user nginx; worker_processes auto; #error_log /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /dev/stdout main; error_log /dev/stdout info; sendfile on; #tcp_nopush on; keepalive_timeout 65; #gzip on; # Pritunl Fake API Server definition server { listen 80; server_name _; return 301 https://$host$request_uri; } server { listen [::]:443 ssl; listen 443 ssl; server_name _; ssl_certificate /etc/nginx/certs/tls.crt.pem; ssl_certificate_key /etc/nginx/certs/tls.key.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; sendfile off; tcp_nodelay on; absolute_redirect off; root /var/www/html; index index.php index.html; location / { # First attempt to serve request as file, then # as directory, then fall back to index.php try_files $uri $uri/ /index.php?path=$uri&$args; } # Pass the PHP scripts to PHP-FPM listening on php-fpm.sock location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass fpm:9000; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_NAME $fastcgi_script_name; fastcgi_index index.php; include fastcgi_params; } location ~* \.(jpg|jpeg|gif|png|css|js|ico|xml)$ { expires 5d; } # Deny access to . files, for security location ~ /\. { log_not_found off; deny all; } } }