Blog
4 min read

What Is Nginx? The Web Server in Front of Half the Internet

Nginx ("engine-x") is a web server that serves files, forwards requests to your app, handles HTTPS and balances load. What it does, what a basic config looks like, where the files live, the commands you'll need, and whether you need it at all.

Nginx (pronounced "engine-x") is a web server — software that listens for requests from browsers and decides how to answer them. It's one of the most widely used pieces of software on the internet, and if you deploy an app to your own server, you'll probably meet it.

What it does

Nginx usually does one or more of these jobs:

  1. Serves static files. HTML, CSS, JavaScript and images, straight from a folder, very fast.
  2. Acts as a reverse proxy. It receives requests on ports 80/443 and forwards them to your app running on, say, port 3000. Your app never faces the internet directly. (Reverse proxies explained)
  3. Handles HTTPS. It holds the SSL certificate and decrypts traffic, so your app doesn't have to.
  4. Balances load between several copies of your app. (What is a load balancer?)
  5. Adds the extras: compression, caching, redirects, rate limiting, security headers.

Why not let the app handle requests directly?

You could — Node.js, Python and others can listen on a port. But Nginx is better at the boring, important parts: serving files efficiently, handling thousands of slow connections, terminating TLS, and restarting nothing when your app restarts. It also lets one server host several apps on different domains.

What a basic config looks like

A typical config for a Node app with HTTPS:

server {
    listen 80;
    server_name myapp.com www.myapp.com;
    return 301 https://myapp.com$request_uri;
}

server {
    listen 443 ssl;
    server_name myapp.com;

    ssl_certificate     /etc/letsencrypt/live/myapp.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/myapp.com/privkey.pem;

    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Read it as: "Redirect plain HTTP to HTTPS. For HTTPS requests to myapp.com, use this certificate and forward everything to the app on port 3000, passing along the original host and visitor IP."

For a single-page React app served as static files:

location / {
    root /var/www/myapp/dist;
    try_files $uri $uri/ /index.html;
}

That try_files line is what stops 404s when refreshing a page.

Where things live (on Ubuntu/Debian)

Path Contains
/etc/nginx/nginx.conf Main config
/etc/nginx/sites-available/ One file per site
/etc/nginx/sites-enabled/ Links to the sites that are switched on
/var/log/nginx/access.log Every request
/var/log/nginx/error.log Problems — check here first

Commands you'll need

sudo nginx -t                    # test the config for errors — always do this first
sudo systemctl reload nginx      # apply changes without dropping connections
sudo systemctl status nginx      # is it running?
sudo tail -f /var/log/nginx/error.log

Always run nginx -t before reloading. A typo in the config and a restart can take every site on the server down.

Common errors

  • 502 Bad Gateway — Nginx couldn't reach your app. Is it running on the port in proxy_pass? (502 Bad Gateway)
  • 504 Gateway Timeout — your app took too long. Look for slow requests.
  • 413 Request Entity Too Large — uploads bigger than 1 MB by default. Raise client_max_body_size.
  • WebSockets don't connect — they need extra Upgrade and Connection headers in the proxy config.

Nginx vs Caddy vs Traefik

Caddy gets HTTPS certificates automatically with a much shorter config — great for small setups. Traefik configures itself from Docker labels — good for container-heavy setups. Nginx is the most widely documented and battle-tested. All three do the job; we compare them in reverse proxies explained.

Do you need it?

If you host on Vercel, Netlify or a managed platform, it's handled for you (often with Nginx or something like it underneath). If you run your own VPS, you need something in front of your app — Nginx or Caddy are the usual picks. (Deploy a Node app to a VPS)

The summary

  • Nginx serves files, forwards requests to your app, and handles HTTPS.
  • Configs are server blocks with location rules.
  • nginx -t before every reload; errors are in /var/log/nginx/error.log.
  • 502 means it can't reach your app, not that Nginx is broken.

EasySpawn puts a managed proxy in front of your app with automatic HTTPS on your own domain — no Nginx configs to write or certificates to renew. See how it works or join the waitlist.

Related: Reverse Proxies Explained · What Is a Server? · 502 Bad Gateway · How Automatic SSL Actually Works

Keep reading