16. Live Project: Building a Reels App with EC2, S3 and RDS
16.11 Domain and HTTPS
Part 6 pramane subdomain aani Certbot.
- GoDaddy (or Route 53) → add an A record: Name
reels→ your Elastic IP. Check withdig reels.yourdomain.com +short. - Get the certificate and redirect HTTP to HTTPS:
sudo yum install -y certbot python3-certbot-nginx # Ubuntu: sudo apt install -y certbot python3-certbot-nginx
sudo certbot --nginx -d reels.yourdomain.com --redirect
sudo certbot renew --dry-run
- Set
'cookie_secure' => trueinconfig.php, thensudo service php-fpm restart. - Add HSTS inside the new
listen 443server block Certbot created, test and reload:
add_header Strict-Transport-Security "max-age=31536000" always;
sudo nginx -t && sudo service nginx reload
curl -I http://reels.yourdomain.com # 301 → https
curl -sI https://reels.yourdomain.com/login.php | grep -Ei 'strict|content-security|x-frame'
add_header inheritance in Nginx
If a location block has its own add_header, Nginx drops the server-level headers for that location. Keep all security headers at server level (as in reels.conf) and check them with curl -sI after every change.
Ravindra Bagale's Tip
HTTPS lavlyavar login "hot nahi" – page reload hoto aani parat login page. Karan: cookie_secure true aahe pan tumhi ajun http:// var aahat, kiwa ulat. Nehmi HTTPS URL vapra aani redirect chalu aahe ka curl -I ne check kara.
Lab
Point reels.yourdomain.com to your Elastic IP, run Certbot with --redirect, switch cookie_secure to true, add HSTS, and confirm the headers with curl -sI.