yum upgrades for production use, this is the repository for you.
Active subscription is required.
Technical Briefing: Migrating Off the Deprecated ondrej/nginx Module Packages
The Problem
At NGINX 1.28 (stable, announced April 2025), the maintainer of the ondrej nginx PPA dropped the mainline module packages. The stated reasons: recompiling every external module for each upstream patch release is unsustainable, and mainline adoption was low. Separately, Ubuntu’s nginx-extras stopped accepting new third-party modules long ago.
The practical consequence is that configs relying on load_module lines for Brotli, Lua, NAXSI, ModSecurity, VTS, or JWT can break on a routine apt upgrade — a new NGINX binary arrives with no matching modules.
The Fix
Migrate to the GetPageSpeed APT repository, which packages 130+ NGINX modules for Debian and Ubuntu on the same build infrastructure used for RHEL since 2016.
Setup
curl -fsSLO https://extras.getpagespeed.com/release-latest.deb
sudo apt install ./release-latest.deb
sudo getpagespeed-extras-channel stable
sudo apt update
sudo apt install nginx nginx-module-brotli nginx-module-lua
Key Behavioral Difference
Each nginx-module-* package drops an auto-load file into /etc/nginx/modules-enabled/, so no load_module directive is needed — unlike hand-compiled modules. Manually copied load_module lines (e.g. load_module modules/ngx_http_brotli_filter_module.so;) must be deleted, or reload fails with "module ... is already loaded."
Inventory Before Changing Anything
nginx -V 2>&1 | tr ' ' '\n' | grep -- --add
grep -R 'load_module' /etc/nginx/
dpkg -l | grep -E 'nginx'
Removing the Old Source
sudo add-apt-repository --remove ppa:ondrej/nginx
or:
sudo rm -f /etc/apt/sources.list.d/ondrej-*nginx*.list /etc/apt/sources.list.d/*ondrej*.list
sudo apt update
nginx.conf and site configs stay untouched — only the package source changes.
Repository Mechanics
The release package manages a signed deb822 source under /etc/apt/sources.list.d/ and exposes stable, mainline, and nginx-mod channels, switched via getpagespeed-extras-channel <channel> rather than hand-editing files. APT resolves the GetPageSpeed build (e.g. nginx 1.30.3-15~gps1+deb12+stable) as the install candidate.
Verification
sudo nginx -t
sudo systemctl reload nginx
curl -sI -H 'Accept-Encoding: br' https://your-site/ | grep -i content-encoding
A content-encoding: br response confirms Brotli loaded and is compressing.
Common Module Swaps
| Old | New |
|---|---|
ngx_brotli |
nginx-module-brotli |
lua-nginx-module (OpenResty) |
nginx-module-lua |
ModSecurity-nginx |
nginx-module-modsecurity |
nginx-module-vts |
nginx-module-vts |
headers-more-nginx-module |
nginx-module-headers-more |
ngx_http_geoip2_module |
nginx-module-geoip2 |
njs |
nginx-module-njs |
APT Pin to Prevent Distro NGINX From Winning Future Upgrades
sudo tee /etc/apt/preferences.d/99-getpagespeed-nginx <<'EOF'
Package: nginx*
Pin: origin extras.getpagespeed.com
Pin-Priority: 1001
EOF
Priority 1001 lets APT hold or downgrade to the GetPageSpeed package, keeping binary and modules ABI-matched.
Channel Switching
sudo getpagespeed-extras-channel mainline && sudo apt update
Unlike the deprecated ondrej/nginx-mainline PPA, both channels keep the full module set built and ABI-matched, so mainline doesn’t cost Brotli, Lua, or ModSecurity.
Caveats and Q&A
- The
ondrej/phpPPA is separate — leave it in place; only the NGINX source is removed. - Downtime is limited to the package replacement plus one
systemctl reload nginx; run in a maintenance window for critical traffic and keep a copy of/etc/nginx. - Rollback: re-add the previous source and
sudo apt install --allow-downgrades nginx=<previous-version>; restoring config is a file copy and reload, no data touched. - Supported: Ubuntu 18.04–24.04 and Debian 12–13, on both
amd64andarm64. - Adding the repo and running
apt updateare free; browsing the catalog needs no account. Installing modules requires an active per-server subscription tied to the server IP; one subscription covers both RPM and APT repositories, so mixed RHEL-and-Debian fleets stay on one plan.
Post-Migration Monitoring
GetPageSpeed Amplify runs scheduled gixy scans across every host and ties findings to live NGINX runtime metrics. It is drop-in compatible with the deprecated nginx-amplify-agent (EOL January 2026).
Read the full article: Migrate From the ondrej nginx PPA to GetPageSpeed
