You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx+Varnish缓存代理链路配置未达预期问题咨询

Nginx + Varnish 链路配置异常排查调整

问题背景

已编写Nginx与Varnish缓存配合的配置文件存放于conf.d目录,Nginx同时会加载sites-enabled目录中的默认配置,当前配置运行效果不符合预期,目标实现的请求流转链路如下:

Nginx(443端口) → Varnish(6081端口) → Nginx(81端口) → PHP(9000端口)

当前使用的Nginx配置如下:

server {

    listen 443;

    #server_name  tirana.com;
    
    access_log   /var/log/nginx/access.log;
    error_log    /var/log/nginx/error.log;

    location = /favicon.ico { access_log off; log_not_found off; }
    location = /robots.txt  { access_log off; log_not_found off; }

    location / {
        proxy_pass http://127.0.0.1:6081;
        proxy_set_header Host $http_host;
        proxy_set_header X-Forwarded-Host $http_host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto https;
        proxy_set_header HTTPS "on";
    }

    location ~ /\.ht {
       deny all;
    }

    location ~ /.well-known {
       allow all;
    }

    ssl_certificate /etc/nginx/ssl/tirana_com.crt;
    ssl_certificate_key /etc/nginx/ssl/torana.com.key;

}

server {

    listen 80;

    server_name tirana.com;

    #return 301 https://tirana.com$request_uri;
    return 301 https://www.$host$request_uri;

}

server {

    listen 81;

    #server_name tirana.com;

    root /var/www/html;

    index index.php index.html;

    access_log   /var/log/nginx/access1.log;
    error_log    /var/log/nginx/error1.log;

    location / {
        try_files $uri $uri/ /index.php?$args;
        #try_files   $uri $uri/ /index.php?$query_string;
    }

    location ~\.php$ {
        include fastcgi.conf;
        fastcgi_pass unix:/run/php/php8.1-fpm.sock;
    }
}

调整思路

按从基础配置到链路逻辑的顺序逐一排查修正:

  • 解决配置冲突问题
    首先检查sites-enabled目录下的默认配置,确认不存在监听80/443/81端口的重复server块,否则会出现端口抢占、请求匹配到错误服务的问题。清理冲突配置后先执行nginx -t验证无语法、端口冲突问题,再进行后续调整。
  • 修正443端口HTTPS服务配置
    • 443端口监听缺少ssl参数:当前配置为listen 443;,默认以明文HTTP协议监听,HTTPS请求无法完成握手,需修改为listen 443 ssl;
    • 取消server_name的注释,补全所有需要绑定的域名(含带www、不带www的记录),示例:server_name tirana.com www.tirana.com;,避免其他指向本机443端口的请求串到当前站点
    • 修正SSL证书拼写错误:当前私钥路径写为/etc/nginx/ssl/torana.com.key,和域名tirana.com拼写不一致,会导致SSL加载失败,替换为实际正确的私钥文件路径
  • 修正80端口HTTP跳转配置
    当前80端口server块仅配置了server_name tirana.com;,http://www.tirana.com的请求不会匹配到该规则触发跳转,需补全server_name为server_name tirana.com www.tirana.com;。另外确认跳转规则和业务预期一致,避免出现域名重定向死循环。
  • 适配81端口源站Nginx配置
    • 取消81端口server块的server_name注释,补全对应域名,避免多站点场景下请求匹配错误
    • 确认PHP-FPM监听配置和Nginx配置一致:预期链路中PHP走9000TCP端口,但当前配置fastcgi_pass用的是Unix套接字/run/php/php8.1-fpm.sock,如果PHP-FPM配置为监听9000端口,需修改为fastcgi_pass 127.0.0.1:9000;;如果用Unix套接字则保持现有配置,同步调整Varnish后端配置指向127.0.0.1:81即可
    • 补充代理头识别逻辑:在81端口server块中添加配置,识别前端传递的HTTPS标识,避免PHP程序获取到错误的协议信息,触发静态资源混合内容、跳转错误问题,参考配置:
      set $fastcgi_https off;
      if ($http_x_forwarded_proto = 'https') {
          set $fastcgi_https on;
      }
      fastcgi_param HTTPS $fastcgi_https;
      
  • 逐层验证链路可用性
    配置调整完成后按顺序验证:
    1. 执行nginx -t确认配置无错误,执行systemctl reload nginx重载配置
    2. 验证Varnish配置无语法错误后重载Varnish服务
    3. 逐层请求排查:直接请求81端口确认源站Nginx+PHP正常响应,再请求6081端口确认Varnish正常回源缓存,最后请求443端口确认HTTPS入口正常转发,定位具体故障节点。

内容的提问来源于stack exchange,提问作者Dari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 20:57:18