Docker Compose中Nginx仍报退出码137(已加倍内存,证书更新后出现)
问题排查:Nginx容器启动失败(退出码137)
已将服务器内存加倍,但Nginx容器仍启动失败并报退出码137,问题始于今日执行Let's Encrypt证书更新脚本后。
容器日志
Attaching to nginx nginx | /docker-entrypoint.sh: /docker-entrypoint.d/ is not empty, will attempt to perform configuration nginx | /docker-entrypoint.sh: Looking for shell scripts in /docker-entrypoint.d/ nginx | /docker-entrypoint.sh: Launching /docker-entrypoint.d/10-listen-on-ipv6-by-default.sh nginx | 10-listen-on-ipv6-by-default.sh: info: Getting the checksum of /etc/nginx/conf.d/default.conf nginx | 10-listen-on-ipv6-by-default.sh: info: /etc/nginx/conf.d/default.conf differs from the packaged version nginx | /docker-entrypoint.sh: Launching /docker-entrypoint.d/20-envsubst-on-templates.sh nginx | /docker-entrypoint.sh: Launching /docker-entrypoint.d/30-tune-worker-processes.sh nginx | /docker-entrypoint.sh: Configuration complete; ready for start up nginx | 2022/11/01 07:18:38 [notice] 1#1: using the "epoll" event method nginx | 2022/11/01 07:18:38 [notice] 1#1: nginx/1.23.2 nginx | 2022/11/01 07:18:38 [notice] 1#1: built by gcc 11.2.1 20220219 (Alpine 11.2.1_git20220219) nginx | 2022/11/01 07:18:38 [notice] 1#1: OS: Linux 5.4.0-131-generic nginx | 2022/11/01 07:18:38 [notice] 1#1: getrlimit(RLIMIT_NOFILE): 1048576:1048576 nginx | 2022/11/01 07:18:38 [notice] 1#1: start worker processes nginx | 2022/11/01 07:18:38 [notice] 1#1: start worker process 29 nginx | 2022/11/01 07:18:38 [notice] 1#1: start worker process 30 nginx exited with code 137
Docker Compose配置文件
version: '3.8' services: nginx: container_name: nginx image: nginx:1.23.2-alpine restart: always ports: - 80:80 - 443:443 volumes: - /opt/aaa/conf/nginx/:/etc/nginx/conf.d/ - /opt/aaa/letsencrypt:/etc/letsencrypt/ - /var/www/html/.well-known:/code/well-known - /etc/ssl/dhparam.pem:/etc/ssl/dhparam.pem - /opt/aaa/website/static:/code/static - /opt/aaa/install:/opt/install networks: - mehere networks: personal: name: mehere
排查思路
- 检查证书文件权限与完整性:查看
/opt/aaa/letsencrypt/live/目标域名/下的证书文件(如fullchain.pem、privkey.pem)是否存在,权限是否允许容器内nginx用户(默认UID/GID为101)读取。可临时将证书文件权限设为644、目录权限设为755测试。 - 验证Nginx配置语法:直接用容器镜像测试配置有效性,执行命令:
查看是否有语法错误或证书路径引用问题。docker run --rm -v /opt/aaa/conf/nginx/:/etc/nginx/conf.d/ -v /opt/aaa/letsencrypt:/etc/letsencrypt/ nginx:1.23.2-alpine nginx -t - 排查证书更新后的路径/链接问题:确认Let's Encrypt更新脚本是否导致证书文件的符号链接失效,或配置文件中引用的证书路径与实际路径不匹配。
- 检查系统OOM Killer日志:即使服务器内存已加倍,仍需确认是否是系统OOM Killer终止了nginx进程,执行
dmesg | grep -i oom查看相关日志;同时检查Docker是否对容器设置了内存限制(可通过docker inspect nginx查看HostConfig.Memory字段)。 - 验证挂载的其他关键文件:检查
/etc/ssl/dhparam.pem是否存在、未损坏,且容器用户可读取,nginx配置中是否正确引用该文件。 - 简化配置定位问题:临时修改Compose配置,移除非必要的挂载卷(如静态文件、安装目录等),使用最小化配置启动容器。若能正常运行,再逐个加回挂载项,定位具体触发问题的挂载目录。
内容的提问来源于stack exchange,提问作者Astin Gengo
相关产品推荐
相关产品推荐

