[{"data":1,"prerenderedAt":1368},["ShallowReactive",2],{"search-posts-dataset":3,"post-detail-/posts/nginx-reverse-proxy":159,"all-published-articles-list":1307,"series-posts-/posts/nginx-reverse-proxy":1367},[4,20,35,48,62,75,87,99,111,122,135,149],{"path":5,"title":6,"description":7,"categories":8,"tags":11,"date":16,"image":17},"/posts/incident-checklist","Checklist xử lí sự cố máy chủ Linux: Phục hồi sau thảm họa","Qui trình phản ứng và xử lí sự cố máy chủ Linux khi hệ thống bị sập, tràn RAM/HDD hoặc nghi ngờ bị xâm nhập: Các bước chuẩn đoán, cô lập, phân tích log và khôi phục.",[9,10],"linux","devops",[12,13,14,15],"incident","troubleshooting","security","sysadmin","2026-08-15T00:00:00.000Z",{"src":18,"alt":19},"/img/incident-response.webp","Xử lí sự cố máy chủ Linux",{"path":21,"title":22,"description":23,"categories":24,"tags":27,"date":31,"image":32},"/posts/backup-postgres-docker","Sao lưu tự động PostgreSQL trong Docker với cron job và gzip","Hướng dẫn xây dựng script tự động backup database PostgreSQL chạy trong Docker container: gzip, cron hàng ngày, tự động xóa bản sao lưu cũ và kiểm thử phục hồi.",[25,26],"docker","database",[28,29,30,10],"postgresql","backup","automation","2025-10-20T00:00:00.000Z",{"src":33,"alt":34},"/img/postgres-backup.webp","Sao lưu tự động PostgreSQL Docker",{"path":36,"title":37,"description":38,"categories":39,"tags":40,"date":44,"image":45},"/posts/docker-compose-production","Thiết kế Docker compose chuẩn Production","Hướng dẫn thực chiến xây dựng docker-compose.yml hoàn chỉnh cho Production: healthchecks, restart policies, resource limits, quản lí .env và Persistent Volumes",[25,10],[41,42,43],"production","compose","backend","2025-10-15T00:00:00.000Z",{"src":46,"alt":47},"/img/docker-compose.webp","Docker Compose Production Best Practices",{"path":49,"title":50,"description":51,"categories":52,"tags":53,"date":58,"image":59},"/posts/monitoring-server-basics","Giám sát server Linux từ cơ bản đến nâng cao: htop, ncdu, prometheus và Uptime Kuma","Cẩm nang toàn diện về giám sát hiệu năng máy chủ Linux: Khai thác công cụ CLI thời gian thực (Htop, Btop, Ncdu), thiết lập hệ thống cảnh báo sự cố Uptime Kuma qua Telegram và thu thập chỉ số với Prometheus & Grafana.",[9,10],[54,55,56,57],"monitoring","grafana","prometheus","uptime","2024-10-18T00:00:00.000Z",{"src":60,"alt":61},"/img/monitoring.webp","Giám sát máy chủ Linux",{"path":63,"title":64,"description":65,"categories":66,"tags":68,"date":71,"image":72},"/posts/nginx-reverse-proxy","Hướng dẫn cấu hình Nginx Reverse Proxy với SSL Certbot và Docker chuẩn Production","Cẩm nang toàn diện cấu hình Nginx Reverse Proxy trên Ubuntu: Tích hợp chứng chỉ SSL Let's Encrypt miễn phí qua Certbot, hỗ trợ WebSockets, HTTP/2, nén Brotli/Gzip và Rate Limiting chống DDoS.",[9,67],"nginx",[10,69,70],"ssl","webserver","2024-10-10T00:00:00.000Z",{"src":73,"alt":74},"/img/nginx.webp","Nginx Reverse Proxy với SSL",{"path":76,"title":77,"description":78,"categories":79,"tags":80,"date":83,"image":84},"/posts/how-to-secure-a-vps","Bảo mật máy chủ Linux VPS: Cẩm nang toàn diện 8 bước chống tấn công","Hướng dẫn thực chiến từng bước thiết lập bảo mật máy chủ Linux VPS mới: Vô hiệu hóa mật khẩu SSH, thiết lập SSH Key Ed25519, cấu hình Fail2ban, tường lửa UFW và cập nhật tự động Unattended-Upgrades.",[9,14],[81,82,10],"vps","hardening","2024-10-05T00:00:00.000Z",{"src":85,"alt":86},"/img/linux-security.webp","Bảo mật máy chủ Linux VPS",{"path":88,"title":89,"description":90,"categories":91,"tags":92,"date":95,"image":96},"/posts/systemd-node-service","Quản lí ứng dụng Node.js trong Production với Systemd Service và Journalctl","Hướng dẫn triển khai ứng dụng Node.js, Go hoặc Python dưới dạng Systemd Service trên Linux: Tự động khởi động lại khi crash, quản lý biến môi trường, giới hạn bộ nhớ RAM và theo dõi log thời gian thực với Journalctl.",[9,10],[93,94,43,41],"systemd","nodejs","2024-10-01T00:00:00.000Z",{"src":97,"alt":98},"/img/systemd.webp","Quản lý ứng dụng với Systemd Service",{"path":100,"title":101,"description":102,"categories":103,"tags":104,"date":107,"image":108},"/posts/how-to-install-docker-on-ubuntu-server","Hướng dẫn cài đặt Docker & Docker compose trên Ubuntu server","Hướng dẫn toàn diện cách cài đặt Docker Engine và Docker Compose V2 trên Ubuntu Server, cấu hình bảo mật non-root user, tối ưu daemon và xử lí xung đột tường lửa UFW",[9,25],[105,10,106],"beginner","ubuntu","2024-09-30T00:00:00.000Z",{"src":109,"alt":110},"/img/docker.webp","Cài đặt Docker trên Ubuntu Server",{"path":112,"title":113,"description":114,"categories":115,"tags":116,"date":118,"image":119},"/posts/ssh-key-authentication","Xác thực SSH Key từ cơ bản đến nâng cao: Ed25519, SSH Config và Bảo mật đa tầng","Cẩm nang toàn diện về xác thực SSH Key trên máy chủ Linux: So sánh Ed25519 vs RSA, cấu hình SSH Config quản lí hàng chục VPS, chuyển tiếp Agent Forwarding, và các qui tắc bảo mật chống lộ khóa.",[9,14],[117,10,15],"ssh","2024-09-25T00:00:00.000Z",{"src":120,"alt":121},"/img/ssh-keys.webp","Xác thực SSH Key Linux",{"path":123,"title":124,"description":125,"categories":126,"tags":127,"date":131,"image":132},"/posts/ufw-firewall-basics","Làm chủ tường lửa UFW trên Linux: Qui tắc, giới hạn kết nối và xử lí xung đột Docker","Hướng dẫn toàn diện làm chủ tường lửa UFW (Uncomplicated Firewall) trên Ubuntu: Thiết lập chính sách mặc định, mở cổng theo IP, giới hạn brute-force (Rate Limiting) và khắc phục lỗi Docker bypass tường lửa.",[9,14],[128,129,130,15],"ufw","firewall","networking","2024-09-20T00:00:00.000Z",{"src":133,"alt":134},"/img/ufw-firewall.webp","Cấu hình Tường lửa UFW Linux",{"path":136,"title":137,"description":138,"categories":139,"tags":141,"date":145,"image":146},"/posts/git-deploy-key","Tự động hóa triển khai với Git deploy keys: Thiết lập an toàn cho GitHub và GitLab","Hướng dẫn thiết lập Git Deploy Key chuẩn bảo mật để kéo mã nguồn tự động từ GitHub hoặc GitLab về máy chủ Production: Phân quyền Read-Only, cấu hình SSH Config và tích hợp Webhook tự động cập nhật.",[140,10],"git",[142,143,144,30],"github","gitlab","cicd","2024-09-18T00:00:00.000Z",{"src":147,"alt":148},"/img/git-deploy.webp","Git Deploy Keys cho máy chủ",{"path":150,"title":151,"description":152,"categories":153,"tags":154,"date":155,"image":156},"/posts/ubuntu-server-initial-setup","Qui trình thiết lập ban đầu cho Ubuntu Server: Swap, Timezone, User và Firewall","Hướng dẫn các bước thiết lập chuẩn mực ban đầu cho máy chủ Ubuntu Server mới: Cấu hình múi giờ Việt Nam (Asia/Ho_Chi_Minh), tạo phân vùng RAM ảo (Swap File), phân quyền Sudoer và kích hoạt tường lửa UFW.",[9],[106,105,15],"2024-09-15T00:00:00.000Z",{"src":157,"alt":158},"/img/ubuntu.webp","Thiết lập ban đầu Ubuntu Server",{"id":160,"title":64,"author":161,"body":162,"categories":1295,"date":71,"description":65,"draft":1296,"extension":1297,"image":1298,"meta":1299,"navigation":425,"path":63,"seo":1300,"series":1301,"series_order":1301,"slug":1302,"stem":1303,"tags":1304,"updated":1305,"__hash__":1306},"post/posts/nginx-reverse-proxy.md","Duong Thu",{"type":163,"value":164,"toc":1283},"minimal",[165,170,179,182,216,219,223,226,269,272,300,303,323,326,344,346,350,361,368,383,386,642,648,669,672,686,697,713,715,719,722,725,784,787,808,811,827,832,835,852,854,858,861,867,881,888,1038,1049,1051,1055,1063,1069,1083,1086,1101,1107,1146,1164,1166,1170,1270,1272,1276,1279],[166,167,169],"h2",{"id":168},"nginx-reverse-proxy-là-gì-và-tại-sao-bạn-cần-nó","Nginx Reverse Proxy là gì và tại sao bạn cần nó?",[171,172,173,174,178],"p",{},"Trong kiến trúc hệ thống hiện đại, ",[175,176,177],"strong",{},"Reverse Proxy"," là một máy chủ đứng trước các ứng dụng backend (Node.js, Python, Go, Java, Docker container...) và nhận mọi yêu cầu (HTTP/HTTPS request) từ trình duyệt của người dùng gửi tới, sau đó chuyển tiếp (forward) chúng đến các dịch vụ nội bộ phù hợp..",[171,180,181],{},"Sử dụng Nginx làm Reverse Proxy mang lại nhiều lợi thế vượt trội:",[183,184,185,192,198,204,210],"ul",{},[186,187,188,191],"li",{},[175,189,190],{},"Bảo mật tuyệt đối",": Ẩn giấu địa chỉ IP nội bộ và kiến trúc hạ tầng thực sự của các container ứng dụng.",[186,193,194,197],{},[175,195,196],{},"Tập trung quản lý chứng chỉ SSL/TLS",": Tự động giải mã HTTPS tại Nginx (SSL Termination), giảm tải gánh nặng tính toán mật mã cho ứng dụng backend.",[186,199,200,203],{},[175,201,202],{},"Tải và Cân bằng tải (Load Balancing)",": Phân phối lưu lượng truy cập đều đặn giữa nhiều bản sao container backend.",[186,205,206,209],{},[175,207,208],{},"Tối ưu tốc độ",": Bộ nhớ đệm (Caching), nén dữ liệu Gzip/Brotli và hỗ trợ giao thức HTTP/2, HTTP/3 giúp website tải siêu nhanh.",[186,211,212,215],{},[175,213,214],{},"Bảo vệ ứng dụng",": Giới hạn tần suất yêu cầu (Rate Limiting) để ngăn chặn các cuộc tấn công quét lỗ hổng hoặc DDoS phân tầng.",[217,218],"hr",{},[166,220,222],{"id":221},"_1-cài-đặt-nginx-trên-ubuntu-server","1. Cài đặt Nginx trên Ubuntu Server",[171,224,225],{},"Cập nhật danh sách gói và tiến hành cài đặt Nginx từ kho phần mềm chính thức:",[227,228,233],"pre",{"className":229,"code":230,"language":231,"meta":232,"style":232},"language-bash shiki shiki-themes github-dark github-dark github-dark","sudo apt update\nsudo apt install -y nginx\n","bash","",[234,235,236,252],"code",{"__ignoreMap":232},[237,238,241,245,249],"span",{"class":239,"line":240},"line",1,[237,242,244],{"class":243},"sb7EE","sudo",[237,246,248],{"class":247},"skqr8"," apt",[237,250,251],{"class":247}," update\n",[237,253,255,257,259,262,266],{"class":239,"line":254},2,[237,256,244],{"class":243},[237,258,248],{"class":247},[237,260,261],{"class":247}," install",[237,263,265],{"class":264},"sKJT9"," -y",[237,267,268],{"class":247}," nginx\n",[171,270,271],{},"Khởi động và kích hoạt Nginx tự chạy cùng hệ điều hành:",[227,273,275],{"className":229,"code":274,"language":231,"meta":232,"style":232},"sudo systemctl enable nginx\nsudo systemctl start nginx\n",[234,276,277,289],{"__ignoreMap":232},[237,278,279,281,284,287],{"class":239,"line":240},[237,280,244],{"class":243},[237,282,283],{"class":247}," systemctl",[237,285,286],{"class":247}," enable",[237,288,268],{"class":247},[237,290,291,293,295,298],{"class":239,"line":254},[237,292,244],{"class":243},[237,294,283],{"class":247},[237,296,297],{"class":247}," start",[237,299,268],{"class":247},[171,301,302],{},"Kiểm tra trạng thái hoạt động:",[227,304,306],{"className":229,"code":305,"language":231,"meta":232,"style":232},"sudo systemctl status nginx --no-pager\n",[234,307,308],{"__ignoreMap":232},[237,309,310,312,314,317,320],{"class":239,"line":240},[237,311,244],{"class":243},[237,313,283],{"class":247},[237,315,316],{"class":247}," status",[237,318,319],{"class":247}," nginx",[237,321,322],{"class":264}," --no-pager\n",[171,324,325],{},"Mở cổng tường lửa UFW cho phép lưu lượng HTTP (80) và HTTPS (443):",[227,327,329],{"className":229,"code":328,"language":231,"meta":232,"style":232},"sudo ufw allow 'Nginx Full'\n",[234,330,331],{"__ignoreMap":232},[237,332,333,335,338,341],{"class":239,"line":240},[237,334,244],{"class":243},[237,336,337],{"class":247}," ufw",[237,339,340],{"class":247}," allow",[237,342,343],{"class":247}," 'Nginx Full'\n",[217,345],{},[166,347,349],{"id":348},"_2-cấu-trúc-server-block-chuẩn-cho-ứng-dụng-web-docker","2. Cấu trúc Server Block chuẩn cho ứng dụng Web / Docker",[171,351,352,353,356,357,360],{},"Giả sử bạn có một ứng dụng Node.js hoặc Docker container đang lắng nghe tại cổng ",[234,354,355],{},"http://127.0.0.1:3000"," và bạn muốn gắn tên miền ",[234,358,359],{},"api.example.com"," trỏ tới dịch vụ này.",[171,362,363,364,367],{},"Tạo một file cấu hình Server Block mới tại ",[234,365,366],{},"/etc/nginx/sites-available/api.example.com.conf",":",[227,369,371],{"className":229,"code":370,"language":231,"meta":232,"style":232},"sudo nano /etc/nginx/sites-available/api.example.com.conf\n",[234,372,373],{"__ignoreMap":232},[237,374,375,377,380],{"class":239,"line":240},[237,376,244],{"class":243},[237,378,379],{"class":247}," nano",[237,381,382],{"class":247}," /etc/nginx/sites-available/api.example.com.conf\n",[171,384,385],{},"Dán nội dung cấu hình chuẩn hóa sau vào file:",[227,387,390],{"className":388,"code":389,"language":67,"meta":232,"style":232},"language-nginx shiki shiki-themes github-dark github-dark github-dark","# Định nghĩa nhóm Upstream Backend\nupstream nodejs_backend {\n    server 127.0.0.1:3000 max_fails=3 fail_timeout=10s;\n    keepalive 32;\n}\n\nserver {\n    listen 80;\n    listen [::]:80;\n    server_name api.example.com;\n\n    # Cấu hình log riêng cho domain\n    access_log /var/log/nginx/api.example.com.access.log;\n    error_log /var/log/nginx/api.example.com.error.log warn;\n\n    # Giới hạn kích thước tải lên file (ví dụ: tối đa 20MB)\n    client_max_body_size 20M;\n\n    location / {\n        proxy_pass http://nodejs_backend;\n        \n        # Thiết lập các HTTP Headers chuyển tiếp chuẩn xác\n        proxy_http_version 1.1;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n\n        # Hỗ trợ WebSockets thời gian thực\n        proxy_set_header Upgrade $http_upgrade;\n        proxy_set_header Connection \"upgrade\";\n\n        # Thời gian chờ phản hồi từ ứng dụng\n        proxy_connect_timeout 60s;\n        proxy_send_timeout 60s;\n        proxy_read_timeout 60s;\n\n        # Bộ đệm truyền tải\n        proxy_buffering on;\n        proxy_buffer_size 8k;\n        proxy_buffers 8 8k;\n    }\n}\n",[234,391,392,397,402,408,414,420,427,433,439,445,451,456,462,468,474,479,485,491,496,502,508,514,520,526,532,538,544,550,555,561,567,573,578,584,590,596,602,607,613,619,625,631,637],{"__ignoreMap":232},[237,393,394],{"class":239,"line":240},[237,395,396],{},"# Định nghĩa nhóm Upstream Backend\n",[237,398,399],{"class":239,"line":254},[237,400,401],{},"upstream nodejs_backend {\n",[237,403,405],{"class":239,"line":404},3,[237,406,407],{},"    server 127.0.0.1:3000 max_fails=3 fail_timeout=10s;\n",[237,409,411],{"class":239,"line":410},4,[237,412,413],{},"    keepalive 32;\n",[237,415,417],{"class":239,"line":416},5,[237,418,419],{},"}\n",[237,421,423],{"class":239,"line":422},6,[237,424,426],{"emptyLinePlaceholder":425},true,"\n",[237,428,430],{"class":239,"line":429},7,[237,431,432],{},"server {\n",[237,434,436],{"class":239,"line":435},8,[237,437,438],{},"    listen 80;\n",[237,440,442],{"class":239,"line":441},9,[237,443,444],{},"    listen [::]:80;\n",[237,446,448],{"class":239,"line":447},10,[237,449,450],{},"    server_name api.example.com;\n",[237,452,454],{"class":239,"line":453},11,[237,455,426],{"emptyLinePlaceholder":425},[237,457,459],{"class":239,"line":458},12,[237,460,461],{},"    # Cấu hình log riêng cho domain\n",[237,463,465],{"class":239,"line":464},13,[237,466,467],{},"    access_log /var/log/nginx/api.example.com.access.log;\n",[237,469,471],{"class":239,"line":470},14,[237,472,473],{},"    error_log /var/log/nginx/api.example.com.error.log warn;\n",[237,475,477],{"class":239,"line":476},15,[237,478,426],{"emptyLinePlaceholder":425},[237,480,482],{"class":239,"line":481},16,[237,483,484],{},"    # Giới hạn kích thước tải lên file (ví dụ: tối đa 20MB)\n",[237,486,488],{"class":239,"line":487},17,[237,489,490],{},"    client_max_body_size 20M;\n",[237,492,494],{"class":239,"line":493},18,[237,495,426],{"emptyLinePlaceholder":425},[237,497,499],{"class":239,"line":498},19,[237,500,501],{},"    location / {\n",[237,503,505],{"class":239,"line":504},20,[237,506,507],{},"        proxy_pass http://nodejs_backend;\n",[237,509,511],{"class":239,"line":510},21,[237,512,513],{},"        \n",[237,515,517],{"class":239,"line":516},22,[237,518,519],{},"        # Thiết lập các HTTP Headers chuyển tiếp chuẩn xác\n",[237,521,523],{"class":239,"line":522},23,[237,524,525],{},"        proxy_http_version 1.1;\n",[237,527,529],{"class":239,"line":528},24,[237,530,531],{},"        proxy_set_header Host $host;\n",[237,533,535],{"class":239,"line":534},25,[237,536,537],{},"        proxy_set_header X-Real-IP $remote_addr;\n",[237,539,541],{"class":239,"line":540},26,[237,542,543],{},"        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n",[237,545,547],{"class":239,"line":546},27,[237,548,549],{},"        proxy_set_header X-Forwarded-Proto $scheme;\n",[237,551,553],{"class":239,"line":552},28,[237,554,426],{"emptyLinePlaceholder":425},[237,556,558],{"class":239,"line":557},29,[237,559,560],{},"        # Hỗ trợ WebSockets thời gian thực\n",[237,562,564],{"class":239,"line":563},30,[237,565,566],{},"        proxy_set_header Upgrade $http_upgrade;\n",[237,568,570],{"class":239,"line":569},31,[237,571,572],{},"        proxy_set_header Connection \"upgrade\";\n",[237,574,576],{"class":239,"line":575},32,[237,577,426],{"emptyLinePlaceholder":425},[237,579,581],{"class":239,"line":580},33,[237,582,583],{},"        # Thời gian chờ phản hồi từ ứng dụng\n",[237,585,587],{"class":239,"line":586},34,[237,588,589],{},"        proxy_connect_timeout 60s;\n",[237,591,593],{"class":239,"line":592},35,[237,594,595],{},"        proxy_send_timeout 60s;\n",[237,597,599],{"class":239,"line":598},36,[237,600,601],{},"        proxy_read_timeout 60s;\n",[237,603,605],{"class":239,"line":604},37,[237,606,426],{"emptyLinePlaceholder":425},[237,608,610],{"class":239,"line":609},38,[237,611,612],{},"        # Bộ đệm truyền tải\n",[237,614,616],{"class":239,"line":615},39,[237,617,618],{},"        proxy_buffering on;\n",[237,620,622],{"class":239,"line":621},40,[237,623,624],{},"        proxy_buffer_size 8k;\n",[237,626,628],{"class":239,"line":627},41,[237,629,630],{},"        proxy_buffers 8 8k;\n",[237,632,634],{"class":239,"line":633},42,[237,635,636],{},"    }\n",[237,638,640],{"class":239,"line":639},43,[237,641,419],{},[171,643,644,645,367],{},"Kích hoạt file cấu hình bằng cách tạo liên kết mềm (symlink) sang thư mục ",[234,646,647],{},"sites-enabled",[227,649,651],{"className":229,"code":650,"language":231,"meta":232,"style":232},"sudo ln -s /etc/nginx/sites-available/api.example.com.conf /etc/nginx/sites-enabled/\n",[234,652,653],{"__ignoreMap":232},[237,654,655,657,660,663,666],{"class":239,"line":240},[237,656,244],{"class":243},[237,658,659],{"class":247}," ln",[237,661,662],{"class":264}," -s",[237,664,665],{"class":247}," /etc/nginx/sites-available/api.example.com.conf",[237,667,668],{"class":247}," /etc/nginx/sites-enabled/\n",[171,670,671],{},"Kiểm tra cú pháp cấu hình Nginx:",[227,673,675],{"className":229,"code":674,"language":231,"meta":232,"style":232},"sudo nginx -t\n",[234,676,677],{"__ignoreMap":232},[237,678,679,681,683],{"class":239,"line":240},[237,680,244],{"class":243},[237,682,319],{"class":247},[237,684,685],{"class":264}," -t\n",[171,687,688,689,692,693,696],{},"Nếu hiển thị ",[234,690,691],{},"syntax is ok"," và ",[234,694,695],{},"test is successful",", hãy reload Nginx:",[227,698,700],{"className":229,"code":699,"language":231,"meta":232,"style":232},"sudo systemctl reload nginx\n",[234,701,702],{"__ignoreMap":232},[237,703,704,706,708,711],{"class":239,"line":240},[237,705,244],{"class":243},[237,707,283],{"class":247},[237,709,710],{"class":247}," reload",[237,712,268],{"class":247},[217,714],{},[166,716,718],{"id":717},"_3-cài-đặt-chứng-chỉ-ssl-miễn-phí-với-lets-encrypt-certbot","3. Cài đặt chứng chỉ SSL miễn phí với Let's Encrypt & Certbot",[171,720,721],{},"Certbot là công cụ tự động xin cấp và gia hạn chứng chỉ bảo mật SSL/TLS miễn phí từ tổ chức phi lợi nhuận Let's Encrypt.",[171,723,724],{},"Cài đặt Certbot qua Snap (cách thức chính thức được khuyến nghị bởi EFF):",[227,726,728],{"className":229,"code":727,"language":231,"meta":232,"style":232},"sudo snap install core && sudo snap refresh core\nsudo snap install --classic certbot\nsudo ln -s /snap/bin/certbot /usr/bin/certbot\n",[234,729,730,756,770],{"__ignoreMap":232},[237,731,732,734,737,739,742,746,748,750,753],{"class":239,"line":240},[237,733,244],{"class":243},[237,735,736],{"class":247}," snap",[237,738,261],{"class":247},[237,740,741],{"class":247}," core",[237,743,745],{"class":744},"sFJ4l"," && ",[237,747,244],{"class":243},[237,749,736],{"class":247},[237,751,752],{"class":247}," refresh",[237,754,755],{"class":247}," core\n",[237,757,758,760,762,764,767],{"class":239,"line":254},[237,759,244],{"class":243},[237,761,736],{"class":247},[237,763,261],{"class":247},[237,765,766],{"class":264}," --classic",[237,768,769],{"class":247}," certbot\n",[237,771,772,774,776,778,781],{"class":239,"line":404},[237,773,244],{"class":243},[237,775,659],{"class":247},[237,777,662],{"class":264},[237,779,780],{"class":247}," /snap/bin/certbot",[237,782,783],{"class":247}," /usr/bin/certbot\n",[171,785,786],{},"Chạy lệnh tạo chứng chỉ tự động cho tên miền của bạn:",[227,788,790],{"className":229,"code":789,"language":231,"meta":232,"style":232},"sudo certbot --nginx -d api.example.com\n",[234,791,792],{"__ignoreMap":232},[237,793,794,796,799,802,805],{"class":239,"line":240},[237,795,244],{"class":243},[237,797,798],{"class":247}," certbot",[237,800,801],{"class":264}," --nginx",[237,803,804],{"class":264}," -d",[237,806,807],{"class":247}," api.example.com\n",[171,809,810],{},"Trong quá trình cài đặt:",[812,813,814,817,824],"ol",{},[186,815,816],{},"Nhập email của bạn để nhận thông báo gia hạn chứng chỉ.",[186,818,819,820,823],{},"Đồng ý với điều khoản dịch vụ (",[234,821,822],{},"Y",").",[186,825,826],{},"Chọn tùy chọn tự động chuyển hướng toàn bộ lưu lượng HTTP sang HTTPS (Redirect).",[828,829,831],"h3",{"id":830},"kiểm-tra-tính-năng-tự-động-gia-hạn-chứng-chỉ-auto-renewal","Kiểm tra tính năng tự động gia hạn chứng chỉ (Auto-Renewal)",[171,833,834],{},"Chứng chỉ của Let's Encrypt có thời hạn 90 ngày. Certbot đã tự động cài đặt bộ lập lịch (systemd timer) để gia hạn tự động trước khi hết hạn 30 ngày. Hãy kiểm tra thử quá trình giả lập gia hạn:",[227,836,838],{"className":229,"code":837,"language":231,"meta":232,"style":232},"sudo certbot renew --dry-run\n",[234,839,840],{"__ignoreMap":232},[237,841,842,844,846,849],{"class":239,"line":240},[237,843,244],{"class":243},[237,845,798],{"class":247},[237,847,848],{"class":247}," renew",[237,850,851],{"class":264}," --dry-run\n",[217,853],{},[166,855,857],{"id":856},"_4-tối-ưu-hiệu-năng-nginx-gzip-http2","4. Tối ưu hiệu năng Nginx (Gzip & HTTP/2)",[171,859,860],{},"Để tăng tốc độ tải trang lên mức tối đa, hãy bật tính năng nén Gzip và HTTP/2.",[171,862,863,864,367],{},"Mở file cấu hình chính ",[234,865,866],{},"/etc/nginx/nginx.conf",[227,868,870],{"className":229,"code":869,"language":231,"meta":232,"style":232},"sudo nano /etc/nginx/nginx.conf\n",[234,871,872],{"__ignoreMap":232},[237,873,874,876,878],{"class":239,"line":240},[237,875,244],{"class":243},[237,877,379],{"class":247},[237,879,880],{"class":247}," /etc/nginx/nginx.conf\n",[171,882,883,884,887],{},"Đảm bảo khối ",[234,885,886],{},"http"," có các cấu hình nén sau:",[227,889,891],{"className":388,"code":890,"language":67,"meta":232,"style":232},"## Gzip Settings\ngzip on;\ngzip_disable \"msie6\";\ngzip_vary on;\ngzip_proxied any;\ngzip_comp_level 6;\ngzip_buffers 16 8k;\ngzip_http_version 1.1;\ngzip_min_length 256;\ngzip_types\n    application/atom+xml\n    application/geo+json\n    application/javascript\n    application/x-javascript\n    application/json\n    application/ld+json\n    application/manifest+json\n    application/rdf+xml\n    application/rss+xml\n    application/xhtml+xml\n    application/xml\n    font/eot\n    font/otf\n    font/ttf\n    image/svg+xml\n    text/css\n    text/javascript\n    text/plain\n    text/xml;\n",[234,892,893,898,903,908,913,918,923,928,933,938,943,948,953,958,963,968,973,978,983,988,993,998,1003,1008,1013,1018,1023,1028,1033],{"__ignoreMap":232},[237,894,895],{"class":239,"line":240},[237,896,897],{},"## Gzip Settings\n",[237,899,900],{"class":239,"line":254},[237,901,902],{},"gzip on;\n",[237,904,905],{"class":239,"line":404},[237,906,907],{},"gzip_disable \"msie6\";\n",[237,909,910],{"class":239,"line":410},[237,911,912],{},"gzip_vary on;\n",[237,914,915],{"class":239,"line":416},[237,916,917],{},"gzip_proxied any;\n",[237,919,920],{"class":239,"line":422},[237,921,922],{},"gzip_comp_level 6;\n",[237,924,925],{"class":239,"line":429},[237,926,927],{},"gzip_buffers 16 8k;\n",[237,929,930],{"class":239,"line":435},[237,931,932],{},"gzip_http_version 1.1;\n",[237,934,935],{"class":239,"line":441},[237,936,937],{},"gzip_min_length 256;\n",[237,939,940],{"class":239,"line":447},[237,941,942],{},"gzip_types\n",[237,944,945],{"class":239,"line":453},[237,946,947],{},"    application/atom+xml\n",[237,949,950],{"class":239,"line":458},[237,951,952],{},"    application/geo+json\n",[237,954,955],{"class":239,"line":464},[237,956,957],{},"    application/javascript\n",[237,959,960],{"class":239,"line":470},[237,961,962],{},"    application/x-javascript\n",[237,964,965],{"class":239,"line":476},[237,966,967],{},"    application/json\n",[237,969,970],{"class":239,"line":481},[237,971,972],{},"    application/ld+json\n",[237,974,975],{"class":239,"line":487},[237,976,977],{},"    application/manifest+json\n",[237,979,980],{"class":239,"line":493},[237,981,982],{},"    application/rdf+xml\n",[237,984,985],{"class":239,"line":498},[237,986,987],{},"    application/rss+xml\n",[237,989,990],{"class":239,"line":504},[237,991,992],{},"    application/xhtml+xml\n",[237,994,995],{"class":239,"line":510},[237,996,997],{},"    application/xml\n",[237,999,1000],{"class":239,"line":516},[237,1001,1002],{},"    font/eot\n",[237,1004,1005],{"class":239,"line":522},[237,1006,1007],{},"    font/otf\n",[237,1009,1010],{"class":239,"line":528},[237,1011,1012],{},"    font/ttf\n",[237,1014,1015],{"class":239,"line":534},[237,1016,1017],{},"    image/svg+xml\n",[237,1019,1020],{"class":239,"line":540},[237,1021,1022],{},"    text/css\n",[237,1024,1025],{"class":239,"line":546},[237,1026,1027],{},"    text/javascript\n",[237,1029,1030],{"class":239,"line":552},[237,1031,1032],{},"    text/plain\n",[237,1034,1035],{"class":239,"line":557},[237,1036,1037],{},"    text/xml;\n",[171,1039,1040,1041,1044,1045,1048],{},"Sau khi Certbot chỉnh sửa file cấu hình ở Bước 3, khối ",[234,1042,1043],{},"server"," HTTPS sẽ tự động có dạng ",[234,1046,1047],{},"listen 443 ssl http2;",". Điều này giúp trình duyệt có thể ghép kênh (Multiplexing) nhiều file tài nguyên tĩnh qua một kết nối TCP duy nhất.",[217,1050],{},[166,1052,1054],{"id":1053},"_5-chống-spam-ddos-với-rate-limiting","5. Chống Spam & DDoS với Rate Limiting",[171,1056,1057,1058,1062],{},"Để ngăn chặn các kẻ tấn công spam request làm sập backend, Nginx hỗ trợ thuật toán giới hạn tốc độ ",[1059,1060,1061],"em",{},"Leaky Bucket",".",[171,1064,1065,1066,367],{},"Mở file ",[234,1067,1068],{},"/etc/nginx/conf.d/rate_limit.conf",[227,1070,1072],{"className":229,"code":1071,"language":231,"meta":232,"style":232},"sudo nano /etc/nginx/conf.d/rate_limit.conf\n",[234,1073,1074],{"__ignoreMap":232},[237,1075,1076,1078,1080],{"class":239,"line":240},[237,1077,244],{"class":243},[237,1079,379],{"class":247},[237,1081,1082],{"class":247}," /etc/nginx/conf.d/rate_limit.conf\n",[171,1084,1085],{},"Thêm cấu hình:",[227,1087,1089],{"className":388,"code":1088,"language":67,"meta":232,"style":232},"# Giới hạn tối đa 10 requests / giây theo từng địa chỉ IP khách\nlimit_req_zone $binary_remote_addr zone=api_limit:10m rate=10r/s;\n",[234,1090,1091,1096],{"__ignoreMap":232},[237,1092,1093],{"class":239,"line":240},[237,1094,1095],{},"# Giới hạn tối đa 10 requests / giây theo từng địa chỉ IP khách\n",[237,1097,1098],{"class":239,"line":254},[237,1099,1100],{},"limit_req_zone $binary_remote_addr zone=api_limit:10m rate=10r/s;\n",[171,1102,1103,1104,367],{},"Sau đó, trong file cấu hình domain của bạn, áp dụng quy tắc vào ",[234,1105,1106],{},"location /",[227,1108,1110],{"className":388,"code":1109,"language":67,"meta":232,"style":232},"location / {\n    limit_req zone=api_limit burst=20 nodelay;\n    limit_req_status 429;\n    \n    proxy_pass http://nodejs_backend;\n    ...\n}\n",[234,1111,1112,1117,1122,1127,1132,1137,1142],{"__ignoreMap":232},[237,1113,1114],{"class":239,"line":240},[237,1115,1116],{},"location / {\n",[237,1118,1119],{"class":239,"line":254},[237,1120,1121],{},"    limit_req zone=api_limit burst=20 nodelay;\n",[237,1123,1124],{"class":239,"line":404},[237,1125,1126],{},"    limit_req_status 429;\n",[237,1128,1129],{"class":239,"line":410},[237,1130,1131],{},"    \n",[237,1133,1134],{"class":239,"line":416},[237,1135,1136],{},"    proxy_pass http://nodejs_backend;\n",[237,1138,1139],{"class":239,"line":422},[237,1140,1141],{},"    ...\n",[237,1143,1144],{"class":239,"line":429},[237,1145,419],{},[183,1147,1148,1156],{},[186,1149,1150,1155],{},[175,1151,1152],{},[234,1153,1154],{},"burst=20",": Cho phép người dùng bình thường có thể gửi tối đa 20 request tức thời trong tích tắc mà không bị chặn.",[186,1157,1158,1163],{},[175,1159,1160],{},[234,1161,1162],{},"limit_req_status 429",": Trả về mã lỗi HTTP 429 Too Many Requests chuẩn mực quốc tế khi vượt ngưỡng.",[217,1165],{},[166,1167,1169],{"id":1168},"_6-các-lệnh-quản-lý-nginx-cần-ghi-nhớ","6. Các lệnh quản lý Nginx cần ghi nhớ",[227,1171,1173],{"className":229,"code":1172,"language":231,"meta":232,"style":232},"# Kiểm tra file cấu hình trước khi áp dụng (CỰC KỲ QUAN TRỌNG)\nsudo nginx -t\n\n# Nạp lại cấu hình mượt mà không làm gián đoạn kết nối người dùng (Zero Downtime)\nsudo systemctl reload nginx\n\n# Khởi động lại toàn bộ dịch vụ Nginx\nsudo systemctl restart nginx\n\n# Xem log truy cập thời gian thực\nsudo tail -f /var/log/nginx/access.log\n\n# Xem log lỗi\nsudo tail -f /var/log/nginx/error.log\n",[234,1174,1175,1181,1189,1193,1198,1208,1212,1217,1228,1232,1237,1250,1254,1259],{"__ignoreMap":232},[237,1176,1177],{"class":239,"line":240},[237,1178,1180],{"class":1179},"sGGCZ","# Kiểm tra file cấu hình trước khi áp dụng (CỰC KỲ QUAN TRỌNG)\n",[237,1182,1183,1185,1187],{"class":239,"line":254},[237,1184,244],{"class":243},[237,1186,319],{"class":247},[237,1188,685],{"class":264},[237,1190,1191],{"class":239,"line":404},[237,1192,426],{"emptyLinePlaceholder":425},[237,1194,1195],{"class":239,"line":410},[237,1196,1197],{"class":1179},"# Nạp lại cấu hình mượt mà không làm gián đoạn kết nối người dùng (Zero Downtime)\n",[237,1199,1200,1202,1204,1206],{"class":239,"line":416},[237,1201,244],{"class":243},[237,1203,283],{"class":247},[237,1205,710],{"class":247},[237,1207,268],{"class":247},[237,1209,1210],{"class":239,"line":422},[237,1211,426],{"emptyLinePlaceholder":425},[237,1213,1214],{"class":239,"line":429},[237,1215,1216],{"class":1179},"# Khởi động lại toàn bộ dịch vụ Nginx\n",[237,1218,1219,1221,1223,1226],{"class":239,"line":435},[237,1220,244],{"class":243},[237,1222,283],{"class":247},[237,1224,1225],{"class":247}," restart",[237,1227,268],{"class":247},[237,1229,1230],{"class":239,"line":441},[237,1231,426],{"emptyLinePlaceholder":425},[237,1233,1234],{"class":239,"line":447},[237,1235,1236],{"class":1179},"# Xem log truy cập thời gian thực\n",[237,1238,1239,1241,1244,1247],{"class":239,"line":453},[237,1240,244],{"class":243},[237,1242,1243],{"class":247}," tail",[237,1245,1246],{"class":264}," -f",[237,1248,1249],{"class":247}," /var/log/nginx/access.log\n",[237,1251,1252],{"class":239,"line":458},[237,1253,426],{"emptyLinePlaceholder":425},[237,1255,1256],{"class":239,"line":464},[237,1257,1258],{"class":1179},"# Xem log lỗi\n",[237,1260,1261,1263,1265,1267],{"class":239,"line":470},[237,1262,244],{"class":243},[237,1264,1243],{"class":247},[237,1266,1246],{"class":264},[237,1268,1269],{"class":247}," /var/log/nginx/error.log\n",[217,1271],{},[166,1273,1275],{"id":1274},"lời-kết","Lời kết",[171,1277,1278],{},"Với Nginx Reverse Proxy kết hợp chứng chỉ SSL Let's Encrypt, bạn đã xây dựng được một cổng vào (API Gateway / Ingress) an toàn, nhanh chóng và đạt chuẩn sản xuất cho toàn bộ hệ thống ứng dụng trên máy chủ của mình.",[1280,1281,1282],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html pre.shiki code .sb7EE, html code.shiki .sb7EE{--shiki-default:#B392F0;--shiki-dark:#B392F0;--shiki-light:#B392F0}html pre.shiki code .skqr8, html code.shiki .skqr8{--shiki-default:#9ECBFF;--shiki-dark:#9ECBFF;--shiki-light:#9ECBFF}html pre.shiki code .sKJT9, html code.shiki .sKJT9{--shiki-default:#79B8FF;--shiki-dark:#79B8FF;--shiki-light:#79B8FF}html pre.shiki code .sFJ4l, html code.shiki .sFJ4l{--shiki-default:#E1E4E8;--shiki-dark:#E1E4E8;--shiki-light:#E1E4E8}html pre.shiki code .sGGCZ, html code.shiki .sGGCZ{--shiki-default:#6A737D;--shiki-dark:#6A737D;--shiki-light:#6A737D}",{"title":232,"searchDepth":254,"depth":254,"links":1284},[1285,1286,1287,1288,1291,1292,1293,1294],{"id":168,"depth":254,"text":169},{"id":221,"depth":254,"text":222},{"id":348,"depth":254,"text":349},{"id":717,"depth":254,"text":718,"children":1289},[1290],{"id":830,"depth":404,"text":831},{"id":856,"depth":254,"text":857},{"id":1053,"depth":254,"text":1054},{"id":1168,"depth":254,"text":1169},{"id":1274,"depth":254,"text":1275},[9,67],false,"md",{"src":73,"alt":74},{},{"title":64,"description":65},null,"nginx-reverse-proxy","posts/nginx-reverse-proxy",[10,69,70],"2026-08-26","EyxbwbOVNR",[1308,1313,1318,1323,1328,1332,1337,1342,1347,1352,1357,1362],{"path":5,"title":6,"categories":1309,"tags":1310,"date":16,"draft":1296,"slug":1311,"description":7,"image":1312},[9,10],[12,13,14,15],"incident-checklist",{"src":18,"alt":19},{"path":21,"title":22,"categories":1314,"tags":1315,"date":31,"draft":1296,"slug":1316,"description":23,"image":1317},[25,26],[28,29,30,10],"backup-postgres-docker",{"src":33,"alt":34},{"path":36,"title":37,"categories":1319,"tags":1320,"date":44,"draft":1296,"slug":1321,"description":38,"image":1322},[25,10],[41,42,43],"docker-compose-production",{"src":46,"alt":47},{"path":49,"title":50,"categories":1324,"tags":1325,"date":58,"draft":1296,"slug":1326,"description":51,"image":1327},[9,10],[54,55,56,57],"monitoring-server-basics",{"src":60,"alt":61},{"path":63,"title":64,"categories":1329,"tags":1330,"date":71,"draft":1296,"slug":1302,"description":65,"image":1331},[9,67],[10,69,70],{"src":73,"alt":74},{"path":76,"title":77,"categories":1333,"tags":1334,"date":83,"draft":1296,"slug":1335,"description":78,"image":1336},[9,14],[81,82,10],"how-to-secure-a-vps",{"src":85,"alt":86},{"path":88,"title":89,"categories":1338,"tags":1339,"date":95,"draft":1296,"slug":1340,"description":90,"image":1341},[9,10],[93,94,43,41],"systemd-node-service",{"src":97,"alt":98},{"path":100,"title":101,"categories":1343,"tags":1344,"date":107,"draft":1296,"slug":1345,"description":102,"image":1346},[9,25],[105,10,106],"how-to-install-docker-on-ubuntu-server",{"src":109,"alt":110},{"path":112,"title":113,"categories":1348,"tags":1349,"date":118,"draft":1296,"slug":1350,"description":114,"image":1351},[9,14],[117,10,15],"ssh-key-authentication",{"src":120,"alt":121},{"path":123,"title":124,"categories":1353,"tags":1354,"date":131,"draft":1296,"slug":1355,"description":125,"image":1356},[9,14],[128,129,130,15],"ufw-firewall-basics",{"src":133,"alt":134},{"path":136,"title":137,"categories":1358,"tags":1359,"date":145,"draft":1296,"slug":1360,"description":138,"image":1361},[140,10],[142,143,144,30],"git-deploy-key",{"src":147,"alt":148},{"path":150,"title":151,"categories":1363,"tags":1364,"date":155,"draft":1296,"slug":1365,"description":152,"image":1366},[9],[106,105,15],"ubuntu-server-initial-setup",{"src":157,"alt":158},[],1789616168121]