---
tags:
- devops
- l1
- flashcard-deck
- nginx
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Nginx & Web Servers](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
nginx/084e06a09ed8	nginx	easy	nginx, architecture, workers	How does Nginx achieve high concurrency with minimal resources?	Nginx uses an event-driven, non-blocking architecture. A master process manages multiple worker processes, each running an event loop (epoll/kqueue) that handles thousands of connections. There is no thread-per-connection overhead, allowing 10K+ concurrent connections on modest hardware. Total max connections = worker_processes x worker_connections.\n\nRemember: nginx config: http→server(vhost)→location(path). Directives inherit downward.	training/library/topics/nginx-web-servers/primer.md
nginx/7cc847a83137	nginx	easy	nginx, config, testing	What command should you always run before reloading Nginx?	nginx -t to test the configuration syntax. Always run nginx -t before nginx -s reload. Reload is graceful (no dropped connections); restart drops connections and should be avoided in production.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	training/library/topics/nginx-web-servers/primer.md
nginx/c1bdff2bce15	nginx	easy	nginx, server-blocks, virtual-hosts	How does Nginx select which server block handles a request?	1. Match the listen directive (IP:port). 2. Match server_name against the Host header. 3. If no match, use the default_server block. A catch-all block typically uses server_name _ (match nothing convention) and returns 444 to close unmatched connections.\n\nRemember: nginx config: http→server(vhost)→location(path). Directives inherit downward.	training/library/topics/nginx-web-servers/primer.md
nginx/83d51066f9b5	nginx	medium	nginx, location, matching	What is the Nginx location matching priority order?	From highest to lowest: 1. = (exact match), 2. ^~ (prefix, skips regex check), 3. ~ (case-sensitive regex) and ~* (case-insensitive regex) evaluated in config order, 4. plain prefix (longest match). Nginx first finds the longest prefix, then checks regex locations. First regex match wins. If no regex matches, the longest prefix is used.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	training/library/topics/nginx-web-servers/primer.md
nginx/abb38e49365a	nginx	medium	nginx, proxy-pass, trailing-slash	Why does the trailing slash in proxy_pass matter?	Without trailing slash (proxy_pass http://backend): the location path is appended — /app/page goes to backend as /app/page. With trailing slash (proxy_pass http://backend/): the location path is replaced — /app/page goes to backend as /page. With a path (proxy_pass http://backend/v2/): location is replaced with the path — /app/page becomes /v2/page. This is a top-5 Nginx misconfiguration.\n\nRemember: nginx config: http→server(vhost)→location(path). Directives inherit downward.	training/library/topics/nginx-web-servers/primer.md
nginx/83a2ae97e588	nginx	medium	nginx, upstream, load-balancing	What load balancing methods does Nginx support and how are upstream health checks configured?	Methods: round_robin (default), least_conn, ip_hash (sticky sessions), hash $key (consistent hashing), random. Health checks (OSS): passive only — set max_fails=3 fail_timeout=30s per server. After 3 failures in 30 seconds, the server is marked down for 30 seconds. Use keepalive connections to backends for performance.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	training/library/topics/nginx-web-servers/primer.md
nginx/eb5dc3945fa2	nginx	medium	nginx, ssl, tls	What are the key directives for modern TLS configuration in Nginx?	ssl_protocols TLSv1.2 TLSv1.3, ssl_ciphers with ECDHE suites, ssl_prefer_server_ciphers off, ssl_stapling on (OCSP stapling), ssl_session_cache shared:SSL:10m, ssl_session_tickets off, and add_header Strict-Transport-Security for HSTS. Redirect HTTP to HTTPS with a separate server block returning 301.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	training/library/topics/nginx-web-servers/primer.md
nginx/edaffc6d09a1	nginx	hard	nginx, caching, proxy-cache	How do you configure Nginx proxy caching with stale content fallback?	Define proxy_cache_path with keys_zone, max_size, and inactive time. In the location block: proxy_cache my_cache, proxy_cache_valid 200 302 10m (cache successful responses for 10 minutes), proxy_cache_use_stale error timeout updating http_500 http_502 (serve stale content when backend is down). Add X-Cache-Status header for debugging cache hits vs misses.\n\nRemember: `nginx -t` tests. `nginx -s reload` = zero-downtime. Config: /etc/nginx/nginx.conf.	training/library/topics/nginx-web-servers/primer.md
nginx/513ccd8f384b	nginx	hard	nginx, rate-limiting, security	How does Nginx rate limiting work with burst and nodelay?	limit_req_zone defines a shared memory zone with a rate (e.g., 10r/s per IP using $binary_remote_addr). In the location: limit_req zone=api burst=20 nodelay. Burst=20 allows 20 requests to exceed the rate before rejecting. Nodelay processes burst requests immediately rather than delaying them. Excess requests beyond the burst get a 429 status (limit_req_status 429).\n\nExample: `limit_req_zone $binary_remote_addr zone=one:10m rate=10r/s;`	training/library/topics/nginx-web-servers/primer.md
nginx/8161dab5dea1	nginx	hard	nginx, websocket, proxy	How do you configure Nginx to proxy WebSocket connections?	Set proxy_http_version 1.1, proxy_set_header Upgrade $http_upgrade, and proxy_set_header Connection "upgrade" in the location block. Also set proxy_read_timeout to a high value (e.g., 86400 seconds) to prevent Nginx from closing idle WebSocket connections. Without these headers, the HTTP upgrade handshake fails and WebSocket connections are rejected.\n\nRemember: `nginx -t` tests. `nginx -s reload` = zero-downtime. Config: /etc/nginx/nginx.conf.	training/library/topics/nginx-web-servers/primer.md
nginx/3a7f1c9b2e4d	nginx	easy	nginx, reverse-proxy, config	What is the minimal Nginx reverse proxy configuration for a backend app?	A server block with listen 80, server_name, and a location / block containing proxy_pass http://backend:port. Add proxy_set_header Host $host and proxy_set_header X-Real-IP $remote_addr so the backend sees the original client info. Without these headers the backend only sees the proxy's IP address.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/4b8e2d0a1f5c	nginx	medium	nginx, upstream, config	How do you define an upstream block and what options control backend behavior?	upstream app_backend { server 10.0.1.1:8080 weight=3; server 10.0.1.2:8080; server 10.0.1.3:8080 backup; keepalive 32; } The weight parameter controls traffic distribution, backup marks a server as failover-only, and keepalive sets the number of idle connections cached per worker to reduce TCP handshake overhead.\n\nExample: `upstream backend { server 10.0.0.1:8080; server 10.0.0.2:8080; }` — round-robin.	
nginx/5c9f3e1b2a6d	nginx	medium	nginx, location, rewrite	What is the difference between return and rewrite in Nginx location blocks?	return sends an immediate HTTP response (e.g., return 301 https://$host$request_uri) and is faster because it stops processing. rewrite modifies the URI internally and continues processing through other location blocks. Use return for redirects and rewrite for internal URI transformations. Mixing both causes hard-to-debug behavior.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/6d0a4f2c3b7e	nginx	medium	nginx, ssl-termination, performance	What are the performance benefits of SSL termination at the Nginx layer?	Nginx handles the expensive TLS handshake and encryption, offloading this CPU work from backend servers. Benefits: centralized certificate management, session resumption via ssl_session_cache, OCSP stapling to reduce client-side lookups, and backend servers communicate over plain HTTP on a trusted internal network. This can reduce backend CPU usage by 10-30%.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/7e1b5a3d4c8f	nginx	easy	nginx, error-pages, debugging	How do you configure custom error pages in Nginx and what are the most common HTTP errors to handle?	Use error_page directive: error_page 502 503 504 /50x.html with a location = /50x.html block pointing to the file. Common errors: 502 Bad Gateway (backend down), 503 Service Unavailable (overloaded), 504 Gateway Timeout (backend too slow). Check error logs at /var/log/nginx/error.log for root cause.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/8f2c6b4e5d9a	nginx	hard	nginx, caching, microcaching	What is microcaching in Nginx and when should you use it?	Microcaching caches responses for very short periods (1-5 seconds) using proxy_cache_valid 200 1s. Even 1-second caching dramatically reduces backend load during traffic spikes because hundreds of concurrent requests hit the cache instead of the backend. Use fastcgi_cache_lock on to prevent cache stampedes where multiple requests try to populate the cache simultaneously.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/9a3d7c5f6e0b	nginx	hard	nginx, load-balancing, sticky	How do you implement sticky sessions in Nginx without Nginx Plus?	Use ip_hash in the upstream block to route clients to the same backend based on their IP address. Limitation: all clients behind the same NAT share one backend. Alternative: use the hash directive with a cookie value (hash $cookie_jsessionid consistent) for more granular stickiness. Consistent hashing minimizes redistribution when backends are added or removed.\n\nRemember: nginx config: http→server(vhost)→location(path). Directives inherit downward.	
nginx/0b4e8d6a7f1c	nginx	medium	nginx, headers, security	What security headers should you add to every Nginx server block?	add_header X-Frame-Options "SAMEORIGIN" (prevents clickjacking)\nadd_header X-Content-Type-Options "nosniff" (prevents MIME sniffing)\nadd_header X-XSS-Protection "1; mode=block"\nadd_header Referrer-Policy "strict-origin-when-cross-origin"\nadd_header Content-Security-Policy "default-src 'self'"\nUse always parameter to add headers on error responses too.\n\nRemember: nginx = web server + reverse proxy + LB. Event-driven, 10K+ connections.\n\nFun fact: Created 2004 by Igor Sysoev for C10K problem. "engine-x."	
nginx/2b15d5dd8c00	nginx	medium	nginx, worker-connections, tuning, concurrency	How do worker_connections and worker_rlimit_nofile interact for high-concurrency Nginx?	worker_connections sets max simultaneous connections per worker. Each proxied connection uses two file descriptors (client + backend). worker_rlimit_nofile must be >= worker_connections (ideally 2x for proxying). Total capacity = worker_processes × worker_connections. Also raise the OS ulimit to match.\n\nRemember: `worker_processes auto;` = one per CPU. Thousands of connections via epoll.	training/library/topics/nginx-web-servers/primer.md
nginx/00c5fa69e249	nginx	medium	nginx, stub-status, monitoring, prometheus	How do you expose Nginx metrics for Prometheus monitoring?	Enable stub_status in a location block (returns active connections, accepts, handled, requests). Use nginx-prometheus-exporter sidecar to scrape stub_status and expose /metrics in Prometheus format. For richer metrics (per-upstream, per-location), use the commercial Nginx Plus API or OpenTelemetry module.\n\nRemember: nginx config: http→server(vhost)→location(path). Directives inherit downward.	training/library/topics/nginx-web-servers/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Nginx & Web Servers](../../../../library/topics/nginx-web-servers/index.md) (Topic Pack, L1) — Nginx & Web Servers

<!-- wiki:related:end -->
