aws-lc NGINX in 2026: Why we still ship quictls
by Danila Vershinin, October 9, 2026
Technical Briefing: NGINX TLS Backends — aws-lc Support, quictls Backports, and the OpenSSL 3.5 LTS Migration The Problem NGINX’s TLS backend options have been constrained by two separate issues: compile-time incompatibilities with aws-lc, and the end-of-life status of the quictls fork that NGINX-MOD has historically shipped against. aws-lc header collisions. aws-lc and NGINX’s old QUIC shim collided at compile time in 2024. This has now been resolved: NGINX upstream added aws-lc support in 1.2…
Read More...NGINX Dynamic TLS Records: An Honest Benchmark in 2026
by Danila Vershinin, October 8, 2026
Technical Briefing: NGINX Dynamic TLS Records — An Honest Benchmark in 2026 The Problem NGINX’s default sslbuffersize is 16 KB, and each TLS record of that size straddles roughly 12 TCP segments. On a lossy link, if a single segment drops, the receiver cannot deliver any byte of that record until retransmission completes — adding at least one full RTT to TTFB on a connection mid-slow-start. Cloudflare’s 2015 ngxhttptlsdynsize patch (shipped in nginx-mod) was built to address this by ramping rec…
Read More...NGINX limit_req Per Hour, Day, Week, Month with NGINX-MOD
by Danila Vershinin, October 6, 2026
Technical Briefing: Sub-Hourly NGINX Rate Limits with NGINX-MOD The Problem Stock NGINX limitreqzone accepts only two rate units: r/s and r/m. A directive like rate=10r/h fails nginx -t with invalid rate, because the parser matches only those two suffixes and then attempts ngxatoi on the remainder. There is a second, quieter defect. Internally, upstream stores the rate as milli-requests-per-second: ctx->rate = rate 1000 / scale This silently truncates rates slower than roughly 4r/h to zero, so…
Read More...Whitelist OpenAI IP Ranges in NGINX and fail2ban
by Danila Vershinin, October 5, 2026
Technical Briefing: Keeping OpenAI Crawlers Unblocked — IP Feeds, NGINX Rate-Limit Bypass, and fail2ban Exemptions The Problem OpenAI publishes three crawler IP feeds — GPTBot, ChatGPT-User, and OAI-SearchBot — as JSON, each with a creationTime field and a prefixes array of ipv4Prefix entries. These ranges live in Microsoft Azure space and rotate, so any hard-coded list goes stale quickly. The practical failure mode is silent: robots.txt alone is insufficient. Rate limiting (limitreq/limitconn)…
Read More...NGINX Microcaching: Full-Page Caching Without Varnish
by Danila Vershinin, October 4, 2026
Technical Briefing: NGINX Microcaching — Varnish-Style Full-Page Caching with Stock Directives The Problem Full-page caching typically means standing up a second daemon (Varnish), a second port, and a second configuration language alongside NGINX. That operational overhead is real: an extra process to monitor, an extra config surface to maintain, and an extra hop in the request path. The question this technique answers is whether the common case — serving mostly-anonymous pages fast and shieldi…
Read More...zlib-ng vs zlib in NGINX: Benchmark and Methodology
by Danila Vershinin, October 3, 2026
Technical Briefing: zlib-ng vs Stock zlib Under NGINX — Measured, Not Assumed The Problem Vendor benchmarks for zlib-ng typically compress one big buffer in a single call against a synthetic corpus. NGINX does not work that way. It feeds the compressor in small chunks, opens a fresh deflate stream per response, and wraps output in a gzip header. The question this evaluation answers is whether zlib-ng actually beats stock zlib under NGINX’s real compression pattern — and the answer required buil…
Read More...NGINX Abuse Guard Module: Auto-Ban Scanners and Bots
by Danila Vershinin, October 2, 2026
Technical Briefing: NGINX Abuse Guard — Banning Scanners by Response Status, Inside the Worker The Problem Public-facing NGINX servers are continuously probed. Scanners request paths like /wp-login.php, /.env, and /phpmyadmin, producing walls of 404s. Bots hitting locked-down admin endpoints generate 403s. Credential-stuffing runs produce failed logins. The signal is asymmetry: legitimate visitors almost never burst errors, while abusive clients do. Existing tools address this imperfectly: limi…
Read More...NGINX Module Version Mismatch: When APT Lets It Through
by Danila Vershinin, October 1, 2026
Technical Briefing: NGINX Dynamic Module ABI Mismatch — Why apt-get upgrade Can Wedge Your Server The Problem NGINX dynamic modules are validated at load time, not install time. The loader in src/core/ngxmodule.c performs two checks in order: An exact version match: module->version != nginxversion (e.g. 1029008 = 1.29.8 vs 1031005 = 1.31.5). A signature string comparison against NGXMODULESIGNATURE. The signature encodes pointer/type sizes and feature bits (epoll, threads, file AIO, QUIC, SSL) b…
Read More...NGINX ACME Module: Let’s Encrypt SSL Without Certbot
by Danila Vershinin, September 30, 2026
Technical Briefing: Native ACME Support in NGINX via nginx-module-acme The Problem SSL certificate renewal for NGINX has traditionally depended on external tooling — Certbot, cron jobs, Python dependencies, and deploy hooks. That pipeline is a separate moving part from the web server itself, and it has to be maintained alongside it. The Fix NGINX now has a native ACME module (nginx-module-acme) that lets NGINX itself speak ACMEv2 to Let’s Encrypt. Certbot, cron jobs, Python dependencies, and de…
Read More...Trusted IP Lists for FirewallD, NGINX and fail2ban
by Danila Vershinin, September 29, 2026
Technical Briefing: Trusted IP List Packages for FirewallD, NGINX, and fail2ban The Problem Hardcoded allowlists for services like Stripe webhooks, Cloudflare, and Googlebot go stale silently. When vendors rotate their published IP ranges, existing allowlists stop matching — breaking integrations or blocking legitimate traffic without any obvious failure signal. The Fix The GetPageSpeed trusted-lists project packages current, officially published IP ranges for 30+ services as RPM packages. A dn…
Read More...