169202c358a8be181b7840
  59. ##
  60. #geoip_country /usr/share/GeoIP/GeoIP.dat;
  61. #geoip_city /usr/share/GeoIP/GeoIPCity.dat;
  62. ##
  63. # SSL Settings
  64. ##
  65. ssl_protocols TLSv1.2;
  66. ssl_ciphers 'EECDH+CHACHA20:EECDH+AESGCM';
  67. ssl_prefer_server_ciphers on;
  68. ssl_session_cache shared:SSL:50m;
  69. ssl_session_timeout 1d;
  70. ssl_session_tickets off;
  71. ssl_ecdh_curve X25519:sect571r1:secp521r1:secp384r1;
  72. ##Common headers for security
  73. more_set_headers "X-Frame-Options : SAMEORIGIN";
  74. more_set_headers "X-Xss-Protection : 1; mode=block";
  75. more_set_headers "X-Content-Type-Options : nosniff";
  76. more_set_headers "Referrer-Policy : strict-origin-when-cross-origin";
  77. ##
  78. # Basic Settings
  79. ##
  80. # server_names_hash_bucket_size 64;
  81. # server_name_in_redirect off;
  82. include /etc/nginx/mime.types;
  83. default_type application/octet-stream;
  84. ##
  85. # Logging Settings
  86. # access_log disabled for performance
  87. ##
  88. access_log off;
  89. error_log /var/log/nginx/error.log;
  90. # Log format Settings
  91. log_format rt_cache '$remote_addr_ipscrub $upstream_response_time $upstream_cache_status [$time_local] '
  92. '$http_host "$request" $status $body_bytes_sent '
  93. '"$http_referer" "$http_user_agent" $server_protocol';
  94. # ipscrub settings
  95. ipscrub_period_seconds 3600;
  96. ##
  97. # Gzip Settings
  98. ##
  99. gzip on;
  100. gzip_disable "msie6";
  101. gzip_vary on;
  102. gzip_proxied any;
  103. gzip_comp_level 6;
  104. gzip_buffers 16 8k;
  105. gzip_http_version 1.1;
  106. gzip_types
  107. application/atom+xml
  108. application/javascript
  109. application/json
  110. application/rss+xml
  111. application/vnd.ms-fontobject
  112. application/x-font-ttf
  113. application/x-web-app-manifest+json
  114. application/xhtml+xml
  115. application/xml
  116. font/opentype
  117. image/svg+xml
  118. image/x-icon
  119. text/css
  120. text/plain
  121. text/x-component
  122. text/xml
  123. text/javascript;
  124. ##
  125. # Brotli Settings
  126. ##
  127. brotli on;
  128. brotli_static on;
  129. brotli_buffers 16 8k;
  130. brotli_comp_level 4;
  131. brotli_types *;
  132. ##
  133. # Virtual Host Configs
  134. ##
  135. include /etc/nginx/conf.d/*.conf;
  136. include /etc/nginx/sites-enabled/*;
  137. }
  138. #mail {
  139. # # See sample authentication script at:
  140. # # http://wiki.nginx.org/ImapAuthenticateWithApachePhpScript
  141. #
  142. # # auth_http localhost/auth.php;
  143. # # pop3_capabilities "TOP" "USER";
  144. # # imap_capabilities "IMAP4rev1" "UIDPLUS";
  145. #
  146. # server {
  147. # listen localhost:110;
  148. # protocol pop3;
  149. # proxy on;
  150. # }
  151. #
  152. # server {
  153. # listen localhost:143;
  154. # protocol imap;
  155. # proxy on;
  156. # }
  157. #}