server { listen 80; server_name _; root /var/www/html; index index.php; server_tokens off; client_max_body_size 64k; # Container healthcheck. Must not hit /wp-trap.php — that would log every # probe as an attack. location = /health { access_log off; default_type text/plain; return 200 "ok\n"; } # Block access to config file location = /wp-trap-config.php { return 403; } # Honeypot rewrites: route wp-login.php and wp-admin to trap. # Cookie test is anchored to the cookie-name boundary so an attacker # can't bypass with Cookie: bypass=wordpress_logged_in_x. location = /wp-login.php { if ($http_cookie !~* "(^|;\s*)wordpress_logged_in_[a-f0-9]+=") { rewrite ^ /wp-trap.php last; } try_files $uri =404; } location = /wp-admin { if ($http_cookie !~* "(^|;\s*)wordpress_logged_in_[a-f0-9]+=") { rewrite ^ /wp-trap.php last; } try_files $uri =404; } location ~ \.php$ { try_files $uri =404; fastcgi_pass 127.0.0.1:9000; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; include fastcgi_params; } location / { try_files $uri $uri/ =404; } }