LimeSurvey nginx example configuration
From LimeSurvey Manual
Nginx configuration example for LimeSurvey
Below is an example configuration for running LimeSurvey with nginx and PHP-FPM. Adjust paths, domain names, and PHP-FPM socket/port settings to match your server setup.
Note: This is a basic example. Always review and adapt it to your own security requirements before using it in production.
server {
listen 80;
server_name survey.example.com;
# Redirect all HTTP traffic to HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name survey.example.com;
root /var/www/limesurvey;
index index.php;
# SSL certificates
ssl_certificate /etc/ssl/certs/survey.example.com.crt;
ssl_certificate_key /etc/ssl/private/survey.example.com.key;
# Recommended SSL settings
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers on;
client_max_body_size 100M;
access_log /var/log/nginx/limesurvey_access.log;
error_log /var/log/nginx/limesurvey_error.log;
location / {
try_files $uri $uri/ /index.php?$args;
}
location ~ \.php$ {
include fastcgi_params;
fastcgi_pass unix:/run/php/php8.1-fpm.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param PATH_INFO $fastcgi_path_info;
}
# Deny access to hidden files and sensitive directories
location ~ /\.(?!well-known).* {
deny all;
}
location ~* /(application|protected|modules|framework|db|application/config)/ {
deny all;
}
location ~* \.(log|sql|htaccess)$ {
deny all;
}
# Allow LimeSurvey to serve uploaded files and assets
location /upload/ {
try_files $uri $uri/ =404;
}
location /tmp/ {
deny all;
}
}
Explanation of key directives
fastcgi_pass: Points to the PHP-FPM socket or TCP address handling PHP requests. Update this to match your PHP-FPM pool configuration.try_files: Ensures URLs are routed correctly through LimeSurvey's front controller (index.php).client_max_body_size: Increases the maximum upload size, useful for surveys with file-upload questions.- Deny rules: Block direct web access to configuration files, logs, and application directories that should never be publicly reachable.