Skip to content

Nginx Web Server Configuration & Security Hardening ​

1. Production Nginx Server Block ​

nginx
server {
    listen 443 ssl http2;
    server_name portal.school.sch.id;
    root /var/www/ScholarGate-SSO/public;

    index index.php index.html;

    ssl_certificate /etc/letsencrypt/live/portal.school.sch.id/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/portal.school.sch.id/privkey.pem;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location ~ \.php$ {
        include fastcgi_params;
        fastcgi_pass unix:/var/run/php/php8.3-fpm.sock;
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    }

    # Block access to sensitive system files
    location ~ /\.(env|git|htaccess) {
        deny all;
    }
}

2. Operations & Troubleshooting Runbook ​

Issue / SymptomRoot CauseRemediation Procedure
DAPODIK Connection FreezeRemote DAPODIK web service offlineThe asynchronous test automatically times out after 6 seconds. Verify DAPODIK local IP and port settings.
Zitadel OIDC Handshake RejectedMismatched Redirect URI or Client SecretUpdate Redirect URI in Zitadel IAM admin console to match APP_URL/auth/callback.
API Key Unauthorized (401)Invalid X-API-Key or CORS domain blockRe-issue API key or add client domain to CORS origin whitelist.