A practical guide to the four generators: what each setting does, where the output goes on your server, and how to test it before going live.
# tell you where the snippet belongs and which modules it needs.sudo cp site.conf site.conf.bak.Everything runs in your browser. Nothing you type is sent to a server. Every combination of options was checked against real Nginx 1.27.x and Apache 2.4.x binaries during development (not live each time you generate a config).
Builds a complete site config for a reverse proxy, WordPress, a static site or a PHP-FPM app.
Open the Config Generator →https:// or a trailing slash, e.g. example.com.127.0.0.1:3000.1m. Raise it if your app accepts larger uploads, otherwise users get a "413 Request Entity Too Large" error./var/www/example.com.unix:/run/php/php8.3-fpm.sock, or a TCP address like 127.0.0.1:9000. Check your PHP version's pool config if unsure.set_real_ip_from lines for Cloudflare's published IP ranges plus real_ip_header CF-Connecting-IP, so logs and apps see real visitor IPs. On Apache the equivalent mod_remoteip lines are shown as comments, because they must go in the virtual host, not .htaccess. Either way, set Cloudflare's SSL/TLS mode to Full (strict): "Flexible" talks to your server over plain HTTP, so an HTTP-to-HTTPS redirect loops forever. Cloudflare's ranges change rarely; the current list is at cloudflare.com/ips.Running WordPress or a PHP app and would rather not manage Nginx and PHP-FPM yourself? Kinsta offers managed WordPress hosting with free migrations, and Cloudways offers managed cloud hosting for WordPress and PHP apps on DigitalOcean, Vultr or AWS (affiliate links).
Nginx (nginx.conf): save it as its own site file and enable it.
# Debian / Ubuntu
sudo nano /etc/nginx/sites-available/example.com # paste the output
sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
# RHEL / Alma / Rocky / Fedora
sudo nano /etc/nginx/conf.d/example.com.conf
Apache (.htaccess): save it as .htaccess in the site's root folder. Apache only reads it if the virtual host allows overrides (AllowOverride All), and the modules named in the comments must be enabled, e.g. sudo a2enmod rewrite proxy proxy_http on Debian/Ubuntu.
Apache limitation: .htaccess can only proxy through mod_rewrite's [P] flag. Directives like ProxyPass and ProxyPreserveHost aren't allowed there at all. For full proxy control, put the rules in the virtual host config instead.
Creates correct redirects for the most common moves, including the differences between Nginx and Apache.
Open the Redirect Generator →https:// or trailing slash./old-page.https://.server {} blocks, added next to your existing ones. A single-path redirect is a location block that goes inside your existing server {} (the file is named location-snippet.conf to make that clear)..htaccess on the site being redirected. For a domain move, that's the old domain's server.www or the bare domain still needs a valid certificate for the name being redirected from. The output comments flag this.Check it worked: curl -I http://example.com should show 301 and the new Location:.
Gives you the Certbot command to get a free certificate, plus the matching Nginx or Apache SSL config.
Open the SSL Generator →example.com, www.example.com.*.example.com. It requires a DNS-01 challenge (a DNS TXT record), because Certbot can't prove ownership of a wildcard over HTTP.server {} block that listens on 443.SSLSessionCache, plus SSLStaplingCache when OCSP stapling is on) must go once in the main server config (httpd.conf or ssl.conf), outside any <VirtualHost>. Apache refuses to start if they're inside one. The second part goes inside your <VirtualHost *:443> block.Confirm renewals will work: sudo certbot renew --dry-run.
Adds the HTTP security headers most sites should send.
Open the Security Headers Generator →DENY blocks all framing. SAMEORIGIN lets only your own site frame its pages.strict-origin-when-cross-origin is the recommended default.server {} block. Gotcha: add_header doesn't inherit into a location block that has its own add_header lines, so repeat the headers there too or they silently disappear for those requests.<VirtualHost> or .htaccess. Requires mod_headers (sudo a2enmod headers on Debian/Ubuntu).Check them: curl -I https://example.com lists the headers your site sends.
Always test the config before reloading. A reload with a broken config can take your site down.
# Nginx
sudo nginx -t && sudo systemctl reload nginx
# Apache (Debian / Ubuntu)
sudo apachectl configtest && sudo systemctl reload apache2
# Apache (RHEL / Alma / Rocky / Fedora)
sudo apachectl configtest && sudo systemctl reload httpd
The && means the reload only happens if the test passes. If the test fails, the error names the file and line. Fix it, or restore your backup.
Your settings are stored in the page address after the #. That means:
# is never sent to any server. The SSL generator deliberately leaves your email out of the link.If a generated config doesn't work on your distro or setup, or you'd like another generator, email admin@proxyforge.tech.