# the published listener, which is what the suite and the browser use server { listen 443 ssl; server_name host-site-https; ssl_certificate /etc/nginx/tls/cert.pem; ssl_certificate_key /etc/nginx/tls/key.pem; root /usr/share/nginx/html; index post-https.html; } # for the container healthcheck only, and not published. busybox wget, which is all this image # carries, has no TLS, so a check against the listener above cannot tell "not started yet" from # "cannot speak https at all" server { listen 80; server_name localhost; root /usr/share/nginx/html; index post-https.html; }