LochStudios  /  Help Centre  /  VPS & Linux  /  Create an Nginx Server Block (Virtual Host) for Your Site

Create an Nginx Server Block (Virtual Host) for Your Site

Add an Nginx server block on your LochStudios KVM VPS so a name on AtlasDNS serves files from this server.

Updated

A server block (also called a virtual host) tells Nginx which hostname to answer and which folder holds the files. This article adds one site on a LochStudios KVM VPS. Credentials, the IPv4, and an out-of-band console sit on that server in the portal. Sign in at the portal, open the VPS service, and copy the login from there. Do not guess a hostname.

On Beginner and Standard shared hosting (cPanel) you do not edit Nginx. Open the hosting service, click Log in to cPanel, and add the name there: Add an Addon Domain.

If you also want MariaDB and PHP-FPM in the same sitting, use Install a LEMP stack after this site answers on HTTP.

A step is unclear? Open a support ticket and we will help.

Before you start

  1. Sign in at the portal, open the VPS service, and copy the IPv4.
  2. Connect over SSH with a sudo user, or root on a fresh box.

- Windows: Connect to your VPS via SSH from Windows
- macOS or Linux: Connect to your VPS via SSH from macOS or Linux

  1. Patch the image and use a sudo user for daily work: First steps on a new VPS.
  2. Install Nginx and confirm it answers on this IPv4: Install Nginx on Ubuntu/Debian.

If SSH from your computer will not connect, open the console on the same service. That session does not need port 22 from your network.

Do not add a server block on a box that already has Apache listening on port 80. One process owns that port. If you want Apache instead, see Set up Apache virtual hosts.

The rest of this article uses the Ubuntu and Debian layout (sites-available / sites-enabled). AlmaLinux and Rocky Linux use /etc/nginx/conf.d/ instead. That difference is at the end.

Point the name at this VPS

DNS for domains registered with us lives in the portal: Domains → the domain → DNS. AtlasDNS is the default. Do not send the name to a third-party DNS host.

Our nameservers:

ns1.atlasdns.net.au
ns2.atlasdns.net.au
ns3.atlasdns.net.au
  1. Copy the VPS IPv4 from the server in the portal.
  2. On Domains → the domain → DNS, set an A record for @ (the apex) to that IPv4.
  3. Point www the same way (another A, or a CNAME to the apex).
  4. Save.

Full steps: Point your domain at your hosting. If the domain is registered elsewhere, set the three AtlasDNS nameservers first, then open a support ticket so we can put the zone on this account.

You can write the server block before the name resolves. Browsers will not show the site until the A record is this VPS IPv4.

Check from the VPS:

dig +short yourdomain.com A
dig +short www.yourdomain.com A

The answer must be this VPS IPv4. Changes are often quick, but they can take a while to show everywhere. See DNS propagation explained.

Replace yourdomain.com with the real name everywhere below.

Create the site directories

sudo mkdir -p /var/www/yourdomain.com/html
sudo mkdir -p /var/www/yourdomain.com/logs

On Ubuntu and Debian, Nginx runs as www-data:

sudo chown -R www-data:www-data /var/www/yourdomain.com/html
sudo chmod -R 755 /var/www/yourdomain.com

On AlmaLinux or Rocky Linux, use nginx:nginx instead of www-data:www-data.

Add a test page

sudo bash -c 'echo "Welcome to yourdomain.com" > /var/www/yourdomain.com/html/index.html'
sudo chown www-data:www-data /var/www/yourdomain.com/html/index.html

Replace that file with your real site once the name answers.

Create the server block

sudo nano /etc/nginx/sites-available/yourdomain.com

Paste this (keep yourdomain.com as the real name):

server {
    listen 80;
    listen [::]:80;

    server_name yourdomain.com www.yourdomain.com;

    root /var/www/yourdomain.com/html;
    index index.html index.htm;

    access_log /var/www/yourdomain.com/logs/access.log;
    error_log /var/www/yourdomain.com/logs/error.log;

    location / {
        try_files $uri $uri/ =404;
    }
}

Save the file (Ctrl+O, Enter, Ctrl+X in nano).

server_name must match the hostnames you pointed at this IPv4. Extra names need their own A or CNAME first.

Enable the site

Ubuntu and Debian load whatever is linked under sites-enabled:

sudo ln -s /etc/nginx/sites-available/yourdomain.com /etc/nginx/sites-enabled/yourdomain.com

Leave the default site in place until this block answers. Then you can drop the welcome page:

sudo rm /etc/nginx/sites-enabled/default

Do not delete /etc/nginx/sites-available/default. Removing the symlink is enough.

Test and reload

sudo nginx -t

You should see syntax is ok and test is successful. Only then:

sudo systemctl reload nginx

Reload keeps current connections. Restart only if you have a reason.

Confirm it answers

From the VPS, send the hostname even if public DNS is still catching up:

curl -I -H "Host: yourdomain.com" http://127.0.0.1

You should get HTTP/1.1 200. Then browse to http://yourdomain.com (or the IPv4 if the name is not live yet). You should see the test page.

If curl on the server works but your browser does not, the host firewall is usually still closed on port 80.

Allow HTTP and HTTPS on UFW

UFW is the host firewall on our Ubuntu images. Allow SSH before you enable it, or you will cut off SSH from your computer. The console in the portal still works if that happens.

If UFW is already active:

sudo ufw allow 'Nginx Full'
sudo ufw status

Nginx Full is the package profile for ports 80 and 443.

If UFW is still inactive, do not run sudo ufw enable from this article. Set the defaults and allow SSH first: Set up a UFW firewall on Ubuntu.

On AlmaLinux or Rocky Linux, open the ports with firewalld if that service is running:

sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload

AlmaLinux and Rocky Linux

There is no sites-available / sites-enabled pair. Put the same server { ... } block in:

sudo nano /etc/nginx/conf.d/yourdomain.com.conf

Then sudo nginx -t and sudo systemctl reload nginx. The document root and chown user are nginx, not www-data.

Add HTTPS

There is no AutoSSL on a stock VPS. After the name points at this IPv4, issue TLS with Certbot (Let's Encrypt): Get a Free SSL Certificate with Certbot.

Do not hand-edit certificate paths until that article says to. Certbot can update this server block for you.

PHP on this site

This block serves static files only. For PHP-FPM, follow Install a LEMP stack and Install PHP and Common Extensions. Point index at index.php and add the location ~ \.php$ socket from those articles. Match the socket under /run/php/ on this image.

More than one site

Repeat the directory, file, symlink, nginx -t, and reload steps for each hostname. Each site needs its own folder and its own server_name. Point every name at this VPS IPv4 on Domains → the domain → DNS.

Disable a site without deleting it

sudo rm /etc/nginx/sites-enabled/yourdomain.com
sudo nginx -t
sudo systemctl reload nginx

The file under sites-available stays. Re-enable with the same ln -s command, then test and reload again.

If it did not work

Work through these in order:

  • nginx -t failed. Fix the file it names before you reload.
  • Wrong A record. dig +short yourdomain.com A must be the IPv4 on the VPS in the portal.
  • The name is not in the block. server_name must match the hostname in the browser.
  • You still see the Nginx welcome page. The default site is winning. Confirm the symlink exists under sites-enabled, reload, then remove sites-enabled/default if this site should be the one that answers.
  • Port 80 is closed. sudo systemctl is-active nginx should print active. sudo ufw status should allow 80/tcp (and 443/tcp once you want HTTPS).
  • Address already in use. Something else (often Apache) holds port 80. Check with sudo ss -tlnp | grep -E ':80|:443'.

Still stuck? Open a support ticket. Tell us the VPS service, the domain, and what sudo nginx -t and sudo systemctl status nginx printed.

Need a VPS first? See VPS. Shared hosting with cPanel is at shared hosting.

Related


Was this article helpful?

← Back to VPS & Linux