Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.

MITAuto-check passedDevOps & Cloud

Install Nginx

skills CLI
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/nginx .claude/skills/nginx && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nginx
GitHub stars
338
Token cost
~1.9k tokens
SKILL.md length
666 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.

  • Editing nginx.conf
  • SKILL.md covers Resolve upstreams through…, Upstreams by service name,…, Structured JSON logs to… and Health and status on separate,…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Security headers

What it does

Nginx is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends. Use when writing or editing nginx.conf, server blocks, upstreams, SSL, proxy caching, security headers, structured logging, or stream (TCP/UDP) proxying. Covers the Docker-DNS resolver that keeps upstreams from going stale, separate access-controlled health ports, the stream-block placement gotcha, and headers that must be sent on errors too. Kept separate from the docker and docker-swarm skills.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with NGINX and Docker. The repository describes itself as: The definitive starting point for Claude Code projects. Based on Claude Code Mastery Guides V1-V5. The licence is MIT.

When your agent uses it

  • Editing nginx.conf
  • Security headers
  • Structured logging
  • Stream (TCP/UDP) proxying

Example prompts

  • “/nginx”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 61fbb99. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are nginx).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nginx loads about 1.9k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 666 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~130
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TheDecipherist/claude-code-mastery-project-starter-kit at commit 61fbb99, republished under its MIT licence (© TheDecipherist). 666 words, ~1,872 tokens.

Download SKILL.mdSave it as .claude/skills/nginx/SKILL.md (or your agent's skills folder).
name
nginx
description
Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends. Use when writing or editing nginx.conf, server blocks, upstreams, SSL, proxy caching, security headers, structured logging, or stream (TCP/UDP) proxying. Covers the Docker-DNS resolver that keeps upstreams from going stale, separate access-controlled health ports, the stream-block placement gotcha, and headers that must be sent on errors too. Kept separate from the docker and docker-swarm skills.
when_to_use
- Writing or editing nginx.conf, a server block, an upstream, or an SSL block - Putting NGINX in front of containerized services as a reverse proxy…

NGINX: Production Reverse-Proxy Config

Aimed at NGINX in front of containerized backends. The defaults are fine for a static site, these are the things that bite in production.

Resolve upstreams through Docker DNS with a short TTL

By default NGINX resolves an upstream host once, at startup, and caches the IP forever. In Docker that IP belongs to a container that will be replaced, so the proxy keeps sending traffic to a dead address. Point NGINX at Docker's internal DNS and force re-resolution:

nginx
http {
    resolver 127.0.0.11 ipv6=off valid=10s;   # Docker DNS, re-resolve every 10s
}

valid=10s is what makes NGINX pick up the new container after a restart or scale. This is the NGINX side of "never hardcode IPs", see the docker-swarm skill for the principle.

Upstreams by service name, with keepalive

Reference backends by service name, never IP. Reuse connections with keepalive, which needs HTTP/1.1 and a cleared Connection header:

nginx
upstream backend {
    server backend-service:8080;
    keepalive 32;
}
server {
    location / {
        proxy_pass http://backend;
        proxy_http_version 1.1;
        proxy_set_header Connection "";
    }
}

Structured JSON logs to stdout/stderr

Log JSON so an aggregator can parse it, and write to stdout/stderr so Docker's logging driver captures it. Never log to a file inside the container.

nginx
log_format json_log escape=json '{'
    '"time":$msec,"method":"$request_method","status":$status,'
    '"uri":"$request_uri","rt":$request_time,'
    '"upstream":"$upstream_addr","cache":"$upstream_cache_status",'
    '"client":"$remote_addr","xff":"$http_x_forwarded_for"'
'}';
access_log /dev/stdout json_log;
error_log  /dev/stderr warn;

Health and status on separate, access-restricted ports

Keep health checks and metrics off the production port: different access control, no log noise, no interference with real traffic. Restrict to internal networks and turn off access logging.

nginx
server {                          # load balancer health check
    listen 82;
    allow 10.0.0.0/8; allow 172.16.0.0/12; allow 127.0.0.1; deny all;
    location /health { access_log off; return 200 "OK"; }
}
server {                          # stub_status for Prometheus/Datadog
    listen 81;
    allow 10.0.0.0/8; allow 127.0.0.1; deny all;
    location /nginx_status { stub_status on; }
}

A deep health check that proxies an upstream's own /health is worth a third port when a service's liveness depends on its backend being reachable.

Stream (TCP/UDP) blocks go OUTSIDE the http block

Proxying a non-HTTP protocol like MongoDB or a database uses the stream module, which is a top-level block, not inside http. Putting it inside http is a silent misconfiguration. HTTP services (an Elasticsearch REST proxy, say) stay inside http.

nginx
load_module modules/ngx_stream_module.so;
include /etc/nginx/mongo.conf;    # stream { ... }  OUTSIDE http
http {
    include /etc/nginx/elasticsearch.conf;   # HTTP proxy, INSIDE http
}

SSL and security headers

Modern protocols and ciphers, session cache, OCSP stapling. When certs come from Docker secrets they are mounted at /run/secrets/<name>:

nginx
ssl_certificate     /run/secrets/server_pem;
ssl_certificate_key /run/secrets/server_key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_session_cache shared:SSL:60m;
ssl_stapling on; ssl_stapling_verify on;

Send security headers with always so they are present on error responses too, not just 2xx/3xx:

nginx
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
Show full SKILL.md (349 more words)Show less

Always add a Content-Security-Policy, this is the one that gets skipped

CSP is the highest-value security header and the one almost always left out. The others harden edges; CSP is the primary defense against XSS and content injection, it tells the browser which sources are allowed to load scripts, styles, images, and frames, so an injected <script> from an attacker simply doesn't execute. A site without a CSP has no second line of defense once markup injection gets through. Add it by default, do not wait to be asked.

default-src 'self' alone is technically a CSP but it breaks most real apps (CDNs, inline styles, analytics) and lulls you into thinking you're covered, so set the directives explicitly:

nginx
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;

Rules that matter:

  • Avoid 'unsafe-inline' and 'unsafe-eval' in script-src. They re-open the XSS hole CSP exists to close. If you have inline scripts, use a per-request nonce or a hash, not a blanket unsafe allow.
  • object-src 'none' and base-uri 'self' are free wins that block plugin and base-tag injection. Set them every time.
  • frame-ancestors controls who can iframe you and supersedes X-Frame-Options, so put your clickjacking policy here.
  • Roll out with report-only first. A too-strict CSP breaks the page silently. Ship Content-Security-Policy-Report-Only to collect violations without enforcing, watch what trips, tighten, then promote to the enforcing header. The real policy is app-specific and is built by tuning, not guessed in one line.

Proxy caching for read-heavy upstreams

Cache GET/HEAD, and serve stale on upstream error or timeout so a backend hiccup doesn't reach users:

nginx
proxy_cache es_cache;
proxy_cache_methods GET HEAD;
proxy_cache_valid 200 1m;
proxy_cache_key $host$uri$args;
proxy_cache_use_stale updating error timeout http_500 http_502 http_503 http_504;
proxy_hide_header X-Powered-By;
add_header X-Proxy-Cache $upstream_cache_status;

Watch line endings in config files

NGINX config copied in with Windows CRLF line endings can fail to parse or behave oddly in a Linux container, which is why production NGINX images often run dos2unix on the configs at build time. If nginx -t reports something that makes no sense, check the line endings first, see the dev-pitfalls skill.


This skill is built to grow. Add a directive when a real production NGINX problem has a stable, defensible fix. ModSecurity/WAF setup (build as a dynamic module, load_module) is deep enough to deserve its own section when needed.

© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/nginx of TheDecipherist/claude-code-mastery-project-starter-kit.

Open the folder on GitHubat commit 61fbb99

Compare with similar skills

Nginx next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nginx compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nginx this skillTheDecipherist/claude-code-mastery-project-starter-kit338—~1.9kAutomated safety check: PassMIT
Odoo Docker Deploymentsickn33/agentic-awesome-skills47k2 repos~1.2kAutomated safety check: NotesMIT
Memstack Deployment Hetzner Setupcwinvestments/memstack423—~4.1kAutomated safety check: NotesProprietary
Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package187—~2.4kAutomated safety check: NotesMIT
Deploy Detect Skilljiushiwon/wg-skills110—~1.1kAutomated safety check: NotesApache-2.0
Super Deploy Skillsjiushiwon/wg-skills110—~716Automated safety check: PassApache-2.0

Similar skills

  • Odoo Docker Deployment

    sickn33/agentic-awesome-skills

    Production-ready Docker and docker-compose setup for Odoo with PostgreSQL, persistent volumes, environment-based configuration, and Nginx reverse proxy.

    47k GitHub starsUsed in 2 repos~1.2k tokens
    DevOps & CloudAuto-check: notes
  • Memstack Deployment Hetzner Setup

    cwinvestments/memstack

    A skill your agent uses when the user says 'Hetzner', 'VPS setup', 'server provisioning', 'deploy to VPS', 'hetzner-setup', 'cloud server', or needs to provision, harden, and deploy applications to…

    423 GitHub stars~4.1k tokensUpdated 10 days ago
    DevOps & CloudAuto-check: notes
  • Frappe Ops Deployment

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.

    187 GitHub stars~2.4k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes
  • Deploy Detect Skill

    jiushiwon/wg-skills

    用于自动检测项目根目录的技术栈(语言、Web 框架、前端框架、数据库、缓存/消息),并生成标准化的「项目部署画像 deploy-profile.md」,作为 server-setup-skill、static-nginx-skill、deploy-native-skill、deploy-docker-skill 共享的事实来源。当用户说「部署检测」「detect…

    110 GitHub stars~1.1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Super Deploy Skills

    jiushiwon/wg-skills

    一键部署技能套件(父入口)。覆盖项目技术栈检测、服务器环境检测与依赖安装、前端 Nginx 托管、原生部署脚本、Docker 部署。当用户说「部署项目」「一键部署」「deploy」「帮我上线」「发布到服务器」时触发,并按意图路由到子技能 deploy-detect-skill / server-setup-skill / static-nginx-skill /…

    110 GitHub stars~716 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Devops Agent

    LeoYeAI/openclaw-master-skills

    Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.

    2.2k GitHub stars~5.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes

More from TheDecipherist/claude-code-mastery-project-starter-kit

All 24 skills in this repo
  • Create Service

    TheDecipherist/claude-code-mastery-project-starter-kit

    Scaffold a new microservice that follows the project's server/handlers/adapters architecture.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check: notes
  • CSS Structure

    TheDecipherist/claude-code-mastery-project-starter-kit

    Where CSS should live. An agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.

    338 GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Docker

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker best practices for writing Dockerfiles, Compose files, and Swarm stacks.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check: notes
  • Docker Swarm

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker Swarm deployment rules: what changes when a compose file goes from a single node to a multi-node Swarm.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Backups

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB backup and restore practices that the documentation gets wrong.

    338 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Replica Sets

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Nginx

What does Nginx do?

Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends. Nginx is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.

When should I use Nginx?

Nginx fits situations like: editing nginx.conf; security headers; structured logging; stream (TCP/UDP) proxying.

How do I install Nginx in Claude Code?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a claude-code`. Or copy the skill folder (.claude/skills/nginx in TheDecipherist/claude-code-mastery-project-starter-kit) into .claude/skills/nginx in your project. Claude Code loads it when a task matches its description.

How do I install Nginx in Codex?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a codex`. Or copy the skill folder (.claude/skills/nginx in TheDecipherist/claude-code-mastery-project-starter-kit) into .agents/skills/nginx in your project. Codex loads it when a task matches its description.

Can I use Nginx in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nginx, .gemini/skills/nginx, .github/skills/nginx and .opencode/skills/nginx in your project.

What does Nginx need to run?

SKILL.md names no scripts, command-line tools or credentials: Nginx is instructions for the agent only. Our summary lists: Docker.

Does Nginx access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nginx safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nginx use?

Nginx is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nginx use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nginx?

Skills that share tags, products or a category with Nginx: Odoo Docker Deployment (sickn33/agentic-awesome-skills, 47k stars), Memstack Deployment Hetzner Setup (cwinvestments/memstack, 423 stars), Frappe Ops Deployment (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Deploy Detect Skill (jiushiwon/wg-skills, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nginx?

TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery-project-starter-kit, which has 338 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on June 29, 2026.

Source: TheDecipherist/claude-code-mastery-project-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.