You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx Proxy Manager反向代理下Docker Push私有仓库速度异常缓慢求助

私有镜像仓库推送延迟排查(Nginx Proxy Manager相关)
  • 搭建Jfrog Artifactory OSS后通过Nginx Proxy Manager反向代理暴露外网,本地CLI及Drone CI均可推送镜像,但推送到私有仓库耗时约5分钟,推送到DockerHub或GitLab仅需数秒
  • 容器体积仅MB级,推送到其他远程仓库无异常,最初认为是仓库本身或服务器老旧导致
  • 更换为Gitea内置镜像仓库后,推送延迟问题依旧,怀疑根源在Nginx Proxy Manager配置
  • 查看Gitea实时日志,请求能实时接收并快速处理,但请求间存在明显延迟,推测代理未正确转发请求或遗漏关键配置

当前Nginx Proxy Manager配置

server {
  set $forward_scheme http;
  set $server         "192.168.X.XX";
  set $port           3000;

  listen 8080;
#listen [::]:8080;

listen 4443 ssl http2;
#listen [::]:4443;


  server_name my.domain.com;

  # Let's Encrypt SSL
  include conf.d/include/letsencrypt-acme-challenge.conf;
  include conf.d/include/ssl-ciphers.conf;
  ssl_certificate /etc/letsencrypt/live/npm-47/fullchain.pem;
  ssl_certificate_key /etc/letsencrypt/live/npm-47/privkey.pem;

  # Force SSL
  include conf.d/include/force-ssl.conf;

  access_log /data/logs/proxy-host-10_access.log proxy;
  error_log /data/logs/proxy-host-10_error.log warn;
  
  #Additional fields I added ontop of the default Nginx Proxy Manager config
  proxy_buffering off; proxy_ignore_headers "X-Accel-Buffering";
  proxy_set_header X-Real-IP $remote_addr;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header X-Forwarded-Proto $scheme;

  location / {
    # Proxy!
    include conf.d/include/proxy.conf;
  }
  # Custom
  include /data/nginx/custom/server_proxy[.]conf;
}

参考资料整理

  • 某镜像仓库社区讨论:Docker镜像推送采用分块上传机制,该机制可能与反向代理的连接超时、缓冲设置冲突,建议调整代理超时参数以维持长连接
  • Stack Overflow方案:针对Docker Registry代理延迟问题,建议开启HTTP/1.1版本并清空Connection头,同时延长各类超时参数,避免连接过早断开

排查修复方向

  1. 调整HTTP版本与连接头
    在代理配置中添加以下内容,适配Docker分块上传的连接复用需求:

    proxy_http_version 1.1;
    proxy_set_header Connection "";
    
  2. 延长超时参数
    添加超时配置防止Nginx提前断开长连接:

    proxy_connect_timeout 600s;
    proxy_send_timeout 600s;
    proxy_read_timeout 600s;
    client_body_timeout 600s;
    send_timeout 600s;
    
  3. 检查内置proxy.conf配置
    查看conf.d/include/proxy.conf中的默认设置,确认是否存在缓冲、超时相关配置覆盖了自定义参数,比如是否默认开启proxy_buffering。

  4. 临时禁用HTTP/2测试
    暂时注释listen 4443 ssl http2;,改用HTTP/1.1测试,部分场景下HTTP/2多路复用可能与Docker上传逻辑存在兼容性问题。

  5. 细化日志分析
    修改access_log格式,添加请求耗时与上游响应耗时字段,明确延迟发生阶段:

    access_log /data/logs/proxy-host-10_access.log proxy "$remote_addr - $remote_user [$time_local] \"$request\" $status $body_bytes_sent \"$http_referer\" \"$http_user_agent\" $request_time $upstream_response_time";
    

内容的提问来源于stack exchange,提问作者97WaterPolo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 05:20:51