Skip to content
Back to skills

Nginx Triage

ASecurity

Work out why nginx is failing on a host, in order of cheapest evidence

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 10, 2026
ai-agents

Security analysis

A100/100

Scanned October 10, 2026

npx -y skills add hue913/agentd --skill nginx-triage --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Nginx Triage?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Nginx Triage
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hue913-nginx-triage/badge)](https://www.skillsdirectory.com/skills/hue913-nginx-triage)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: nginx-triage
description: Work out why nginx is failing on a host, in order of cheapest evidence
when: a healthcheck reports nginx down and you have not read any log yet
args: host
risk: read
run: ssh {host} "systemctl status nginx --no-pager; journalctl -u nginx -n 120 --no-pager; nginx -t 2>&1"
---

# nginx triage

Do these in order, and stop as soon as the cause is obvious:

1. `systemctl status nginx` — is the unit failing to start, or running but misbehaving?
   `Active: failed` with an exit code means config or bind failure, not load.
2. `journalctl -u nginx -n 120` — look for the **first** error, not the last. Later ones are
   usually the restart loop repeating the same failure.
3. `nginx -t` — configuration syntax and cert paths. This is read-only and safe.

Decision table:

| symptom | likely cause | next action |
|---|---|---|
| `bind() to 0.0.0.0:443 failed (98)` | another process holds the port | `ss -ltnp \| grep :443` |
| `SSL_CTX_use_PrivateKey_file ... failed` | cert/key mismatch or wrong path | verify files, do not guess paths |
| `worker_connections are not enough` | limit too low for real traffic | raise it, then reload |
| `connection refused` from the healthcheck only | healthcheck points at the wrong upstream | compare URLs before touching nginx |

Rules:

* Prefer `reload` over `restart`; a restart drops in-flight connections.
* Never edit a config file you have not read in full.
* If the fix is `rm`, `chmod -R`, or a firewall flush, stop and ask a human.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…