You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx持续因Signal结果崩溃,需手动重启,求解决办法

Nginx 周期性崩溃排查与解决

环境信息

  • 服务器:DigitalOcean,系统版本 5.15.0-100-generic #110-Ubuntu
  • 服务架构:PM2 托管多端口运行的 NextJS 前端 + NodeJS 后端,通过 Nginx 反向代理到不同子域名
  • Nginx 版本:nginx/1.18.0 (Ubuntu)
  • SSL 证书:Certbot 1.21.0 签发的主域名+通配符子域名证书

问题现象

Nginx 每隔几天会崩溃,需手动执行 systemctl restart nginx 恢复。崩溃时服务状态:

nginx.service - A high performance web server and a reverse proxy server
     Loaded: loaded (/lib/systemd/system/nginx.service; enabled; vendor preset: enabled)
     Active: failed (Result: signal) since Sun 2024-04-21 08:05:01 UTC; 6h ago
       Docs: man:nginx(8)
   Main PID: 1080798 (code=killed, signal=KILL)
        CPU: 22.910s

对应时间点 Nginx 错误日志无异常,但 /var/log/syslog 有以下关键记录:

Apr 21 07:45:01 [REDACTED FOR PRIVACY] CRON[1218696]: (root) CMD (command -v debian-sa1 > /dev/null && debian-sa1 1 1)
Apr 21 07:55:02 [REDACTED FOR PRIVACY] CRON[1219317]: (root) CMD (command -v debian-sa1 > /dev/null && debian-sa1 1 1)
Apr 21 08:05:01 [REDACTED FOR PRIVACY] CRON[1219922]: (root) CMD (command -v debian-sa1 > /dev/null && debian-sa1 1 1)
Apr 21 08:05:01 [REDACTED FOR PRIVACY] CRON[1219923]: (root) CMD (/tmp/.X291-unix/.rsync/b/sync>/dev/null 2>&1)
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: session-3017.scope: Deactivated successfully.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: session-3017.scope: Consumed 1w 4d 9h 37min 52.082s CPU time.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Main process exited, code=killed, status=9/KILL
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Killing process 1082832 (nginx) with signal SIGKILL.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Killing process 1082835 (nginx) with signal SIGKILL.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Killing process 1082832 (nginx) with signal SIGKILL.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Killing process 1082835 (nginx) with signal SIGKILL.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Failed with result 'signal'.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Unit process 1082832 (nginx) remains running after unit stopped.
Apr 21 08:05:01 [REDACTED FOR PRIVACY] systemd[1]: nginx.service: Unit process 1082835 (nginx) remains running after unit stopped.

排查与解决步骤

1. 清理可疑 Cron 任务

从日志时间线看,Nginx 崩溃与这条非常规 Cron 任务完全同步:

Apr 21 08:05:01 [REDACTED FOR PRIVACY] CRON[1219923]: (root) CMD (/tmp/.X291-unix/.rsync/b/sync>/dev/null 2>&1)

执行以下操作:

  • 删除可疑路径文件:rm -rf /tmp/.X291-unix
  • 查看 root 用户 Cron 列表:crontab -u root -l,找到并删除该可疑任务
  • 检查服务器异常进程、登录记录,排查入侵迹象

2. 修复 Nginx 进程残留问题

日志显示主进程被 SIGKILL 后子进程残留,导致服务无法正常恢复。修改 systemd 配置强制清理:

  • 编辑 /lib/systemd/system/nginx.service,在 [Service] 段添加:
    ExecStopPost=/bin/kill -9 $(pgrep nginx)
    
  • 重新加载 systemd 配置:systemctl daemon-reload
  • 重启 Nginx:systemctl restart nginx

3. 排除 Certbot 影响

Certbot 自动续期重载 Nginx一般不会导致崩溃,可做如下验证:

  • 执行续期测试:certbot renew --dry-run,观察 Nginx 状态
  • 检查 Certbot 日志 /var/log/letsencrypt/letsencrypt.log,确认续期操作无异常
  • 若怀疑重载问题,可临时将续期脚本中的 reload 改为 restart(非长期方案)

4. 配置 Nginx 自动重启

通过 systemd 实现崩溃后自动恢复:

  • 编辑 /lib/systemd/system/nginx.service,在 [Service] 段添加:
    Restart=always
    RestartSec=5
    
  • 重新加载配置并重启:systemctl daemon-reload && systemctl restart nginx

5. 升级 Nginx 版本

当前使用的 1.18.0 为 Ubuntu 20.04 默认版本,存在已知 bug,建议升级到官方稳定版:

  • 添加 Nginx 官方源:
    echo "deb http://nginx.org/packages/ubuntu/ focal nginx" | sudo tee /etc/apt/sources.list.d/nginx.list
    curl -fsSL https://nginx.org/keys/nginx_signing.key | sudo apt-key add -
    
  • 更新并安装:apt update && apt install nginx

内容的提问来源于stack exchange,提问作者Francesco Vecchi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 10:35:12