Nginx stops accepting connections once worker_connections is exhausted, which Cloudflare sees as a refused handshake rather than a slow page.
Nginx stops accepting connections once worker_connections is exhausted, which Cloudflare sees as a refused handshake rather than a slow page.
Raise worker_connections and worker_processes, confirm the box is not out of file descriptors (ulimit -n), and check that ufw or the cloud firewall allows 443 from Cloudflare's ranges.
Nginx has its own failure mode, but Cloudflare Error 522 has a wider set of causes. The most common one overall is: The origin firewall silently drops Cloudflare's IP ranges.
Allowlist Cloudflare's IP ranges with an accept rule, and make sure the default policy does not drop them earlier in the chain.
Probing the origin address directly shows whether it is reachable from outside Cloudflare, which immediately tells you whether the fault is the firewall or the host.
Nginx stops accepting connections once worker_connections is exhausted, which Cloudflare sees as a refused handshake rather than a slow page.
Raise worker_connections and worker_processes, confirm the box is not out of file descriptors (ulimit -n), and check that ufw or the cloud firewall allows 443 from Cloudflare's ranges.
Cloudflare tried to open a connection to the origin and nothing answered before the timeout. Usually a firewall silently dropping Cloudflare's traffic, an overloaded origin, or a wrong origin IP.