🌐

Nginx 配置生成

勾选即生成反向代理、负载均衡、HTTPS、限流、跨域的 Nginx 配置,自带自检

🎯使用场景

🌐站点参数

域名(多个用空格分开)
网站根目录
默认首页

🔒端口与 HTTPS

证书路径
私钥路径

⚡性能与安全

上传上限 20 MB
静态缓存 30 天
限流 不限
跨域 CORS 允许的来源(留空不启用)
日志文件名(留空按域名推导)

📄生成的配置

# ===================================================
# nginx 配置 · 静态站点 / SPA
# 由 997 工具箱生成:https://it997.com/tool/nginx-conf
# 保存为 /etc/nginx/conf.d/xxx.conf,先 nginx -t 再 reload
# ===================================================

server {
    listen 80;
    server_name example.com www.example.com;

    # 证书续期校验目录:放行了 certbot 才能自动续,路径按自己 webroot 改
    location ^~ /.well-known/acme-challenge/ {
        root /var/www/example.com;
    }

    location / {
        return 301 https://$host$request_uri;
    }
}

server {
    listen 443 ssl;
    http2 on;
    server_name example.com www.example.com;

    root /var/www/example.com;
    index index.html index.htm;
    charset utf-8;

    client_max_body_size 20m;
    access_log /var/log/nginx/example_com.access.log;
    error_log  /var/log/nginx/example_com.error.log;

    # ---- HTTPS ----
    ssl_certificate     /etc/nginx/ssl/example.com/fullchain.pem;
    ssl_certificate_key /etc/nginx/ssl/example.com/privkey.pem;
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_prefer_server_ciphers on;
    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 1d;
    ssl_session_tickets off;

    # ---- 压缩 ----
    gzip on;
    gzip_vary on;
    gzip_comp_level 6;
    gzip_min_length 1024;
    gzip_types text/plain text/css text/xml application/json application/javascript application/xml application/xml+rss image/svg+xml;

    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-Frame-Options "SAMEORIGIN" always;
    add_header Referrer-Policy "strict-origin-when-cross-origin" always;

    location / {
        try_files $uri $uri/index.html /index.html;
    }

    # ---- 静态资源缓存 30 天 ----
    location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|webp|woff2?|ttf|map)$ {
        expires 30d;
        access_log off;
    }
}

🩺配置自检

提示HSTS 一旦生效浏览器会强制走 HTTPS,max-age 期间无法回退到 HTTP,确认证书续期没问题再开。
提示http2 on; 需要 nginx ≥ 1.25.1;老版本请改成 listen 443 ssl http2; 并删掉这一行。

🧨几个改起来最容易翻车的点

  • try_files 别写成 $uri/:会先 301 跳转到带尾斜杠的地址, 与 canonical、站内链接对不上。要写 $uri $uri/index.html /index.html。
  • location 里用了 add_header,外层的就失效:子块一旦出现 add_header, 父块的全部 add_header 都会被丢弃,安全头要重抄一遍。
  • limit_req_zone 只能写在 http { } 里:贴进 server 块会报 "limit_req_zone" directive is not allowed here。
  • 反代场景拿不到真实客户端 IP:后端要读 X-Forwarded-For, Java / Node 侧记得配对应的转发头解析,不然日志里全是 127.0.0.1。
  • 证书续期要放行校验目录:强制跳 HTTPS 时, /.well-known/acme-challenge/ 必须单独放行,否则 certbot 续不了。

Nginx 配置生成怎么用

按场景勾选就能生成一份可直接 nginx -t 的 server 配置:静态站点与 SPA 路由回退、反向代理(含 WebSocket)、PHP-FPM、多后端负载均衡,外加 HTTPS 强制跳转、gzip、静态缓存、限流与跨域头。生成前会把证书路径、后端数量、server_name 写法这些容易翻车的地方先提示出来。

  1. 选使用场景(静态 / 反代 / PHP / 负载均衡)
  2. 填域名与对应参数,勾选要开的开关
  3. 复制或下载 .conf,nginx -t 通过后 reload

小贴士所有配置都在浏览器本地生成,不上传服务器;limit_req_zone 必须放进 http { },配置里已单独标出。

Nginx 配置生成常见问题

Nginx 配置生成是免费的吗?

完全免费,无需注册登录,也不限使用次数。997 工具箱所有工具都不收费。

使用Nginx 配置生成会把我的数据上传到服务器吗?

不会。Nginx 配置生成在浏览器本地完成计算,输入的文本和文件都不会离开你的设备,页面关闭后数据即消失。

Nginx 配置生成在手机上能用吗?

可以。页面做了移动端适配,手机和平板的浏览器打开同样能正常使用,也不需要安装任何 App。