A server block (also called a virtual host) tells Nginx which hostname to answer and which folder holds the files. This article adds one site on a LochStudios KVM VPS. Credentials, the IPv4, and an out-of-band console sit on that server in the portal. Sign in at the portal, open the VPS service, and copy the login from there. Do not guess a hostname.
On Beginner and Standard shared hosting (cPanel) you do not edit Nginx. Open the hosting service, click Log in to cPanel, and add the name there: Add an Addon Domain.
If you also want MariaDB and PHP-FPM in the same sitting, use Install a LEMP stack after this site answers on HTTP.
A step is unclear? Open a support ticket and we will help.
Before you start
- Sign in at the portal, open the VPS service, and copy the IPv4.
- Connect over SSH with a sudo user, or
rooton a fresh box.
- Windows: Connect to your VPS via SSH from Windows
- macOS or Linux: Connect to your VPS via SSH from macOS or Linux
- Patch the image and use a sudo user for daily work: First steps on a new VPS.
- Install Nginx and confirm it answers on this IPv4: Install Nginx on Ubuntu/Debian.
If SSH from your computer will not connect, open the console on the same service. That session does not need port 22 from your network.
Do not add a server block on a box that already has Apache listening on port 80. One process owns that port. If you want Apache instead, see Set up Apache virtual hosts.
The rest of this article uses the Ubuntu and Debian layout (sites-available / sites-enabled). AlmaLinux and Rocky Linux use /etc/nginx/conf.d/ instead. That difference is at the end.
Point the name at this VPS
DNS for domains registered with us lives in the portal: Domains → the domain → DNS. AtlasDNS is the default. Do not send the name to a third-party DNS host.
Our nameservers:
ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
- Copy the VPS IPv4 from the server in the portal.
- On Domains → the domain → DNS, set an A record for
@(the apex) to that IPv4. - Point
wwwthe same way (another A, or a CNAME to the apex). - Save.
Full steps: Point your domain at your hosting. If the domain is registered elsewhere, set the three AtlasDNS nameservers first, then open a support ticket so we can put the zone on this account.
You can write the server block before the name resolves. Browsers will not show the site until the A record is this VPS IPv4.
Check from the VPS:
dig +short yourdomain.com A
dig +short www.yourdomain.com A
The answer must be this VPS IPv4. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.
Replace yourdomain.com with the real name everywhere below.
Create the site directories
sudo mkdir -p /var/www/yourdomain.com/html
sudo mkdir -p /var/www/yourdomain.com/logs
On Ubuntu and Debian, Nginx runs as www-data:
sudo chown -R www-data:www-data /var/www/yourdomain.com/html
sudo chmod -R 755 /var/www/yourdomain.com
On AlmaLinux or Rocky Linux, use nginx:nginx instead of www-data:www-data.
Add a test page
sudo bash -c 'echo "Welcome to yourdomain.com" > /var/www/yourdomain.com/html/index.html'
sudo chown www-data:www-data /var/www/yourdomain.com/html/index.html
Replace that file with your real site once the name answers.
Create the server block
sudo nano /etc/nginx/sites-available/yourdomain.com
Paste this (keep yourdomain.com as the real name):
server {
listen 80;
listen [::]:80;
server_name yourdomain.com www.yourdomain.com;
root /var/www/yourdomain.com/html;
index index.html index.htm;
access_log /var/www/yourdomain.com/logs/access.log;
error_log /var/www/yourdomain.com/logs/error.log;
location / {
try_files $uri $uri/ =404;
}
}
Save the file (Ctrl+O, Enter, Ctrl+X in nano).
server_name must match the hostnames you pointed at this IPv4. Extra names need their own A or CNAME first.
Enable the site
Ubuntu and Debian load whatever is linked under sites-enabled:
sudo ln -s /etc/nginx/sites-available/yourdomain.com /etc/nginx/sites-enabled/yourdomain.com
Leave the default site in place until this block answers. Then you can drop the welcome page:
sudo rm /etc/nginx/sites-enabled/default
Do not delete /etc/nginx/sites-available/default. Removing the symlink is enough.
Test and reload
sudo nginx -t
You should see syntax is ok and test is successful. Only then:
sudo systemctl reload nginx
Reload keeps current connections. Restart only if you have a reason.
Confirm it answers
From the VPS, send the hostname even if public DNS is still catching up:
curl -I -H "Host: yourdomain.com" http://127.0.0.1
You should get HTTP/1.1 200. Then browse to http://yourdomain.com (or the IPv4 if the name is not live yet). You should see the test page.
If curl on the server works but your browser does not, the host firewall is usually still closed on port 80.
Allow HTTP and HTTPS on UFW
UFW is the host firewall on our Ubuntu images. Allow SSH before you enable it, or you will cut off SSH from your computer. The console in the portal still works if that happens.
If UFW is already active:
sudo ufw allow 'Nginx Full'
sudo ufw status
Nginx Full is the package profile for ports 80 and 443.
If UFW is still inactive, do not run sudo ufw enable from this article. Set the defaults and allow SSH first: Set up a UFW firewall on Ubuntu.
On AlmaLinux or Rocky Linux, open the ports with firewalld if that service is running:
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
AlmaLinux and Rocky Linux
There is no sites-available / sites-enabled pair. Put the same server { ... } block in:
sudo nano /etc/nginx/conf.d/yourdomain.com.conf
Then sudo nginx -t and sudo systemctl reload nginx. The document root and chown user are nginx, not www-data.
Add HTTPS
There is no AutoSSL on a stock VPS. After the name points at this IPv4, issue TLS with Certbot (Let's Encrypt): Get a Free SSL Certificate with Certbot.
Do not hand-edit certificate paths until that article says to. Certbot can update this server block for you.
PHP on this site
This block serves static files only. For PHP-FPM, follow Install a LEMP stack and Install PHP and Common Extensions. Point index at index.php and add the location ~ \.php$ socket from those articles. Match the socket under /run/php/ on this image.
More than one site
Repeat the directory, file, symlink, nginx -t, and reload steps for each hostname. Each site needs its own folder and its own server_name. Point every name at this VPS IPv4 on Domains → the domain → DNS.
Disable a site without deleting it
sudo rm /etc/nginx/sites-enabled/yourdomain.com
sudo nginx -t
sudo systemctl reload nginx
The file under sites-available stays. Re-enable with the same ln -s command, then test and reload again.
If it did not work
Work through these in order:
nginx -tfailed. Fix the file it names before you reload.- Wrong A record.
dig +short yourdomain.com Amust be the IPv4 on the VPS in the portal. - The name is not in the block.
server_namemust match the hostname in the browser. - You still see the Nginx welcome page. The default site is winning. Confirm the symlink exists under
sites-enabled, reload, then removesites-enabled/defaultif this site should be the one that answers. - Port 80 is closed.
sudo systemctl is-active nginxshould printactive.sudo ufw statusshould allow 80/tcp (and 443/tcp once you want HTTPS). Address already in use. Something else (often Apache) holds port 80. Check withsudo ss -tlnp | grep -E ':80|:443'.
Still stuck? Open a support ticket. Tell us the VPS service, the domain, and what sudo nginx -t and sudo systemctl status nginx printed.
Need a VPS first? See VPS. Shared hosting with cPanel is at shared hosting.