nginx 1.18

1.18 released 21 April 2020, latest 1.18.0.

nginx 1.18 reached end of life on 20 April 2021.

What changed

NGINX 1.18 is a stable release line that consolidated the work delivered through the preceding 1.17 mainline series, following the earlier 1.16 stable line. The accumulated changes included configuration and operational controls such as delayed authentication responses, dry-run modes for request and connection limiting, proxy cookie flag controls, TLS early-data handling, and additional variables and proxying improvements. As a stable line, it was intended to provide a fixed feature set with subsequent maintenance fixes rather than continued feature development.

What staying costs

NGINX 1.18 has reached end of life and no longer receives upstream security fixes, defect corrections, or compatibility maintenance. A newly discovered issue in the core server or an included module will not be remediated in this line. Staying on it also increases operational risk as operating-system packages, OpenSSL versions, client TLS behavior, HTTP/2 implementations, and third-party modules move forward. The practical result is a growing need to accept unpatched risk, carry local fixes, or constrain upgrades elsewhere in the platform.

What to do

Plan a move to a currently maintained NGINX release line. First inventory the installed build, enabled modules, package source, custom patches, TLS settings, upstream definitions, and any third-party dynamic modules. Rebuild or obtain compatible versions of third-party modules for the target release, since module binary compatibility must not be assumed. Test the target version in a representative environment with production configuration, certificates, traffic patterns, HTTP/2 and TLS clients, rate limits, caching, authentication, and upstream failure handling. Roll out gradually with configuration validation, health checks, error and latency monitoring, and a tested rollback path. After the migration, remove obsolete compatibility workarounds and establish a routine for tracking supported NGINX releases.

We can tell you what moving off nginx 1.18 involves.

What it takes to move off nginx 1.18 depends on what you built on it — the version you are on, how much depends on it, and how much of the work is mechanical. Leave your email with this version and we can tell you what that looks like for you.

Not sure yet? Get my plan