树莓派搭配Nginx时MinIO超100MB文件上传卡顿故障排查
树莓派Docker部署MinIO大文件上传失败问题解决
问题现象
- 通过Nginx反向代理访问MinIO控制台,上传超过100MB文件时进度卡在3%-10%
- 直接通过IP+端口访问MinIO上传,Firefox提示
Error: A network error occurred.,Chrome提示Error: Error - File size too large
已尝试配置
Nginx配置
upstream minio_s3 { least_conn; server minio.localhost:9010; } upstream minio_console { least_conn; server minio.localhost:9011; } server { server_name example.com; ignore_invalid_headers off; client_max_body_size 0; proxy_buffering off; proxy_request_buffering off; location / { proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_connect_timeout 300; proxy_http_version 1.1; proxy_set_header Connection ""; chunked_transfer_encoding off; proxy_pass http://minio_s3; } ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers HIGH:!aNULL:!MD5; listen 443 ssl; } server { server_name example.com; ignore_invalid_headers off; client_max_body_size 16384M; proxy_buffering off; proxy_request_buffering off; proxy_connect_timeout 30m; proxy_read_timeout 30m; proxy_send_timeout 30m; fastcgi_read_timeout 999999; client_body_timeout 30m; client_body_temp_path /home/example/tmp; location / { proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-NginX-Proxy true; proxy_connect_timeout 999999; proxy_read_timeout 30m; proxy_send_timeout 30m; proxy_request_buffering off; send_timeout 30m; real_ip_header X-Real-IP; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Connection keep-alive; chunked_transfer_encoding off; tcp_nodelay on; proxy_pass http://minio_console/; } ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_ciphers HIGH:!aNULL:!MD5; ssl_session_timeout 1d; ssl_session_cache shared:SSL:50m; ssl_session_tickets off; add_header Strict-Transport-Security max-age=15768000; listen 443 ssl; } server { if ($host = example.com) { return 301 https://$host$request_uri; } server_name example.com; listen 80; return 404; }
Docker Compose配置
minio: image: minio/minio:latest env_file: - .env command: server --address ":${MINIO_API_PORT-9010}" --console-address ":${MINIO_PORT-9011}" /data ports: - '${MINIO_API_PORT-9010}:${MINIO_API_PORT-9010}' - '${MINIO_PORT-9011}:${MINIO_PORT-9011}' volumes: - './minio_data:/data' environment: - 'MINIO_ROOT_USER=${MINIO_ROOT_USER-username}' - 'MINIO_ROOT_PASSWORD=${MINIO_ROOT_PASSWORD-password}' - 'MINIO_DEFAULT_BUCKETS=${MINIO_DEFAULT_BUCKETS-avatars,apps}' - 'MINIO_SERVER_URL=${MINIO_SERVER_URL-http://minio.localhost:9010}' - 'MINIO_BROWSER_REDIRECT_URL=${MINIO_URL-http://minio.localhost:9011}'
MinIO配置导出
subnet license= api_key= proxy= # callhome enable=off frequency=24h drive max_timeout=15m site name= region= api requests_max=1600 requests_deadline=15m cluster_deadline=15m cors_allow_origin=* remote_transport_deadline=2h list_quorum=strict replication_priority=auto replication_max_workers=500 transition_workers=100 stale_uploads_cleanup_interval=6h stale_uploads_expiry=24h delete_cleanup_interval=5m odirect=on gzip_objects=on root_access=on sync_events=off object_max_versions=9223372036854775807 scanner speed=default alert_excess_versions=100 alert_excess_folders=50000 batch replication_workers_wait=0ms keyrotation_workers_wait=0ms expiration_workers_wait=0ms compression allow_encryption=off extensions=.txt,.log,.csv,.json,.tar,.xml,.bin mime_types=text/*,application/json,application/xml,binary/octet-stream,*,application/x-executable browser csp_policy="default-src 'self' 'unsafe-eval' 'unsafe-inline'; script-src 'self' https://unpkg.com; connect-src 'self' https://unpkg.com;" hsts_seconds=0 hsts_include_subdomains=off hsts_preload=off referrer_policy=strict-origin-when-cross-origin ilm transition_workers=100 expiration_workers=100
MinIO调试日志
mc: <DEBUG> GET /minio/admin/v3/trace?batch-expire=false&batch-keyrotation=false&batch-replication=false&bootstrap=false&decommission=false&err=false&ftp=false&healing=false&ilm=false&internal=false&os=false&rebalance=false&replication-resync=false&s3=true&scanner=false&storage=false&threshold=0s HTTP/1.1 Host: 127.0.0.1:9010 User-Agent: MinIO (linux; arm64) madmin-go/2.0.0 mc/RELEASE.2024-07-03T20-17-25Z Accept-Encoding: zstd,gzip Authorization: AWS4-HMAC-SHA256 Credential=Sha256/20240709//s3/aws4_request, SignedHeaders=host;x-amz-content-sha256;x-amz-date, Signature=**REDACTED** X-Amz-Content-Sha256: Sha256 X-Amz-Date: 20240709T063437Z mc: <DEBUG> HTTP/1.1 200 OK Transfer-Encoding: chunked Cache-Control: no-cache Content-Encoding: gzip Content-Type: text/event-stream Date: Tue, 09 Jul 2024 06:34:38 GMT Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Origin Vary: Accept-Encoding X-Accel-Buffering: no X-Amz-Id-2: ID X-Amz-Request-Id: ID X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block mc: <DEBUG> Response Time: 1.005568677s 2024-07-09T06:35:10.763 [200 OK] s3.GetBucketLocation mt-minio.drewdru.com/games/?location= 89.232.40.222,89.232.40.222 1.281ms ⇣ 1.252028ms ↑ 215 B ↓ 128 B
解决方案
1. 修正MinIO外部访问地址配置
当前MINIO_SERVER_URL和MINIO_BROWSER_REDIRECT_URL使用minio.localhost,会导致客户端无法正确解析API地址,替换为实际域名:
environment: - 'MINIO_SERVER_URL=https://example.com' - 'MINIO_BROWSER_REDIRECT_URL=https://example.com/console'
2. 重构Nginx配置(解决多server块冲突)
合并两个443端口的server块,通过路径区分API和控制台,同时使用Docker内部服务名避免DNS解析问题:
upstream minio_s3 { least_conn; server minio:9010; } upstream minio_console { least_conn; server minio:9011; } server { server_name example.com; ignore_invalid_headers off; client_max_body_size 0; proxy_buffering off; proxy_request_buffering off; client_body_timeout 30m; proxy_connect_timeout 30m; proxy_read_timeout 30m; proxy_send_timeout 30m; # MinIO API路径 location / { proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_http_version 1.1; proxy_set_header Connection ""; chunked_transfer_encoding off; proxy_pass http://minio_s3; } # MinIO控制台路径 location /console/ { proxy_set_header Host $http_host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; chunked_transfer_encoding off; tcp_nodelay on; proxy_pass http://minio_console/; } ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; listen 443 ssl; } server { if ($host = example.com) { return 301 https://$host$request_uri; } server_name example.com; listen 80; return 404; }
3. 调整MinIO分片上传参数
通过环境变量增大分片尺寸并延长上传超时:
environment: - 'MINIO_PART_SIZE=100MiB' - 'MINIO_UPLOAD_TIMEOUT=30m'
4. 统一Docker网络
将MinIO和Nginx加入同一自定义网络,提升容器间传输效率:
version: '3.8' networks: minio-network: driver: bridge services: minio: # 原有MinIO配置... networks: - minio-network nginx: image: nginx:alpine volumes: - ./nginx.conf:/etc/nginx/nginx.conf - ./ssl:/etc/letsencrypt ports: - '80:80' - '443:443' networks: - minio-network
5. 检查树莓派系统限制
- 提升文件描述符限制:
ulimit -n 65535 # 永久生效:编辑/etc/security/limits.conf,添加 # * soft nofile 65535 # * hard nofile 65535 - 测试SSD写入性能,排除存储瓶颈:
dd if=/dev/zero of=testfile bs=1G count=1 oflag=direct
内容的提问来源于stack exchange,提问作者Drew Dru
相关产品推荐
相关产品推荐

