Skip to main content

Migrate From the ondrej nginx PPA to GetPageSpeed


by Danila Vershinin, July 5, 2026

The ondrej/nginx PPA deprecated its module packages at NGINX 1.28. Here is how to migrate to the GetPageSpeed APT repository and keep Brotli, Lua, ModSecurity and 130+ other modules on Debian and Ubuntu.

Read More...

NGINX ACME Module: Let’s Encrypt SSL Without Certbot


by Danila Vershinin, June 29, 2026

Issue and auto-renew Let’s Encrypt certificates directly inside NGINX with the nginx-module-acme module. No certbot, no cron jobs, no downtime, no Python.

Read More...

NGINX Abuse Guard Module: Auto-Ban Scanners and Bots


by Danila Vershinin, June 26, 2026

Stop vulnerability scanners and brute-force bots automatically. The NGINX abuse guard module bans clients by their 404 and 403 error rate, in-worker, with no fail2ban or log shipping.

Read More...

NGINX Microcaching: Varnish-Style Full-Page Caching Without a Third-Party Module


by Danila Vershinin, June 23, 2026

NGINX microcaching the Varnish way: serve dynamic pages from RAM via core proxy_cache on tmpfs, with stale-while-revalidate and request coalescing.

Read More...

Whitelist OpenAI IP Ranges in NGINX and fail2ban


by Danila Vershinin, June 2, 2026

If you want ChatGPT Search, GPTBot, and OpenAI’s on-demand fetcher to actually reach your content, the answer is not just “set Allow: / in robots.txt.” Modern NGINX deployments lean on rate limiting, GeoIP rules, and fail2ban; each of those will silently choke an OpenAI bot if you don’t deliberately whitelist OpenAI IP ranges in every […]

Read More...

NGINX limit_req Per Hour, Day, Week, Month with NGINX-MOD


by Danila Vershinin, May 4, 2026

Stock NGINX rejects rate=10r/h. The NGINX-MOD limit_req_rate patch adds hourly, daily, weekly, monthly, and yearly rate units so SREs can express quotas the way they actually talk about them.

Read More...

NGINX Dynamic TLS Records: An Honest Benchmark in 2026


by Danila Vershinin, April 29, 2026

We rebuilt nginx-mod with Cloudflare’s 2015 dynamic TLS records patch and benchmarked it in a controlled rig with random interleave, CPU pinning, and 200 cold connections per condition. The “50% p95 TTFB win” we expected collapsed under noise control. Here are the honest numbers and what to do instead.

Read More...

aws-lc NGINX in 2026: Why we still ship quictls


by Danila Vershinin, April 26, 2026

Why GetPageSpeed packages aws-lc on EL but still links nginx-mod against quictls in 2026: the honest current state of TLS for NGINX HTTP/3.

Read More...

NGINX slow_start: Gradual Upstream Ramp-Up Without Plus


by Danila Vershinin, April 22, 2026

NGINX Plus has slow_start to ramp traffic to freshly-live upstream servers from zero to full weight. Open-source NGINX has the struct field but never wired the scheduler. NGINX-MOD ships the missing scheduler logic and this article proves it with runtime measurements from a Rocky Linux VM.

Read More...

NGINX Immutable Module: Far-Future Cache-Control Headers


by Danila Vershinin, April 21, 2026

Cut wasted revalidation requests on versioned static assets. The NGINX immutable module emits RFC-compliant far-future Cache-Control headers with the immutable attribute, stale-while-revalidate, and stale-if-error in a single directive. This guide covers every directive, runtime-verified configs for Rocky Linux 10, the Magento 2 cache-busting pattern, and why it beats expires max.

Read More...