SysAdmin Tools

HestiaCP Nginx Template Generator

Create custom .tpl and .stpl web templates for HestiaCP — reverse proxy for Node.js, static sites, PHP apps and more.


Advertisement

Test Before Applying

Generated configuration is a starting point. Always:

  • Test in a non-production environment
  • Validate syntax before reloading services
  • Keep a backup of your working config
  • Adapt to your specific server setup

SysAdmin Tools provides this as a reference only and is not responsible for service interruptions.

1. Template Type
2. Template Name
3. Reverse Proxy
4. Common Options
5. Cache Options
# HestiaCP nginx HTTP template (.tpl) — generated by SysAdmin Tools
server {
    listen      %ip%:%web_port%;
    server_name %domain_idn% %alias_idn%;
    return 301 https://$host$request_uri;
}

Install instructions

1. Save as /usr/local/hestia/data/templates/web/nginx/php-fpm/nodejs.tpl

2. Save the .stpl version in the same location

3. v-change-web-domain-tpl USER DOMAIN nodejs

4. nginx -t && systemctl reload nginx

Advertisement

Advertisement

This HestiaCP nginx template generator builds the .tpl (HTTP) and .stpl (HTTPS) web template files HestiaCP uses to render each domain's Nginx config. Create a reverse-proxy template for a Node.js or Next.js app, a static-site template, or a PHP template — complete with HestiaCP's %variable% placeholders — and drop them into the panel's template directory.

HestiaCP generates every domain's Nginx vhost from a named template, substituting variables like %ip%, %domain%, %web_port%, %ssl_pem% and %ssl_key% at render time. Writing a correct HestiaCP custom nginx template by hand means knowing which variables exist and keeping the .tpl and .stpl versions in sync. This HestiaCP template generator produces both files together so your HestiaCP nodejs template or reverse proxy works on the first apply.

Everything runs client-side. Generate the pair, save them under /usr/local/hestia/data/templates/web/nginx/, assign the template with v-change-web-domain-tpl, then test and reload Nginx.

How to Use the HestiaCP Template Generator

  1. 1

    Choose a template type

    Pick Reverse Proxy (for Node.js, Next.js and other app servers), Static Site, PHP App, or Custom. This decides the core location blocks generated.

  2. 2

    Name the template

    Give the template a short name such as nextjs or nodejs-3000. This becomes the .tpl/.stpl filename and the name you pass to v-change-web-domain-tpl.

  3. 3

    Configure the proxy (if applicable)

    For a reverse proxy, set the upstream port and host, enable WebSocket support, and set the read timeout so long requests are not cut off.

  4. 4

    Toggle common and cache options

    Enable HTTPS redirect, HSTS, gzip, access logging, custom error pages and long-lived static asset caching as needed. The HTTPS (.stpl) template includes the SSL certificate directives automatically.

  5. 5

    Copy both files and apply

    Copy the .tpl and .stpl tabs into the HestiaCP template directory, run v-change-web-domain-tpl for your user and domain, then nginx -t && systemctl reload nginx.

Understanding HestiaCP Nginx Templates

HestiaCP does not store a static Nginx config per domain. Instead it stores a template and renders the real vhost whenever a domain is created or changed, substituting %variable% tokens with that domain's values. Templates live under /usr/local/hestia/data/templates/web/nginx/ (and the php-fpm/ subfolder for PHP-FPM templates). Each template is a pair: a .tpl file for the HTTP (port 80) vhost and a matching .stpl file for the HTTPS (port 443) vhost. The two files are almost identical, differing mainly in the listen directive and the SSL block. The .stpl adds listen %ip%:%web_ssl_port% ssl; plus ssl_certificate %ssl_pem%; and ssl_certificate_key %ssl_key%; — HestiaCP fills those paths from the domain's installed certificate. Keeping the two in sync is essential, which is why this generator always emits both. Common variables include %ip% (the server IP), %domain% and %domain_idn% (the domain, and its punycode form), %web_port% / %web_ssl_port% (the panel's configured HTTP/HTTPS ports), %user% (the account username, used in paths), %docroot% (the document root), and %sdocroot%. For a reverse proxy you add a location / with proxy_pass to your app's port and the standard proxy headers.
FieldDescription
.tplThe HTTP (port 80) template file HestiaCP renders into the non-SSL vhost.
.stplThe HTTPS (port 443) template, identical to .tpl plus the SSL certificate directives.
%ip%The server IP address the vhost listens on.
%domain% / %domain_idn%The domain name and its IDN/punycode form for server_name.
%web_port% / %web_ssl_port%The HTTP and HTTPS ports configured in the HestiaCP panel.
%docroot%The document root path for the domain, e.g. /home/%user%/web/%domain%/public_html.
%ssl_pem% / %ssl_key%Paths to the domain's certificate and private key, used only in the .stpl file.
%user%The HestiaCP account username, used to build home-directory paths.

Advertisement

Common HestiaCP Template Use Cases

Reverse proxy for Next.js / Node.js

Generate a proxy template that forwards to a Node.js app on 127.0.0.1:3000 with WebSocket upgrade headers, so HestiaCP serves your Next.js site behind Nginx with SSL.

Run multiple apps on one server

Create differently named templates (nodejs-3000, nodejs-4000) and assign each domain its own, letting one HestiaCP server front several app processes on different ports.

Custom PHP app template

Build a PHP template with a front-controller try_files rule and hidden-file protection for frameworks like Laravel, while keeping HestiaCP's managed PHP-FPM integration.

Harden a static site

Produce a static-site template with gzip, long-lived asset caching and security defaults, applied consistently across every static domain on the panel.

HestiaCP Nginx Template — Frequently Asked Questions

What is a HestiaCP nginx template?
A HestiaCP nginx template is a parameterised Nginx config stored by the control panel and used to generate each domain's actual vhost. Rather than editing a domain's config directly, you edit the template, and HestiaCP renders the real config by replacing %variable% tokens (like %ip%, %domain%, %docroot%) with that domain's values. Each template is a pair of files: a .tpl for HTTP and a .stpl for HTTPS.
How to create a custom HestiaCP template?
Create a .tpl and a matching .stpl file under /usr/local/hestia/data/templates/web/nginx/ (or the php-fpm subfolder for PHP templates), using HestiaCP variables for the dynamic parts. Give them the same base name, e.g. myapp.tpl and myapp.stpl. Then assign the template to a domain with v-change-web-domain-tpl user domain myapp, and reload Nginx. This generator produces both files with the correct variables for you.
How to set up Node.js with HestiaCP?
Run your Node.js app on a local port (e.g. 3000) under a process manager like PM2, then create a reverse-proxy nginx template that proxy_passes to http://127.0.0.1:3000 with the WebSocket upgrade headers. Assign that template to your domain in HestiaCP and let the panel manage SSL. The app stays private on localhost while Nginx handles TLS and public traffic.
What are .tpl and .stpl files in HestiaCP?
They are the two halves of an Nginx web template. The .tpl file defines the HTTP (port 80) server block, while the .stpl file defines the HTTPS (port 443) server block and additionally includes the ssl_certificate and ssl_certificate_key directives (filled from %ssl_pem% and %ssl_key%). They must share the same base name and be kept in sync, which is why tools generate them as a pair.
How to deploy Next.js on HestiaCP?
Build and start your Next.js app with next start (or PM2) on a local port such as 3000, create a reverse-proxy HestiaCP template proxying to that port with WebSocket support and a sensible read timeout, assign it to your domain, then issue an SSL certificate through the panel (Let's Encrypt). HestiaCP's .stpl handles HTTPS termination while Next.js runs behind it.
What HestiaCP template variables are available?
Common variables include %ip% (server IP), %domain% and %domain_idn% (domain and its punycode), %web_port% and %web_ssl_port% (configured HTTP/HTTPS ports), %user% (account name), %docroot% and %sdocroot% (document roots), %home% (home directory), and in .stpl files %ssl_pem% and %ssl_key% for the certificate paths. HestiaCP substitutes these when rendering the vhost from the template.
How to apply a custom template in HestiaCP?
After saving your .tpl and .stpl files in the templates directory, run v-change-web-domain-tpl USER DOMAIN TEMPLATE (for example v-change-web-domain-tpl admin example.com nextjs). HestiaCP re-renders the domain's vhost from your template. Then run nginx -t to validate and systemctl reload nginx to apply. You can also select the template in the panel UI under the domain's advanced options.
How to create a reverse proxy in HestiaCP?
Use a reverse-proxy nginx template whose location / block contains proxy_pass to your upstream (e.g. http://127.0.0.1:3000), along with proxy_set_header directives for Host, X-Real-IP, X-Forwarded-For and X-Forwarded-Proto, plus the Upgrade/Connection headers for WebSockets. Assign it to the domain. This generator's Reverse Proxy type produces exactly this layout in both .tpl and .stpl.
How to add HTTPS to a HestiaCP nginx template?
HTTPS lives in the .stpl file: it listens on %ip%:%web_ssl_port% ssl and includes ssl_certificate %ssl_pem%; and ssl_certificate_key %ssl_key%;. You do not hard-code certificate paths — HestiaCP fills them from the domain's issued certificate. To force HTTPS, enable the HTTPS redirect option so the .tpl (port 80) returns a 301 to the secure URL.
How to reload nginx after a template change?
First re-render affected domains (v-change-web-domain-tpl, or v-rebuild-web-domains USER to rebuild all of a user's domains), then validate the generated config with nginx -t. If it reports syntax is ok, apply it with systemctl reload nginx (a graceful reload that does not drop connections). Never skip nginx -t — a template typo can otherwise take every site on the server offline.
Where exactly do the template files go?
Standard Nginx web templates go in /usr/local/hestia/data/templates/web/nginx/, and PHP-FPM variants in /usr/local/hestia/data/templates/web/nginx/php-fpm/. Save both the .tpl and .stpl with the same base name. After placing them, assign the template to a domain and reload Nginx. Keep a backup of any template you modify so you can roll back quickly.

Related Tools