You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

HAProxy 2.5.0容器执行docker compose up -d后启动即终止求助

问题:HAProxy 2.5.0容器启动后随即终止,启动haproxy时内存分配失败

环境与现象

  • 运行4个Docker容器:MongoDB、apostrophe、astro、HAProxy 2.5.0
  • 前3个容器运行正常,HAProxy容器执行docker compose up -d后看似启动成功,但docker ps中无该容器
  • 进入容器手动执行haproxy -f /usr/local/etc/haproxy/haproxy.cfg时触发内存分配错误

docker-compose.yml配置

version: '3.4'
services:
  astro:
    command: tail -f /dev/null
  apostrophe:
    command: tail -f /dev/null
  haproxy:
    command: tail -f /dev/null

当前容器状态

CONTAINER ID   IMAGE                COMMAND                  CREATED         STATUS         PORTS                                                                      NAMES
ecaa68d94c73   haproxy:2.5.0        "docker-entrypoint.s…"   6 seconds ago   Up 5 seconds   0.0.0.0:80->80/tcp, :::80->80/tcp, 0.0.0.0:443->443/tcp, :::443->443/tcp   project-haproxy-1
d9e938b2ef07   mongo:6              "docker-entrypoint.s…"   7 seconds ago   Up 6 seconds   0.0.0.0:27017->27017/tcp, :::27017->27017/tcp                              project-mongodb-1
0426f9e80cba   project-apostrophe   "docker-entrypoint.s…"   7 seconds ago   Up 6 seconds   0.0.0.0:3000->3000/tcp, :::3000->3000/tcp                                  project-apostrophe-1
3f2ed94657d0   project-astro        "docker-entrypoint.s…"   7 seconds ago   Up 6 seconds   0.0.0.0:4000->4000/tcp, :::4000->4000/tcp                                  project-astro-1

手动启动HAProxy的报错信息

$ ls -l /etc/ssl/private/local.dgadteamdev.com.pem
-rw-r--r--. 1 1000 1000 3008 Apr  3 13:18 /etc/ssl/private/local.dgadteamdev.com.pem
$ haproxy -f /usr/local/etc/haproxy/haproxy.cfg   
[NOTICE]   (14) : haproxy version is 2.5.0-f2e0833
[NOTICE]   (14) : path to executable is /usr/local/sbin/haproxy
[ALERT]    (14) : Not enough memory to allocate 1073741816 entries for fdtab!
[ALERT]    (14) : No polling mechanism available.
  It is likely that haproxy was built with TARGET=generic and that FD_SETSIZE
  is too low on this platform to support maxconn and the number of listeners
  and servers. You should rebuild haproxy specifying your system using TARGET=
  in order to support other polling systems (poll, epoll, kqueue) or reduce the
  global maxconn setting to accommodate the system's limitation. For reference,
  FD_SETSIZE=1024 on this system, global.maxconn=536870878 resulting in a maximum of
  1073741816 file descriptors. You should thus reduce global.maxconn by 536870396. Also,
  check build settings using 'haproxy -vv'.

haproxy -vv输出结果

$ haproxy -vv 
HAProxy version 2.5.0-f2e0833 2021/11/23
Status: stable branch - will stop receiving fixes around Q1 2023.
Known bugs: 
Running on: Linux 6.6.14-200.fc39.x86_64 #1 SMP PREEMPT_DYNAMIC Fri Jan 26 20:12:16 UTC 2024 x86_64
Build options :
  TARGET  = linux-glibc
  CPU     = generic
  CC      = cc
  CFLAGS  = -O2 -g -Wall -Wextra -Wundef -Wdeclaration-after-statement -fwrapv -Wno-address-of-packed-member -Wno-unused-label -Wno-sign-compare -Wno-unused-parameter -Wno-clobbered -Wno-missing-field-initializers -Wno-cast-function-type -Wtype-limits -Wshift-negative-value -Wshift-overflow=2 -Wduplicated-cond -Wnull-dereference
  OPTIONS = USE_PCRE2=1 USE_PCRE2_JIT=1 USE_GETADDRINFO=1 USE_OPENSSL=1 USE_LUA=1 USE_PROMEX=1
  DEBUG   = 

Feature list : +EPOLL -KQUEUE +NETFILTER -PCRE -PCRE_JIT +PCRE2 +PCRE2_JIT +POLL +THREAD +BACKTRACE -STATIC_PCRE -STATIC_PCRE2 +TPROXY +LINUX_TPROXY +LINUX_SPLICE +LIBCRYPT +CRYPT_H +GETADDRINFO +OPENSSL +LUA +ACCEPT4 -CLOSEFROM -ZLIB +SLZ +CPU_AFFINITY +TFO +NS +DL +RT -DEVICEATLAS -51DEGREES -WURFL -SYSTEMD -OBSOLETE_LINKER +PRCTL -PROCCTL +THREAD_DUMP -EVPORTS -OT -QUIC +PROMEX -MEMORY_PROFILING

Default settings :
  bufsize = 16384, maxrewrite = 1024, maxpollevents = 200

Built with multi-threading support (MAX_THREADS=64, default=16).
Built with OpenSSL version : OpenSSL 1.1.1k  25 Mar 2021
Running on OpenSSL version : OpenSSL 1.1.1k  25 Mar 2021
OpenSSL library supports TLS extensions : yes
OpenSSL library supports SNI : yes
OpenSSL library supports : TLSv1.0 TLSv1.1 TLSv1.2 TLSv1.3
Built with Lua version : Lua 5.3.3
Built with the Prometheus exporter as a service
Built with network namespace support.
Built with libslz for stateless compression.
Compression algorithms supported : identity("identity"), deflate("deflate"), raw-deflate("deflate"), gzip("gzip")
Support for malloc_trim() is enabled.
Built with transparent proxy support using: IP_TRANSPARENT IPV6_TRANSPARENT IP_FREEBIND
Built with PCRE2 version : 10.36 2020-12-04
PCRE2 library supports JIT : yes
Encrypted password support via crypt(3): yes
Built with gcc compiler version 10.2.1 20210110

Available polling systems :
      epoll : pref=300,  test result OK
       poll : pref=200,  test result OK
     select : pref=150,  test result OK
Total: 3 (3 usable), will use epoll.

Available multiplexer protocols :
(protocols marked as <default> cannot be specified using 'proto' keyword)
              h2 : mode=HTTP       side=FE|BE     mux=H2       flags=HTX|CLEAN_ABRT|HOL_RISK|NO_UPG
            fcgi : mode=HTTP       side=BE        mux=FCGI     flags=HTX|HOL_RISK|NO_UPG
       <default> : mode=HTTP       side=FE|BE     mux=H1       flags=HTX
              h1 : mode=HTTP       side=FE|BE     mux=H1       flags=HTX|NO_UPG
       <default> : mode=TCP        side=FE|BE     mux=PASS     flags=
            none : mode=TCP        side=FE|BE     mux=PASS     flags=NO_UPG

Available services : prometheus-exporter
Available filters :
        [SPOE] spoe
        [CACHE] cache
        [FCGI] fcgi-app
        [COMP] compression
        [TRACE] trace

解决方案

核心问题

报错明确指出global.maxconn=536870878值过大,远超系统FD_SETSIZE=1024的限制,导致需要分配10亿+文件描述符,内存无法承受。

具体修复步骤

  1. 修改HAProxy配置文件:
    进入HAProxy容器,编辑/usr/local/etc/haproxy/haproxy.cfg,在global段中设置合理的maxconn值,比如:

    global
      maxconn 1024
      # 保留其他原有配置
    

    也可根据业务需求设置更小值(如512、256),确保不超过系统FD限制。

  2. 调整Docker容器启动命令:
    当前docker-compose中HAProxy用tail -f /dev/null维持容器运行,并非HAProxy正常启动方式。应让容器执行默认启动命令或指定配置文件:
    修改docker-compose.yml中的haproxy服务:

    haproxy:
      # 替换tail命令,使用HAProxy启动命令加载配置
      command: haproxy -f /usr/local/etc/haproxy/haproxy.cfg
      # 可选:挂载本地自定义配置文件到容器,方便后续修改
      volumes:
        - ./haproxy.cfg:/usr/local/etc/haproxy/haproxy.cfg:ro
    
  3. 验证修复效果:

    • 重启容器:docker compose down && docker compose up -d
    • 检查容器状态:docker ps确认HAProxy容器持续运行
    • 验证配置语法:docker exec -it project-haproxy-1 haproxy -c -f /usr/local/etc/haproxy/haproxy.cfg,确保配置无错误
  4. 额外优化(可选):
    若需更高并发连接数:

    • 调整宿主机文件描述符限制(修改/etc/security/limits.conf)
    • 确保HAProxy使用epoll(从输出看已支持且默认启用),避免select的FD_SETSIZE限制

内容的提问来源于stack exchange,提问作者Jean Mary

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 07:38:11