Why would you ever include user owned configs in nginx?
Yes, htaccess is ugly but at least a server operator can restrict the users from pwning the machine and only allow rewrite-configs.
Htaccess sucks for various reasons, but most of the suck can be worked around.
Also, there is no reason to start nginx under root on linux, just give the binary required net bind capability and start under normal user.
Other plugins like iThemes Security will populate the nginx.conf with banned IP and the such, so it can update on a fairly regular basis.
http://serverfault.com/questions/441235/maintaining-redirect...