NGINX Modules APT Repository for Ubuntu and Debian
100+ pre-built NGINX dynamic modules for Debian and Ubuntu, both amd64 and arm64. Set up the repo in seconds; apt install works instantly — every server starts a free 30-day trial.
10+ Exclusive Pro Modules. Only here.
In-house modules you will not find in Sury, Ondrej, or any other APT repo:
ipset-access,
nftset-access (honeypot + auto-ban),
cache-purge,
device-type (AI bot detection),
immerse (auto WebP/AVIF),
tuning,
cookie-flag,
spnego, and more.
Why a third-party APT repository?
The stock nginx package on Debian and Ubuntu ships a minimal module set. Dynamic modules that aren't in the base distro repos — ModSecurity v3, brotli, GeoIP2, JWT, TOTP, NJS extras, naxsi — typically force you to either build NGINX from source on every release, or pin a fork like OpenResty and accept its ecosystem boundaries.
A maintained third-party APT repository solves that. You stay on the stock distro nginx (or nginx.org's mainline), apt install nginx-module-* for what you need, and let apt upgrade handle ABI-compatible bumps as new NGINX point releases land. No rebuild step, no compiler on the box, no drift between fleet members.
That's the gap the GetPageSpeed NGINX modules APT repository fills, for 100+ modules across every category a production NGINX deployment needs.
Quick install example
# Bootstrap the repo (one-time, public, no sub needed):
curl -fsSLO https://extras.getpagespeed.com/release-latest.deb
sudo apt install ./release-latest.deb
sudo apt update
# Install instantly — starts the free 30-day trial:
sudo apt install nginx-module-modsecurity
# Module auto-symlinks into /etc/nginx/modules-enabled.
sudo systemctl reload nginx
No compilation | Plus / Pro / Ultra / Fleet | amd64 + arm64
Featured NGINX Modules
Popular modules from the repo, each one a single apt install away
ModSecurity WAF
nginx-module-modsecurityEnterprise-grade Web Application Firewall (WAF) for NGINX. Protect against SQL injection, XSS, and OWASP Top 10 vulnerabilities with the industry-standard ModSecurity v3 engine.
Brotli Compression
nginx-module-brotliGoogle's Brotli compression algorithm for 15-25% better compression than GZIP. Reduces bandwidth costs and improves page load times for text-based content. Static and dynamic variants.
GeoIP2 Database
nginx-module-geoip2MaxMind GeoIP2 integration for NGINX. Enable geo-targeting, region-based access control, and location-aware content delivery with accurate IP geolocation. HTTP and stream contexts.
JWT Authentication
nginx-module-jwtValidate JWT tokens at the edge for API authentication and stateless authorization. Drop-in alternative to NGINX Plus's commercial JWT module, no per-server license required.
Headers More
nginx-module-headers-moreSet, add, and clear arbitrary HTTP request and response headers from NGINX configuration. The OpenResty workhorse for fine-grained header manipulation without Lua.
Lua Scripting
nginx-module-luaEmbed Lua scripting directly in NGINX configuration. Complex routing logic, custom auth, dynamic content, and API gateways without recompiling NGINX. A complete OpenResty alternative.
And dozens more
A representative slice across auth, security, observability, streaming, and rate limiting
nginx-module-auth-totp
Time-based one-time password (TOTP) authentication at the NGINX edge
nginx-module-auth-ldap
LDAP authentication for NGINX with caching and TLS
nginx-module-zstd
Zstandard compression filter, faster decompression than Brotli
nginx-module-security-headers
Automatic security headers (HSTS, CSP, X-Frame-Options) with sane defaults
nginx-module-length-hiding
Randomize response size to defeat TLS metadata analysis
nginx-module-html-sanitize
On-the-fly HTML output sanitization with allowlist tag rules
nginx-module-cache-purge
Purge cached content selectively from NGINX proxy cache
nginx-module-dynamic-etag
Conditional GET for dynamic pages with computed ETag headers
nginx-module-immutable
Far-future Cache-Control: immutable for static assets
nginx-module-njs
Official NGINX JavaScript (njs) scripting language
nginx-module-naxsi
High-performance WAF with learning mode
nginx-module-rtmp
Turn NGINX into an RTMP / HLS / DASH streaming server
nginx-module-spnego-http-auth
Kerberos / SPNEGO authentication for intranet NGINX
nginx-module-push-stream
HTTP long-polling and SSE pub/sub messaging
nginx-module-graphite
Push NGINX metrics to a Graphite carbon receiver
How this APT repository compares
vs the Debian / Ubuntu options for getting NGINX dynamic modules onto your servers
| Approach | Module count | arm64 support | Cost |
|---|---|---|---|
| GetPageSpeed Extras (this repo) | 100+ modules | Yes, every codename | Subscription |
Stock distro nginx modules |
~10 modules | Yes | Free |
| Sury successors / single-maintainer APT repos | ~10 modules | Varies | Free |
| Build NGINX from source per host | Any module you compile | Yes | Engineering time |
| OpenResty bundle | OpenResty ecosystem only | Yes | Free |
Need the same modules on RHEL, SLES, Amazon Linux, or Fedora? The RPM tier ships the same catalog with the same names and versions.
Get started in 2 steps
Set up the repo in under a minute; install instantly on a free 30-day trial.
Bootstrap the repo (public, no sub needed)
One .deb drops the GPG key, sources list, and the apt pre-flight hook in one shot:
curl -fsSLO https://extras.getpagespeed.com/release-latest.deb
sudo apt install ./release-latest.deb
sudo apt update
Install modules — trial starts automatically
Pick what you need from the 100+ module catalog; the first install starts this server's free 30-day trial. ABI-matched to the stock nginx package on your codename. Subscribe to keep servers licensed past the trial.
sudo apt install \
nginx-module-modsecurity \
nginx-module-brotli \
nginx-module-geoip2
# Modules self-register via
# /etc/nginx/modules-enabled.
sudo systemctl reload nginx
One subscription covers both the RPM and DEB repos. Repo setup and the 30-day trial need no account at all.
Supported Distributions
Every supported codename has its own pool, with stable and (where available) mainline NGINX tracks
All packages built for amd64 and arm64. Mainline NGINX variants ship for Focal, Jammy, Noble, Bookworm, and Trixie.
Frequently Asked Questions
Everything you need to know about the APT NGINX modules repository
Repo setup, apt update, and installing standard modules need nothing up front: every install starts a free 30-day trial on this server, automatically. After the trial, unlicensed servers keep working but NGINX appends a small notice to HTML pages until an active GetPageSpeed subscription covers this server's IP. One subscription covers both RPM and DEB.
Pro modules and the NGINX-MOD build require the Pro plan or higher from the start.
The stock distro nginx package on each supported codename. For NGINX mainline, use the -mainline pool variant where available (Focal, Jammy, Noble, Bookworm, Trixie).
Each codename has its own pool, so module ABI compatibility against the distro NGINX (or the mainline variant) is handled per-release. You do not need to recompile or pin a custom NGINX build.
Ubuntu 18.04 (bionic), 20.04 LTS (focal), 22.04 LTS (jammy), and 24.04 LTS (noble). Debian 12 (bookworm) and 13 (trixie). Both amd64 and arm64 for every codename. Mainline NGINX support is shipped as a separate -mainline pool for distros that get it.
Yes. The RPM tier ships the same nginx-module-* catalog on Red Hat-family distros with the same names and versions. If your fleet mixes Debian-family and Red Hat-family hosts, you get one mental model, one set of upstream module versions, and one place to file bugs.
Every module rebuilds on each upstream tag and on each nginx point-release ABI bump. Builds run through a CI matrix across all six supported codenames on both amd64 and arm64, so a Bookworm arm64 host gets the same module versions as a Noble amd64 host on the same day.
Security fixes from upstream module repositories flow through within the same release cadence, and you can pin versions in /etc/apt/preferences.d/ if you need to.
NGINX-MOD is the GetPageSpeed-built NGINX with the most useful modules statically compiled in (active health checks, dynamic upstream API), plus performance patches and faster TLS. Drop-in replacement for the stock nginx package, same configuration format.
Now available as a DEB for Ubuntu 22.04 (jammy), Ubuntu 24.04 (noble), and Debian 12 (bookworm): apt-get install nginx-mod from the ${codename}-nginx-mod APT suite. It also brings the extended limit_req_rate units (r/h, r/d, r/w, r/M, r/Y) that stock NGINX does not support.
Open a ticket with the upstream repository URL and a one-line description. Most module requests land within a release cycle.
Ready to skip the source-build cycle?
Set up the APT repo in under a minute and install instantly on a free 30-day trial. 100+ modules, one sub covers RPM and DEB.
Subscribe Open the setup generator