You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx容器返回502 Bad Gateway/403 Forbidden问题排查求助

问题描述

部署了三个Docker容器(PHP-FPM、Nginx、MySQL),访问网站时频繁返回502 Bad Gateway错误,偶尔出现403 Forbidden错误,无法定位根源。

原配置文件

docker-compose.yml

version: '3'

services:
   app:
     build:
       context: .
     ports:
       - "9000:9000"
     volumes:
       - ./:/var/www/html
     depends_on:
       -db
     environment:
       - TZ=America/Argentina/Buenos_Aires
     networks:
       - stephvaez

   nginx:
       image: nginx:latest
       ports:
         - "9001:80"
         - "9002:443"
       volumes:
         - ./:/var/www/html
         - ./nginx-conf:/etc/nginx/conf.d
         - ./certificates:/etc/nginx/ssl
       depends_on:
         - app
       networks:
         - stephvaez

   DB:
     image: mysql:5.7
     environment:
       MYSQL_ROOT_PASSWORD: stephvaez
       MYSQL_DATABASE: stephvaez
     volumes:
       - mysql-data:/var/lib/mysql
     networks:
         - stephvaez

volumes:
   mysql-data: {}

networks:
   stephvaez:

Nginx配置文件

server {
    listen 80;
    listen [::]:80;
        
    server_name storemanager.local;
        
    return 301 https://$host$request_uri;
        
}
    
server {
    listen 443 ssl;
    listen [::]:443 ssl;
    
    ssl_certificate /etc/nginx/ssl/docker/server.pem;
    ssl_certificate_key /etc/nginx/ssl/docker/server.key;
    
    server_name storemanager.local;
    
    root /var/www/html/public;
    index index.html index.php;
    
    
    location / {
        try_files $uri $uri/ /index.php?$is_args$args;
    }
    
    location ~ \.php$ {
        fastcgi_pass app:9000;
        fastcgi_index index.php;
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    }
    
    location ~ /\.ht {
        deny there;
        return 404;
    }
}

Dockerfile

# Use a base image with PHP-FPM and Nginx
FROM php:8.1-fpm

# Install extensions necessary for Laravel and other dependencies
RUN docker-php-ext-install pdo pdo_mysql

# Install Nginx
RUN apt-get update && apt-get install -y nginx

# Install Composer
RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer

# Copy your Nginx configuration
COPY ./nginx-conf/nginx.conf /etc/nginx/conf.d

# Copy certificates
COPY certificates/ /etc/nginx/ssl/

# Configure Nginx to work with PHP-FPM
RUN echo "upstream php-upstream { server app:9000; }" > /etc/nginx/conf.d/upstream.conf

# Start both Nginx and PHP-FPM
CMD ["nginx", "-g", "daemon off;"]

问题排查与修复方案

1. Dockerfile核心错误

  • 冲突点:docker-compose已单独部署Nginx容器,但Dockerfile中又安装并启动了Nginx,且未启动PHP-FPM服务,导致app容器内的PHP-FPM未运行,Nginx无法转发请求,引发502错误。
  • 修复后Dockerfile:
# PHP-FPM基础镜像
FROM php:8.1-fpm

# 安装Laravel所需扩展
RUN docker-php-ext-install pdo pdo_mysql

# 安装Composer
RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer

# 启动PHP-FPM服务
CMD ["php-fpm"]

2. docker-compose.yml语法与冗余问题

  • 语法错误:depends_on中的-db需改为- db(添加空格),否则会导致服务依赖解析失败。
  • 冗余端口:app容器的9000:9000端口映射无需对外暴露,容器间通过内部网络通信即可,可移除。
  • 修复后docker-compose.yml:
version: '3'

services:
   app:
     build:
       context: .
     volumes:
       - ./:/var/www/html
     depends_on:
       - db
     environment:
       - TZ=America/Argentina/Buenos_Aires
     networks:
       - stephvaez

   nginx:
       image: nginx:latest
       ports:
         - "9001:80"
         - "9002:443"
       volumes:
         - ./:/var/www/html
         - ./nginx-conf:/etc/nginx/conf.d
         - ./certificates:/etc/nginx/ssl
       depends_on:
         - app
       networks:
         - stephvaez

   db:
     image: mysql:5.7
     environment:
       MYSQL_ROOT_PASSWORD: stephvaez
       MYSQL_DATABASE: stephvaez
     volumes:
       - mysql-data:/var/lib/mysql
     networks:
         - stephvaez

volumes:
   mysql-data: {}

networks:
   stephvaez:

3. Nginx配置语法错误

  • 错误点:location ~ /\.ht中的deny there;语法错误,应改为deny all;,否则会导致Nginx配置加载失败,引发403或502错误。
  • 修复后Nginx配置:
server {
    listen 80;
    listen [::]:80;
        
    server_name storemanager.local;
        
    return 301 https://$host$request_uri;
        
}
    
server {
    listen 443 ssl;
    listen [::]:443 ssl;
    
    ssl_certificate /etc/nginx/ssl/docker/server.pem;
    ssl_certificate_key /etc/nginx/ssl/docker/server.key;
    
    server_name storemanager.local;
    
    root /var/www/html/public;
    index index.html index.php;
    
    
    location / {
        try_files $uri $uri/ /index.php?$is_args$args;
    }
    
    location ~ \.php$ {
        fastcgi_pass app:9000;
        fastcgi_index index.php;
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    }
    
    location ~ /\.ht {
        deny all;
        return 404;
    }
}

验证步骤
  1. 停止并清理现有容器:docker-compose down
  2. 重新构建镜像:docker-compose build
  3. 启动容器:docker-compose up -d
  4. 检查容器状态:docker-compose ps,确保所有容器正常运行
  5. 查看日志排查剩余问题:
    • Nginx日志:docker-compose logs nginx
    • PHP-FPM日志:docker-compose logs app

内容的提问来源于stack exchange,提问作者Tom aguilera

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 20:05:22