NGINX VPS HostingWeb Server, Reverse Proxy and Cache
NGINX on a server where every config file is yours: serve static sites, proxy Node, Python or PHP apps, balance load across servers or cache responses. We install NGINX with Let's Encrypt on a hardened KVM VPS.
Full root & SSH NVMe storage Daily backups Anti-DDoS 99.9% uptime SLA 11 locations
-
Root and SSH access
Edit nginx.conf, add modules and reload at will.
-
Reserved vCores
worker_processes auto uses every core in your plan.
-
Dedicated IPv4 and IPv6
Listen on both, with anti-DDoS in front.
-
NVMe storage
Fast static files and on-disk proxy cache.
Why Run NGINX on Your Own VPS
Shared hosts expose NGINX through a panel, if at all. On a VPS you write the configuration, so every directive is available.
-
Any directive, any module
Rewrites, maps, rate limits, custom log formats and dynamic modules, with no panel in the way.
-
Proxy anything
Put Node.js, Python, Go, Java or Docker services behind one NGINX with HTTPS on every domain.
-
Caching where you need it
proxy_cache and fastcgi_cache store responses on NVMe and answer repeat requests without touching your app.
-
Load balancing
Spread traffic across several app servers with upstream blocks, with failed servers taken out automatically by passive health checks.
Common NGINX Roles on One Server
One NGINX process can play several roles at once, chosen per server block and location.
Incoming HTTPS request
-
TLS
HTTPS termination
Let's Encrypt certificates, HTTP/2 and redirects from HTTP to HTTPS.
-
Routing
server and location blocks
Per domain and path: serve a file, proxy, redirect or deny.
-
Cache
proxy_cache / fastcgi_cache
An optional response cache on disk, with keys and lifetimes you set.
-
Upstreams
Your apps or other servers
Node, PHP-FPM, Python, Docker containers or a pool of back-end servers.
Worth knowing
- Test every change with nginx -t, then reload: a reload does not drop open connections.
- Rate-limit login and API endpoints with limit_req.
- Only NGINX should listen on public ports; apps behind it bind to localhost.
- Let's Encrypt certificates renew automatically before they expire.
What You Can Run With NGINX
-
Static sites and SPAs
Hugo, Astro, Jekyll or React builds served directly, with try_files for client-side routing.
-
Reverse proxy for apps
One public entry point for Node, Python, Go or Java services on the same server.
-
Load balancer
Requests spread across several app servers.
-
Caching proxy
Responses from a slow back end or API cached to cut load and latency.
-
Redirect hub
Redirects, canonical domains and legacy URLs for many domains in one place.
-
PHP sites with PHP-FPM
The LEMP setup for WordPress, Laravel and other PHP software.
VPS Plans for NGINX
NGINX itself needs very little: VPS-1 serves static sites and proxies small apps easily. Size up for what runs behind it, and for port speed if you serve large files.
VPS-1
Small websites, APIs, bots and development servers.
- 2 vCores
- 4 GB RAM
- 40 GB NVMe
- 500 Mbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-2
Production apps, WordPress and online stores.
- 4 vCores
- 8 GB RAM
- 75 GB NVMe
- 1 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-3
Busy stores, SaaS products and several projects.
- 6 vCores
- 12 GB RAM
- 100 GB NVMe
- 2 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
VPS-4
High-traffic apps, large databases and agencies.
- 8 vCores
- 24 GB RAM
- 200 GB NVMe
- 3 Gbps
- Full root and SSH access
- Free initial stack installation
- Server hardening and firewall setup
- Daily backup of the previous 24 hours
- Unlimited traffic *
- Anti-DDoS protection
- Dedicated IPv4 and IPv6
- KVM virtualisation
* Unlimited traffic in Europe and North America. In Mumbai, Singapore and Sydney a monthly allowance applies (VPS-1 500 GB, VPS-2/VPS-3 1 TB, VPS-4 3 TB), then speed is limited to 10 Mbps until the next month.
Which Plan for Your NGINX Server
NGINX needs very little. Size for what sits behind it and for the port speed you need.
| Workload | Start with | Why |
|---|---|---|
| Static sites or a proxy for small apps | VPS-1 2 vCores · 4 GB RAM | 500 Mbps port and 2 vCores. |
| Proxy plus apps on the same server | VPS-2 4 vCores · 8 GB RAM | 1 Gbps port and 8 GB for the apps behind it. |
| Caching proxy or load balancer | VPS-3 6 vCores · 12 GB RAM | 2 Gbps port and 100 GB NVMe for the cache. |
| Large downloads or many domains | VPS-4 8 vCores · 24 GB RAM | 3 Gbps port and 200 GB NVMe. |
A starting point, not a limit: every plan upgrades in place, keeping your data, IP address and configuration.
NGINX on Shared Hosting or Your Own VPS?
On shared hosting NGINX belongs to the host. On a VPS every directive is yours.
| Feature | Shared hosting | NGINX VPS |
|---|---|---|
| nginx.conf access | None | Full |
| Reverse proxy to your apps | No | Yes |
| Caching and rate limits | Host defaults | Configured your way |
| Modules | Fixed | Any packaged or compiled module |
| Certificates | Free SSL by the host | Let's Encrypt or your own |
| Server administration | Done by the host | Yours, after our free setup |
| Explore Shared hosting | See Plans |
Adding a Site to Your NGINX Server
Each new domain is a server block, a test and a reload.
-
Create a server block
One file per site in sites-available.
-
Enable it
Link it into sites-enabled.
-
Test and reload
A reload keeps open connections alive.
-
Add HTTPS
A Let's Encrypt certificate that renews automatically.
# 1. Create a server block
sudo nano /etc/nginx/sites-available/app.example.com
# 2. Enable it
sudo ln -s /etc/nginx/sites-available/app.example.com /etc/nginx/sites-enabled/
# 3. Test and reload
sudo nginx -t && sudo systemctl reload nginx
# 4. Add HTTPS
sudo certbot --nginx -d app.example.com
Example commands; adjust names, paths and versions to your project. Deploying and maintaining your application is yours to do (or ask us for a quote).
Installed and Secured Before You Log In
The VPS is unmanaged: after handover the server is yours to run. Before that, our engineers do the first setup once, free, so you start from a hardened server with NGINX in place.
-
Choose a plan and location
Pick the resources you need and the datacentre closest to your users.
-
Tell us your NGINX setup
Versions, database and domain: at order or right after.
-
We install and secure it
Server hardened, NGINX installed and tested, HTTPS on your domain.
-
You take over with root
SSH access to a working server, ready for your code and data.
Your NGINX server
- NGINX from the OS or the official nginx.org repository
- Server blocks for your domains
- HTTPS with Let's Encrypt and automatic renewal
- HTTP to HTTPS redirects and HTTP/2
- A reverse proxy to your app, if you choose a stack at order
Yours to run after handover
- Ongoing server administration
- Application maintenance and updates
- Debugging your code
- Migrating existing sites or data
Not included in the free setup, but we can quote for it. No control panel by default: CloudPanel, HestiaCP or Virtualmin on request at no cost; cPanel and Plesk need their own licence.
Platform Specs and Locations
The same KVM platform on every plan; only the CPU, RAM, storage and port speed change.
| Virtualisation | KVM with reserved vCores and RAM |
|---|---|
| Storage | NVMe SSD on every plan |
| Network | Dedicated IPv4 and IPv6, 500 Mbps to 3 Gbps per plan |
| Operating systems | Ubuntu 26.04, 24.04 and 22.04 LTS · Debian 13, 12 and 11 · AlmaLinux · Rocky Linux · Fedora · FreeBSD |
| Access | Full root over SSH, key-based login |
| Backups | Automatic daily backup of the previous 24 hours; snapshots and longer retention on request |
| Protection | Always-on anti-DDoS mitigation |
| Availability | 99.9% uptime SLA |
Secured before we hand it over
- Non-root sudo user created for daily work
- SSH key login, password login for root disabled
- Firewall (UFW) open only for the ports you use
- Fail2ban blocking repeated login attempts
- Automatic security updates enabled
- Free Let's Encrypt SSL on your domain
- Timezone, swap and hostname configured
Asia-Pacific
- Mumbai
- Singapore
- Sydney
Europe
- London
- Limburg
- Roubaix
- Gravelines
- Strasbourg
- Milan
- Warsaw
North America
- Beauharnois
Availability per location changes with demand; we confirm your location before setup. In Mumbai, Singapore and Sydney each plan includes a monthly traffic allowance (VPS-1 500 GB, VPS-2 and VPS-3 1 TB, VPS-4 3 TB); beyond it, speed is limited to 10 Mbps until the next month.
Who an NGINX VPS Suits
-
Developers running several services
One public entry point with HTTPS in front of everything on the server.
-
Static and Jamstack sites
Fast delivery of static builds without paying for an app platform.
-
Teams scaling out
A load balancer or cache in front of several app servers.
Security and Performance for NGINX
Security
- Set server_tokens off and add security headers such as HSTS and X-Content-Type-Options.
- Deny access to hidden files such as .git and .env with a location rule.
- Use limit_req and limit_conn on login and API endpoints.
- Allow only TLS 1.2 and 1.3.
Performance
- worker_processes auto, with worker_connections sized for your traffic.
- Enable gzip and long expiry headers for versioned static files.
- Use keepalive connections to upstreams to save handshakes.
- Cache with proxy_cache, bypassing it for logged-in users.
Questions Before You Deploy
Not covered here? Ask an engineer before you order.
Get an NGINX Server You Configure
Pick a plan and tell us your domains and back ends. We hand over NGINX with HTTPS on a hardened server.