DigitalOcean Droplets上Nginx负载均衡器配置异常,出现503服务不可用错误
以下是针对你遇到的问题的排查和解决步骤:
1. 检查Nginx Upstream配置正确性
确保负载均衡器的Nginx配置中,upstream块正确指向后端服务器的私有IP和端口,并且配置了合理的健康检查参数:
upstream backend_servers { # 替换为你的后端私有IP和应用端口 server 10.128.0.10:3000 max_fails=3 fail_timeout=30s; server 10.128.0.11:3000 max_fails=3 fail_timeout=30s; } server { listen 80; server_name your-domain.com; location / { proxy_pass http://backend_servers; # 必须传递必要的请求头,避免后端服务拒绝请求 proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; } }
max_fails:Nginx判定后端不可用前的连续失败次数,默认是1次,可根据需求调整fail_timeout:标记后端不可用的时长,到期后会重新尝试连接
如果需要主动健康检查(而非默认的被动检查),需确保Nginx编译了ngx_http_upstream_check_module,并添加如下配置:
upstream backend_servers { server 10.128.0.10:3000; server 10.128.0.11:3000; # 主动健康检查配置 check interval=3000 rise=2 fall=3 timeout=1000 type=http; check_http_send "GET /health HTTP/1.1\r\nHost: localhost\r\n\r\n"; check_http_expect_alive http_2xx; }
2. 验证负载均衡器到后端的网络连通性
在负载均衡器Droplet上,直接测试后端私有IP的健康检查路由:
curl -I http://[后端私有IP]:[应用端口]/health
如果返回200 OK,说明网络连通正常;如果失败,检查后端Droplet的防火墙规则:
# 在后端Droplet上执行,允许负载均衡器私有IP访问应用端口 ufw allow from [负载均衡器私有IP]/32 to any port [应用端口]
3. 确认Express服务监听地址
确保你的Express应用不是仅监听127.0.0.1,而是监听0.0.0.0,这样才能接受来自负载均衡器的请求:
app.listen(3000, '0.0.0.0', () => { console.log('Server running on port 3000'); });
4. 查看Nginx错误日志定位问题
查看Nginx错误日志获取具体故障信息:
tail -f /var/log/nginx/error.log
常见错误提示及对应问题:
connect() failed (111: Connection refused) while connecting to upstream:后端服务未启动或端口未开放no live upstreams while connecting to upstream:所有后端服务器被Nginx标记为不可用timeout while connecting to upstream:后端响应超时,需调整Nginx的proxy_connect_timeout等参数
5. 检查Nginx状态页(可选)
启用Nginx状态页,查看后端服务器的状态:
server { listen 80; server_name your-domain.com; location /nginx_status { stub_status on; allow 127.0.0.1; deny all; } }
在负载均衡器上访问状态页:
curl http://127.0.0.1/nginx_status
通过返回的server字段,可查看后端服务器是否被标记为down。
内容的提问来源于stack exchange,提问作者Kouma Ibrahim
相关产品推荐
相关产品推荐

