Appearance
Nginx Web Server Configuration & Security Hardening
1. Production Nginx Server Block
nginx
server {
listen 443 ssl http2;
server_name portal.school.sch.id;
root /var/www/ScholarGate-SSO/public;
index index.php index.html;
ssl_certificate /etc/letsencrypt/live/portal.school.sch.id/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/portal.school.sch.id/privkey.pem;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ \.php$ {
include fastcgi_params;
fastcgi_pass unix:/var/run/php/php8.3-fpm.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
}
# Block access to sensitive system files
location ~ /\.(env|git|htaccess) {
deny all;
}
}2. Operations & Troubleshooting Runbook
| Issue / Symptom | Root Cause | Remediation Procedure |
|---|---|---|
| DAPODIK Connection Freeze | Remote DAPODIK web service offline | The asynchronous test automatically times out after 6 seconds. Verify DAPODIK local IP and port settings. |
| Zitadel OIDC Handshake Rejected | Mismatched Redirect URI or Client Secret | Update Redirect URI in Zitadel IAM admin console to match APP_URL/auth/callback. |
API Key Unauthorized (401) | Invalid X-API-Key or CORS domain block | Re-issue API key or add client domain to CORS origin whitelist. |