All Tools View Categories About Contact Privacy

Nginx Upstream Block Config Generator

Build an upstream pool with servers and active health checks.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your upstream block will appear here.
-
lines
-
blocks

About Nginx Upstream Block Config Generator

An upstream block is where nginx defines a pool of backends, but a hand-written one drifts into errors fast: a server line with no port, a method pasted in the wrong place, weights that do nothing, or an active health_check that is missing the URI it needs. The Nginx Upstream Block Config Generator builds a clean upstream with multiple servers, keepalive and an optional health_check, distinct from the combined load-balancer tool, and validates its own output.

At the heart of the configuration are a handful of directives. upstream declares a named pool of backend servers. server (in upstream) adds one backend host:port, optionally with weight or other params. ip_hash / least_conn / hash selects the balancing algorithm applied across the pool. keepalive keeps idle connections to backends open for reuse. health_check actively probes a URI to mark backends up or down (NGINX Plus / healthcheck module). weight biases traffic toward a backend relative to the others. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. A server line without a port cannot be parsed, so the generator rejects it with the offending line quoted. An invalid upstream name (starting with a digit, say) is rejected because nginx identifiers must start with a letter or underscore. A health_check without a leading-slash URI is meaningless, so the tool requires one when health checks are on. Keepalive must be a positive integer, so zero or negative values are rejected. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • upstream - declares a named pool of backend servers.
  • server (in upstream) - adds one backend host:port, optionally with weight or other params.
  • ip_hash / least_conn / hash - selects the balancing algorithm applied across the pool.
  • keepalive - keeps idle connections to backends open for reuse.
  • health_check - actively probes a URI to mark backends up or down (NGINX Plus / healthcheck module).
  • weight - biases traffic toward a backend relative to the others.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Give the upstream a valid identifier name.
  2. Pick a balancing method (or leave round robin).
  3. List each backend on its own line as host:port, with optional weight.
  4. Toggle the active health_check and set its URI, interval, fails and passes.
  5. Set the upstream keepalive count.
  6. Click Generate (or Load sample) and review the block.
  7. Reference the upstream from a proxy_pass and run nginx -t.

Examples

Example 1 - Weighted pool two backends, one at weight=2, least_conn method, health check on.

Example 2 - No health check health_check disabled for environments without the module.

Example 3 - ip_hash sticky-by-client-IP upstream with two servers.

Example 4 - Bad server line a line with no port is reported and quoted before generation.

Example 5 - Invalid name a name starting with a digit is rejected.

Benefits

  • Correct upstream block emitted on its own.
  • Per-server validation with the bad line quoted.
  • Optional active health_check with validated URI.
  • keepalive and method in the right context.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

How is this different from the load balancer tool?
That tool emits both the upstream and a proxying server block; this one focuses purely on the upstream pool with active health checks.
What does health_check need?
The health_check directive requires NGINX Plus or the open-source healthcheck module; otherwise remove it or use proxy_next_upstream.
What does keepalive do here?
It keeps idle connections to backends open, improving performance for repeated proxy calls.
Can I add weights?
Yes - append weight=n to a server line and it is passed through unchanged.
Which method should I use?
Round robin is the default; least_conn spreads load by busyness; ip_hash sticks a client to a backend.
Is the output validated?
Yes - it is re-parsed by a built-in tokenizer before display.
Where does it go?
Reference the upstream name from a proxy_pass in your server block, then run nginx -t.
Is anything uploaded?
No. All generation happens in your browser.