Nginx容器返回502 Bad Gateway/403 Forbidden问题排查求助
问题描述
部署了三个Docker容器(PHP-FPM、Nginx、MySQL),访问网站时频繁返回502 Bad Gateway错误,偶尔出现403 Forbidden错误,无法定位根源。
原配置文件
docker-compose.yml
version: '3' services: app: build: context: . ports: - "9000:9000" volumes: - ./:/var/www/html depends_on: -db environment: - TZ=America/Argentina/Buenos_Aires networks: - stephvaez nginx: image: nginx:latest ports: - "9001:80" - "9002:443" volumes: - ./:/var/www/html - ./nginx-conf:/etc/nginx/conf.d - ./certificates:/etc/nginx/ssl depends_on: - app networks: - stephvaez DB: image: mysql:5.7 environment: MYSQL_ROOT_PASSWORD: stephvaez MYSQL_DATABASE: stephvaez volumes: - mysql-data:/var/lib/mysql networks: - stephvaez volumes: mysql-data: {} networks: stephvaez:
Nginx配置文件
server { listen 80; listen [::]:80; server_name storemanager.local; return 301 https://$host$request_uri; } server { listen 443 ssl; listen [::]:443 ssl; ssl_certificate /etc/nginx/ssl/docker/server.pem; ssl_certificate_key /etc/nginx/ssl/docker/server.key; server_name storemanager.local; root /var/www/html/public; index index.html index.php; location / { try_files $uri $uri/ /index.php?$is_args$args; } location ~ \.php$ { fastcgi_pass app:9000; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~ /\.ht { deny there; return 404; } }
Dockerfile
# Use a base image with PHP-FPM and Nginx FROM php:8.1-fpm # Install extensions necessary for Laravel and other dependencies RUN docker-php-ext-install pdo pdo_mysql # Install Nginx RUN apt-get update && apt-get install -y nginx # Install Composer RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer # Copy your Nginx configuration COPY ./nginx-conf/nginx.conf /etc/nginx/conf.d # Copy certificates COPY certificates/ /etc/nginx/ssl/ # Configure Nginx to work with PHP-FPM RUN echo "upstream php-upstream { server app:9000; }" > /etc/nginx/conf.d/upstream.conf # Start both Nginx and PHP-FPM CMD ["nginx", "-g", "daemon off;"]
问题排查与修复方案
1. Dockerfile核心错误
- 冲突点:docker-compose已单独部署Nginx容器,但Dockerfile中又安装并启动了Nginx,且未启动PHP-FPM服务,导致
app容器内的PHP-FPM未运行,Nginx无法转发请求,引发502错误。 - 修复后Dockerfile:
# PHP-FPM基础镜像 FROM php:8.1-fpm # 安装Laravel所需扩展 RUN docker-php-ext-install pdo pdo_mysql # 安装Composer RUN curl -sS https://getcomposer.org/installer | php -- --install-dir=/usr/local/bin --filename=composer # 启动PHP-FPM服务 CMD ["php-fpm"]
2. docker-compose.yml语法与冗余问题
- 语法错误:
depends_on中的-db需改为- db(添加空格),否则会导致服务依赖解析失败。 - 冗余端口:
app容器的9000:9000端口映射无需对外暴露,容器间通过内部网络通信即可,可移除。 - 修复后docker-compose.yml:
version: '3' services: app: build: context: . volumes: - ./:/var/www/html depends_on: - db environment: - TZ=America/Argentina/Buenos_Aires networks: - stephvaez nginx: image: nginx:latest ports: - "9001:80" - "9002:443" volumes: - ./:/var/www/html - ./nginx-conf:/etc/nginx/conf.d - ./certificates:/etc/nginx/ssl depends_on: - app networks: - stephvaez db: image: mysql:5.7 environment: MYSQL_ROOT_PASSWORD: stephvaez MYSQL_DATABASE: stephvaez volumes: - mysql-data:/var/lib/mysql networks: - stephvaez volumes: mysql-data: {} networks: stephvaez:
3. Nginx配置语法错误
- 错误点:
location ~ /\.ht中的deny there;语法错误,应改为deny all;,否则会导致Nginx配置加载失败,引发403或502错误。 - 修复后Nginx配置:
server { listen 80; listen [::]:80; server_name storemanager.local; return 301 https://$host$request_uri; } server { listen 443 ssl; listen [::]:443 ssl; ssl_certificate /etc/nginx/ssl/docker/server.pem; ssl_certificate_key /etc/nginx/ssl/docker/server.key; server_name storemanager.local; root /var/www/html/public; index index.html index.php; location / { try_files $uri $uri/ /index.php?$is_args$args; } location ~ \.php$ { fastcgi_pass app:9000; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~ /\.ht { deny all; return 404; } }
验证步骤
- 停止并清理现有容器:
docker-compose down - 重新构建镜像:
docker-compose build - 启动容器:
docker-compose up -d - 检查容器状态:
docker-compose ps,确保所有容器正常运行 - 查看日志排查剩余问题:
- Nginx日志:
docker-compose logs nginx - PHP-FPM日志:
docker-compose logs app
- Nginx日志:
内容的提问来源于stack exchange,提问作者Tom aguilera
相关产品推荐
相关产品推荐

