Nginx
The default reverse proxy in front of most web stacks: virtual hosts, upstreams and load balancing, TLS termination, caching and rate limiting. Interviewers ask about Nginx because reading and writing its config is an everyday backend task.
on this pageshowhide
explore
- Config Model and Contexts5 questions
- Server and Location Blocks5 questions
- Reverse Proxy and Upstream6 questions
- TLS Termination6 questions
- Caching5 questions
- Rate Limiting and Security6 questions
questions
page 2 of 2In nginx, a `location /search?q=` block never matches anything, and the value logged as `$request_uri` often differs from the path a location matched. What string does nginx actually compare `location` prefixes and regexes against?
basics
~20 sNginx matches locations against the normalized request path: percent-decoded, with dot and dot-dot segments resolved and repeated slashes merged, and with the query string removed. That value is $uri; $request_uri holds the raw original line including the query.
You set `ssl_stapling on;` on an nginx server, but `openssl s_client -status` reports no OCSP response. What else does nginx need before it can staple, and why is the first handshake after a reload usually unstapled?
basics
~20 snginx needs a resolver to look up the OCSP responder named in the certificate, and ssl_trusted_certificate when ssl_stapling_verify is on. It fetches the response lazily on demand, so the earliest handshakes after a reload carry no staple.
You inherit an nginx deployment where 60 virtual hosts are hand-edited into a single 3,000-line nginx.conf. How would you restructure that configuration, and how would you make changing it safe?
basics
~20 sSplit it into one file per virtual host pulled in by include, lift genuinely shared settings once into the http context so inheritance does the repetition, factor recurring fragments into snippets, and gate every change on a rendered nginx -t in CI with a scripted reload.
showing 31–33 of 33