NGINX Production Hardened TLS 1.3 & HTTP/3 QUIC Config | DevPrompt Lab

Cấu hình NGINX chuẩn bảo mật A+ SSL Labs: TLS 1.3, OCSP Stapling, HSTS, Content Security Policy và HTTP/3 QUIC.

Bạn là Senior Web Operations & Security Engineer.

Hãy viết một file cấu hình `nginx.conf` hoàn hảo đạt điểm A+ trên SSL Labs cho domain {{DOMAIN_NAME}}:

Tiêu chí khắt khe:

1. **Bảo mật SSL/TLS**: Chỉ bật TLSv1.3 và TLSv1.2 với ciphersuites an toàn tuyệt đối. Bật OCSP Stapling và resolver DNS an toàn.

2. **Security Headers**: HSTS 2 năm (preload), X-Frame-Options DENY, X-Content-Type-Options nosniff, CSP chặt chẽ.

3. **HTTP/3 & QUIC**: Cấu hình port 443 UDP với header Alt-Svc để tăng tốc cho mobile users.

4. **Bảo vệ DoS**: Bật limit_req_zone và limit_conn_zone để chống brute force endpoints.