You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

152 lines
4.2 KiB

  1. user www-data;
  2. worker_processes auto;
  3. worker_cpu_affinity auto;
  4. worker_rlimit_nofile 100000;
  5. pid /run/nginx.pid;
  6. pcre_jit on;
  7. events
  8. {
  9. multi_accept on;
  10. worker_connections 50000;
  11. accept_mutex on;
  12. use epoll;
  13. http
  14. {
  15. ##
  16. # EasyEngine Settings
  17. ##
  18. sendfile on;
  19. sendfile_max_chunk 512k;
  20. tcp_nopush on;
  21. tcp_nodelay on;
  22. keepalive_timeout 8;
  23. keepalive_requests 500;
  24. lingering_time 20s;
  25. lingering_timeout 5s;
  26. server_tokens off;
  27. reset_timedout_connection on;
  28. add_header X-Powered-By "WordOps v3.9.4 - Optimized by VirtuBox";
  29. add_header rt-Fastcgi-Cache $upstream_cache_status;
  30. # Limit Request
  31. limit_req_status 403;
  32. limit_req_zone $remote_addr_ipscrub zone=one:10m rate=1r/s;
  33. #Simple DOS mitigation
  34. ##Max c/s by ip
  35. #limit_conn_zone $binary_remote_addr zone=limit_per_ip:10m;
  36. #limit_conn limit_per_ip 80;
  37. ##Max rq/s by ip
  38. #limit_req_zone $binary_remote_addr zone=allips:10m rate=400r/s;
  39. #limit_req zone=allips burst=400 nodelay;
  40. # Proxy Settings
  41. # set_real_ip_from proxy-server-ip;
  42. # real_ip_header X-Forwarded-For;
  43. fastcgi_read_timeout 300;
  44. client_max_body_size 100m;
  45. #See - https://www.nginx.com/blog/thread-pools-boost-performance-9x/
  46. aio threads;
  47. # tls dynamic records patch directive
  48. ssl_dyn_rec_enable on;
  49. ssl_dyn_rec_enable on;
  50. ssl_dyn_rec_size_hi 4229;
  51. ssl_dyn_rec_size_lo 1369;
  52. ssl_dyn_rec_threshold 40;
  53. ssl_dyn_rec_timeout 1000;
  54. # nginx-vts-status module
  55. vhost_traffic_status_zone;
  56. resolver 8.8.8.8 1.1.1.1 valid=300s;
  57. resolver_timeout 10;
  58. ##
  59. # GeoIP module configuration, before removing comments
  60. # read the tutorial : https://gist.github.com/VirtuBox/9ed03c9bd9169202c358a8be181b7840
  61. ##
  62. #geoip_country /usr/share/GeoIP/GeoIP.dat;
  63. #geoip_city /usr/share/GeoIP/GeoIPCity.dat;
  64. ##
  65. # SSL Settings
  66. ##
  67. # intermediate configuration. tweak to your needs.
  68. ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
  69. ssl_ciphers 'TLS13+AESGCM+AES256:TLS13+AESGCM+AES128:TLS13+CHACHA20:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA:!DSS';
  70. ssl_prefer_server_ciphers on;
  71. ssl_session_cache shared:SSL:50m;
  72. ssl_session_timeout 1d;
  73. ssl_session_tickets off;
  74. ssl_ecdh_curve X25519:sect571r1:secp521r1:secp384r1;
  75. # Common security headers
  76. more_set_headers "X-Frame-Options : SAMEORIGIN";
  77. more_set_headers "X-Xss-Protection : 1; mode=block";
  78. more_set_headers "X-Content-Type-Options : nosniff";
  79. more_set_headers "Referrer-Policy : strict-origin-when-cross-origin";
  80. more_set_headers "X-Download-Options : noopen";
  81. ##
  82. # Basic Settings
  83. ##
  84. # server_names_hash_bucket_size 64;
  85. # server_name_in_redirect off;
  86. include /etc/nginx/mime.types;
  87. default_type application/octet-stream;
  88. ##
  89. # Logging Settings
  90. # access_log disabled for performance
  91. ##
  92. access_log off;
  93. error_log /var/log/nginx/error.log;
  94. # Log format Settings
  95. log_format rt_cache '$remote_addr_ipscrub $upstream_response_time $upstream_cache_status [$time_local] '
  96. '$http_host "$request" $status $body_bytes_sent '
  97. '"$http_referer" "$http_user_agent" $server_protocol';
  98. # ipscrub settings
  99. ipscrub_period_seconds 3600;
  100. ##
  101. # Gzip Settings
  102. ##
  103. # mitigation of CRIME/BREACH attacks
  104. gzip off;
  105. ##
  106. # Brotli Settings
  107. ##
  108. brotli on;
  109. brotli_static on;
  110. brotli_buffers 16 8k;
  111. brotli_comp_level 4;
  112. brotli_types *;
  113. ##
  114. # Virtual Host Configs
  115. ##
  116. include /etc/nginx/conf.d/*.conf;
  117. include /etc/nginx/sites-enabled/*;
  118. }