如何让AWS EC2(8核)Ubuntu实例支持10K并发连接?
Alright, let's break down why your local Nginx handles 10K concurrent connections fine but your EC2 instance throws a connection refused error at that load. The issue almost always boils down to default system/kernel limits that aren't tuned for high concurrency—local machines often have looser restrictions, but EC2 instances come with conservative defaults. Here's how to fix it step by step:
1. Tune Linux File Descriptor Limits
Every TCP connection uses a file descriptor, and the default limits are way too low for 10K concurrent connections:
Temporary Fix (resets on reboot)
# Boost system-wide file descriptor limit sudo sysctl -w fs.file-max=100000 # Raise per-user limit for your current session ulimit -n 65535
Permanent Fix
Edit /etc/sysctl.conf and add/update these lines:
fs.file-max = 100000 net.core.somaxconn = 10240 # Max pending connections in listen queue net.core.netdev_max_backlog = 10000 # Max packets queued by network interface net.ipv4.tcp_max_syn_backlog = 10240 # Max SYN requests queued net.ipv4.tcp_tw_reuse = 1 # Reuse TIME_WAIT sockets for new connections net.ipv4.tcp_fin_timeout = 30 # Shorten TIME_WAIT timeout
Apply the changes with:
sudo sysctl -p
Next, edit /etc/security/limits.conf to set persistent per-user limits:
* soft nofile 65535 * hard nofile 65535 root soft nofile 65535 root hard nofile 65535
Reboot your instance or log out/in for these to take effect, then verify with ulimit -n.
2. Optimize Nginx Configuration
Even with 8 workers, you need to ensure each can handle enough connections. Edit your main Nginx config (usually /etc/nginx/nginx.conf):
worker_processes auto; # Matches your 8-core instance automatically events { use epoll; # Use efficient epoll multiplexing for high concurrency worker_connections 10000; # Max connections per worker multi_accept on; # Let workers accept all pending connections at once } http { sendfile on; tcp_nopush on; tcp_nodelay on; keepalive_timeout 60; # Keep idle connections open longer keepalive_requests 10000; # Max requests per keepalive connection }
Test the config and restart Nginx:
sudo nginx -t sudo systemctl restart nginx
3. Check EC2-Specific Network/Security Limits
- Security Groups: Confirm your security group allows inbound TCP port 80 traffic from your local IP (you already have this working for 4K concurrency, but double-check no unexpected rules are in place).
- Instance Network Capacity: Your 8-core instance should have enough bandwidth for 10K concurrent connections, but if you're using a low-bandwidth instance type, that could be a bottleneck. However, your error is "connection refused" (not timeout), so this is less likely than the kernel/tuning issues.
- SYN Queue Overflow: The
tcp_max_syn_backlogandsomaxconnsettings we added earlier fix the most common cause of connection refused under high concurrency—when the server's SYN queue fills up before it can process new connections.
4. Validate the Fix
First, check your EC2 instance's connection stats with:
ss -s
Then re-run your ApacheBench test:
ab -c 10000 -n 10000 http://<ec2-ip-address>/
If you still run into issues, check system logs (/var/log/syslog) and Nginx error logs (/var/log/nginx/error.log) for specific clues—like file descriptor exhaustion or SYN queue errors.
内容的提问来源于stack exchange,提问作者Dinesh

