Debian 11下Docker Compose配置Plausible连接外部PostgreSQL故障排查
Debian 11下Plausible连接外部PostgreSQL的问题排查与解决
问题概述
在Debian 11上用Docker Compose部署Plausible时,遇到两个核心问题:
- 配置
host.docker.internal连接外部PostgreSQL时,容器日志报连接拒绝 - 首次用宿主机旧网关IP(172.17.0.1)能启动,但每次执行
docker-compose up,容器所在网络的IP段会递增(从172.17.x.x到172.28.x.x),导致旧IP失效
核心问题分析
- host.docker.internal连接失败:
虽然在Compose配置中加了extra_hosts: - "host.docker.internal:host-gateway",但连接被拒通常是三个原因:PostgreSQL未监听宿主机所有网卡、宿主机防火墙拦截了5432端口、PostgreSQL访问控制规则未允许容器网段接入。 - 容器IP段递增:
每次重启Compose时,若未指定自定义网络,Docker会自动创建新的默认桥接网络,每个新网络的子网段依次递增,导致旧网关IP(如172.17.0.1)不再是容器访问宿主机的有效地址,依赖固定IP的连接自然失效。
解决方案
方案一:修复host.docker.internal连接(推荐)
这是最规范的方式,无需依赖固定IP:
- 修改PostgreSQL配置文件
postgresql.conf,确保监听所有网卡:listen_addresses = '*' - 修改
pg_hba.conf,添加允许Docker私有网段访问的规则(覆盖172.16.0.0/12所有Docker常用子网):host plausible_db plausible 172.16.0.0/12 scram-sha-256 - 重启PostgreSQL服务:
systemctl restart postgresql - 检查宿主机防火墙(以ufw为例),放行5432端口给Docker网段:
ufw allow from 172.16.0.0/12 to any port 5432 - 保持现有Compose中的
extra_hosts配置,plausible-conf.env里的DATABASE_URL用host.docker.internal即可。
方案二:创建固定子网的自定义Docker网络
通过自定义网络固定网关IP,避免每次重启Compose网段变化:
- 在
docker-compose.yml中添加自定义网络配置:version: "3.3" networks: plausible_net: driver: bridge ipam: config: - subnet: 172.30.0.0/16 gateway: 172.30.0.1 services: mail: image: bytemark/smtp restart: always networks: - plausible_net plausible_events_db: image: clickhouse/clickhouse-server:23.3.7.5-alpine restart: always volumes: - event-data:/var/lib/clickhouse - ./clickhouse/clickhouse-config.xml:/etc/clickhouse-server/config.d/logging.xml:ro - ./clickhouse/clickhouse-user-config.xml:/etc/clickhouse-server/users.d/logging.xml:ro ulimits: nofile: soft: 262144 hard: 262144 networks: - plausible_net plausible: image: plausible/analytics:v2.0 restart: always command: sh -c "sleep 10 && /entrypoint.sh db migrate && /entrypoint.sh run" depends_on: - plausible_events_db - mail ports: - 8001:8000 env_file: - plausible-conf.env networks: - plausible_net volumes: event-data: driver: local - 修改
plausible-conf.env中的DATABASE_URL为固定网关IP:DATABASE_URL=postgres://plausible:password@172.30.0.1:5432/plausible_db - 同样需要在PostgreSQL的
pg_hba.conf中添加允许172.30.0.0/16网段访问的规则,重启PostgreSQL并放行防火墙端口。
方案三:使用host模式(不推荐)
仅适合临时测试,安全性低(容器直接共享宿主机网络命名空间):
- 在
plausible服务中启用network_mode: host,并移除ports映射(host模式下直接用宿主机端口) - 修改
plausible-conf.env中的DATABASE_URL为postgres://plausible:password@localhost:5432/plausible_db
相关配置与日志
容器错误日志
Loading plausible.. Starting dependencies.. Starting repos.. Running migrations for Elixir.Plausible.Repo 06:57:08.578 [error] Postgrex.Protocol (#PID<0.164.0>) failed to connect: ** (DBConnection.ConnectionError) tcp connect (host.docker.internal:5432): connection refused - :econnrefused 06:57:08.578 [error] Postgrex.Protocol (#PID<0.163.0>) failed to connect: ** (DBConnection.ConnectionError) tcp connect (host.docker.internal:5432): connection refused - :econnrefused 06:57:09.988 [error] Postgrex.Protocol (#PID<0.163.0>) failed to connect: ** (DBConnection.ConnectionError) tcp connect (host.docker.internal:5432): connection refused - :econnrefused 06:57:10.343 [error] Postgrex.Protocol (#PID<0.164.0>) failed to connect: ** (DBConnection.ConnectionError) tcp connect (host.docker.internal:5432): connection refused - :econnrefused 06:57:11.505 [error] Could not create schema migrations table. This error usually happens due to the following: * The database does not exist * The "schema_migrations" table, which Ecto uses for managing migrations, was defined by another library * There is a deadlock while migrating (such as using concurrent indexes with a migration_lock)
原始docker-compose.yml
version: "3.3" #networks: # lan_access: # driver: bridge services: mail: image: bytemark/smtp restart: always # plausible_db: # supported versions are 12, 13, and 14 # image: postgres:14-alpine # restart: always # volumes: # - db-data:/var/lib/postgresql/data # environment: # - POSTGRES_PASSWORD=postgres plausible_events_db: image: clickhouse/clickhouse-server:23.3.7.5-alpine restart: always volumes: - event-data:/var/lib/clickhouse - ./clickhouse/clickhouse-config.xml:/etc/clickhouse-server/config.d/logging.xml:ro - ./clickhouse/clickhouse-user-config.xml:/etc/clickhouse-server/users.d/logging.xml:ro ulimits: nofile: soft: 262144 hard: 262144 plausible: image: plausible/analytics:v2.0 restart: always command: sh -c "sleep 10 && /entrypoint.sh db migrate && /entrypoint.sh run" #command: sh -c "sleep 10 && /entrypoint.sh db createdb && /entrypoint.sh db migrate && /entrypoint.sh run" depends_on: # - plausible_db - plausible_events_db - mail # networks: # - lan_access # - default # network_mode: bridge # network_mode: host ports: - 8001:8000 env_file: - plausible-conf.env extra_hosts: - "host.docker.internal:host-gateway" volumes: # db-data: # driver: local event-data: driver: local
原始plausible-conf.env
BASE_URL=https://analytics.example.com SECRET_KEY_BASE=SECRET DATABASE_URL=postgres://plausible:password@host.docker.internal:5432/plausible_db #DATABASE_URL=postgres://plausible:password@172.17.0.1::5432/plausible_db #DATABASE_URL=postgres://plausible:password@gateway.docker.internal:5432/plausible_db MAILER_NAME=plausible SMTP_HOST_ADDR=localhost SMTP_HOST_PORT=25
内容的提问来源于stack exchange,提问作者ScorprocS
相关产品推荐
相关产品推荐

