HAProxy 2.5.0容器执行docker compose up -d后启动即终止求助
问题:HAProxy 2.5.0容器启动后随即终止,启动haproxy时内存分配失败
环境与现象
- 运行4个Docker容器:MongoDB、apostrophe、astro、HAProxy 2.5.0
- 前3个容器运行正常,HAProxy容器执行
docker compose up -d后看似启动成功,但docker ps中无该容器 - 进入容器手动执行
haproxy -f /usr/local/etc/haproxy/haproxy.cfg时触发内存分配错误
docker-compose.yml配置
version: '3.4' services: astro: command: tail -f /dev/null apostrophe: command: tail -f /dev/null haproxy: command: tail -f /dev/null
当前容器状态
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES ecaa68d94c73 haproxy:2.5.0 "docker-entrypoint.s…" 6 seconds ago Up 5 seconds 0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp project-haproxy-1 d9e938b2ef07 mongo:6 "docker-entrypoint.s…" 7 seconds ago Up 6 seconds 0.0.0.0:27017->27017/tcp, :::27017->27017/tcp project-mongodb-1 0426f9e80cba project-apostrophe "docker-entrypoint.s…" 7 seconds ago Up 6 seconds 0.0.0.0:3000->3000/tcp, :::3000->3000/tcp project-apostrophe-1 3f2ed94657d0 project-astro "docker-entrypoint.s…" 7 seconds ago Up 6 seconds 0.0.0.0:4000->4000/tcp, :::4000->4000/tcp project-astro-1
手动启动HAProxy的报错信息
$ ls -l /etc/ssl/private/local.dgadteamdev.com.pem -rw-r--r--. 1 1000 1000 3008 Apr 3 13:18 /etc/ssl/private/local.dgadteamdev.com.pem $ haproxy -f /usr/local/etc/haproxy/haproxy.cfg [NOTICE] (14) : haproxy version is 2.5.0-f2e0833 [NOTICE] (14) : path to executable is /usr/local/sbin/haproxy [ALERT] (14) : Not enough memory to allocate 1073741816 entries for fdtab! [ALERT] (14) : No polling mechanism available. It is likely that haproxy was built with TARGET=generic and that FD_SETSIZE is too low on this platform to support maxconn and the number of listeners and servers. You should rebuild haproxy specifying your system using TARGET= in order to support other polling systems (poll, epoll, kqueue) or reduce the global maxconn setting to accommodate the system's limitation. For reference, FD_SETSIZE=1024 on this system, global.maxconn=536870878 resulting in a maximum of 1073741816 file descriptors. You should thus reduce global.maxconn by 536870396. Also, check build settings using 'haproxy -vv'.
haproxy -vv输出结果
$ haproxy -vv HAProxy version 2.5.0-f2e0833 2021/11/23 Status: stable branch - will stop receiving fixes around Q1 2023. Known bugs: Running on: Linux 6.6.14-200.fc39.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Jan 26 20:12:16 UTC 2024 x86_64 Build options : TARGET = linux-glibc CPU = generic CC = cc CFLAGS = -O2 -g -Wall -Wextra -Wundef -Wdeclaration-after-statement -fwrapv -Wno-address-of-packed-member -Wno-unused-label -Wno-sign-compare -Wno-unused-parameter -Wno-clobbered -Wno-missing-field-initializers -Wno-cast-function-type -Wtype-limits -Wshift-negative-value -Wshift-overflow=2 -Wduplicated-cond -Wnull-dereference OPTIONS = USE_PCRE2=1 USE_PCRE2_JIT=1 USE_GETADDRINFO=1 USE_OPENSSL=1 USE_LUA=1 USE_PROMEX=1 DEBUG = Feature list : +EPOLL -KQUEUE +NETFILTER -PCRE -PCRE_JIT +PCRE2 +PCRE2_JIT +POLL +THREAD +BACKTRACE -STATIC_PCRE -STATIC_PCRE2 +TPROXY +LINUX_TPROXY +LINUX_SPLICE +LIBCRYPT +CRYPT_H +GETADDRINFO +OPENSSL +LUA +ACCEPT4 -CLOSEFROM -ZLIB +SLZ +CPU_AFFINITY +TFO +NS +DL +RT -DEVICEATLAS -51DEGREES -WURFL -SYSTEMD -OBSOLETE_LINKER +PRCTL -PROCCTL +THREAD_DUMP -EVPORTS -OT -QUIC +PROMEX -MEMORY_PROFILING Default settings : bufsize = 16384, maxrewrite = 1024, maxpollevents = 200 Built with multi-threading support (MAX_THREADS=64, default=16). Built with OpenSSL version : OpenSSL 1.1.1k 25 Mar 2021 Running on OpenSSL version : OpenSSL 1.1.1k 25 Mar 2021 OpenSSL library supports TLS extensions : yes OpenSSL library supports SNI : yes OpenSSL library supports : TLSv1.0 TLSv1.1 TLSv1.2 TLSv1.3 Built with Lua version : Lua 5.3.3 Built with the Prometheus exporter as a service Built with network namespace support. Built with libslz for stateless compression. Compression algorithms supported : identity("identity"), deflate("deflate"), raw-deflate("deflate"), gzip("gzip") Support for malloc_trim() is enabled. Built with transparent proxy support using: IP_TRANSPARENT IPV6_TRANSPARENT IP_FREEBIND Built with PCRE2 version : 10.36 2020-12-04 PCRE2 library supports JIT : yes Encrypted password support via crypt(3): yes Built with gcc compiler version 10.2.1 20210110 Available polling systems : epoll : pref=300, test result OK poll : pref=200, test result OK select : pref=150, test result OK Total: 3 (3 usable), will use epoll. Available multiplexer protocols : (protocols marked as <default> cannot be specified using 'proto' keyword) h2 : mode=HTTP side=FE|BE mux=H2 flags=HTX|CLEAN_ABRT|HOL_RISK|NO_UPG fcgi : mode=HTTP side=BE mux=FCGI flags=HTX|HOL_RISK|NO_UPG <default> : mode=HTTP side=FE|BE mux=H1 flags=HTX h1 : mode=HTTP side=FE|BE mux=H1 flags=HTX|NO_UPG <default> : mode=TCP side=FE|BE mux=PASS flags= none : mode=TCP side=FE|BE mux=PASS flags=NO_UPG Available services : prometheus-exporter Available filters : [SPOE] spoe [CACHE] cache [FCGI] fcgi-app [COMP] compression [TRACE] trace
解决方案
核心问题
报错明确指出global.maxconn=536870878值过大,远超系统FD_SETSIZE=1024的限制,导致需要分配10亿+文件描述符,内存无法承受。
具体修复步骤
修改HAProxy配置文件:
进入HAProxy容器,编辑/usr/local/etc/haproxy/haproxy.cfg,在global段中设置合理的maxconn值,比如:global maxconn 1024 # 保留其他原有配置也可根据业务需求设置更小值(如512、256),确保不超过系统FD限制。
调整Docker容器启动命令:
当前docker-compose中HAProxy用tail -f /dev/null维持容器运行,并非HAProxy正常启动方式。应让容器执行默认启动命令或指定配置文件:
修改docker-compose.yml中的haproxy服务:haproxy: # 替换tail命令,使用HAProxy启动命令加载配置 command: haproxy -f /usr/local/etc/haproxy/haproxy.cfg # 可选:挂载本地自定义配置文件到容器,方便后续修改 volumes: - ./haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg:ro验证修复效果:
- 重启容器:
docker compose down && docker compose up -d - 检查容器状态:
docker ps确认HAProxy容器持续运行 - 验证配置语法:
docker exec -it project-haproxy-1 haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg,确保配置无错误
- 重启容器:
额外优化(可选):
若需更高并发连接数:- 调整宿主机文件描述符限制(修改
/etc/security/limits.conf) - 确保HAProxy使用
epoll(从输出看已支持且默认启用),避免select的FD_SETSIZE限制
- 调整宿主机文件描述符限制(修改
内容的提问来源于stack exchange,提问作者Jean Mary
相关产品推荐
相关产品推荐

