user www-data; worker_processes auto; pid /run/nginx.pid; error_log /var/log/nginx/error.log warn; include /etc/nginx/modules-enabled/*.conf; events { worker_connections 2048; multi_accept on; } http { include /etc/nginx/mime.types; default_type application/octet-stream; # Standard combined-style format: CrowdSec parses it out of the box. log_format main '$remote_addr - $remote_user [$time_local] ' '"$request" $status $body_bytes_sent ' '"$http_referer" "$http_user_agent"'; access_log /var/log/nginx/access.log main; sendfile on; tcp_nopush on; tcp_nodelay on; keepalive_timeout 65; server_tokens off; types_hash_max_size 2048; client_max_body_size 100m; client_body_buffer_size 128k; client_header_timeout 60; client_body_timeout 60; send_timeout 60; open_file_cache max=10000 inactive=30s; open_file_cache_valid 60s; open_file_cache_min_uses 2; open_file_cache_errors on; gzip on; gzip_comp_level 5; gzip_min_length 1024; gzip_vary on; gzip_types text/plain text/css text/xml application/json application/javascript application/x-javascript image/svg+xml application/rss+xml text/xml+rss; reset_timedout_connection on; # Zone defined here, enforced per-location where needed: limit_req_zone $binary_remote_addr zone=main_limit:10m rate=10r/s; include /etc/nginx/conf.d/*.conf; include /etc/nginx/sites-enabled/*; }