Build an nginx server block that proxies to your app (Flask, Node, Django) with HTTPS, headers and WebSockets.
Put nginx in front of your Flask, Django, Node.js or any HTTP app. Enter your domain and the port your app listens on to get a complete server block with an HTTP→HTTPS redirect, Let’s Encrypt certificate paths, correct proxy headers, optional WebSocket support, static files, gzip and security headers.
Domain, the address your app listens on (e.g. 127.0.0.1:5000), upload size and an optional static folder.
HTTPS, www redirect, WebSockets, gzip and security headers.
Copy the config and the install commands, then test with nginx -t and reload.
Production-style defaults: X-Forwarded headers, keepalive upstream, timeouts
Certbot-ready HTTPS block and redirect
WebSocket upgrade map when you need it
Static files served directly by nginx
Set the right file permissions for your web root and static files.
nginx handles HTTPS, slow clients, compression and static files efficiently and protects your app server, which only has to process application requests.
Host passes the original domain; X-Real-IP and X-Forwarded-For pass the visitor’s IP; X-Forwarded-Proto tells the app the request arrived over HTTPS so it builds correct URLs. In Flask, use ProxyFix to trust them.
Only if your app uses WebSockets (for example Socket.IO or live updates). It adds the Upgrade and Connection headers nginx needs to pass the connection through.
Use certbot: either certbot --nginx, or the webroot method shown in the install commands. The config uses the standard /etc/letsencrypt/live/<domain>/ paths.