Docker Compose部署Nginx+PHP环境下的Nginx性能优化配置咨询
Docker环境Nginx性能优化建议
一、Docker Compose配置优化
1. 镜像与基础参数优化
- 避免使用
latest标签,固定轻量稳定的镜像版本,推荐使用alpine变体减少资源占用,例如nginx:1.25-alpine,避免版本自动更新带来的兼容性问题 - 新增资源限制与文件描述符配置,防止Nginx异常占用宿主机资源,同时满足高并发场景下的文件打开数要求:
nginx: image: nginx:1.25-alpine container_name: nginx restart: always # 新增资源限制 deploy: resources: limits: cpus: '1.0' memory: 512M reservations: cpus: '0.5' memory: 256M # 新增文件描述符配置 ulimits: nofile: soft: 65535 hard: 65535 # 移除废弃的links配置,同internal网络下服务可直接通信 volumes: - ./www:/www:cached # 新增cached参数减少文件同步开销 - ./apps/nginx/nginx.conf:/etc/nginx/nginx.conf:ro # 新增全局配置挂载,只读更安全 - ./apps/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro # 新增tmpfs挂载,将临时目录放入内存提升读写速度 tmpfs: - /var/cache/nginx - /var/run/nginx networks: - proxy - internal labels: - "traefik.enable=true" - "traefik.docker.network=proxy" - "traefik.http.routers.nginx.entrypoints=websecure" - "traefik.http.routers.nginx.rule=Host(`domain.com`) || Host(`www.domain.com`)"
2. 其他优化点
- 所有配置文件挂载统一加
:ro只读属性,避免容器内进程篡改配置提升安全性 - 若静态资源访问量极高,可将常用静态资源目录单独挂载并使用
volume驱动而非bind mount,进一步提升IO性能
二、Nginx配置优化
1. 全局nginx.conf配置优化
新增全局配置文件挂载,调整核心参数适配容器环境:
user nginx; worker_processes auto; # 自动匹配宿主机CPU核心数 worker_rlimit_nofile 65535; # 匹配容器ulimit配置 events { use epoll; # 启用高效事件模型 worker_connections 10240; # 调高单进程最大连接数 multi_accept on; # 允许同时接受多个连接 } http { include /etc/nginx/mime.types; default_type application/octet-stream; # 开启高效文件传输 sendfile on; tcp_nopush on; tcp_nodelay on; # 调整长连接配置,减少TCP握手开销 keepalive_timeout 65; keepalive_requests 1000; # 开启gzip压缩 gzip on; gzip_vary on; gzip_comp_level 5; gzip_types text/plain text/css text/xml text/javascript application/javascript application/xml+rss application/json; # 开启文件元数据缓存,减少磁盘IO open_file_cache max=10240 inactive=60s; open_file_cache_valid 80s; open_file_cache_min_uses 2; open_file_cache_errors on; # 日志写入加缓冲,减少磁盘IO频率 log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main buffer=32k flush=1m; error_log /var/log/nginx/error.log warn; include /etc/nginx/conf.d/*.conf; }
2. 站点配置优化
修改你现有的default.conf配置:
server { server_tokens off; server_name_in_redirect off; listen 80; server_name domain.com www.domain.com; # 补充所有匹配域名 error_log /www/log/error.log warn; access_log /www/log/access.log main buffer=32k flush=1m; root /www; index index.php index.html; # 统一域名,可选301跳转 if ($host = 'domain.com') { return 301 https://www.domain.com$request_uri; } location / { try_files $uri $uri/ /index.php?$query_string; # 补充伪静态规则,适配多数PHP框架 } location ~* \.(jpg|jpeg|gif|png|css|js|ico|xml|woff|woff2|ttf|eot)$ { access_log off; log_not_found off; expires 360d; add_header Cache-Control "public, immutable, no-transform"; # 新增缓存头,避免中间代理篡改 } location ~* \.php$ { try_files $uri =404; # 新增防路径解析漏洞 fastcgi_pass php-fpm:9000; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param PATH_INFO $fastcgi_path_info; # 若有不需要实时更新的页面,可新增fastcgi缓存规则,缓存到tmpfs目录减少PHP调用 } location ~ /\. { access_log off; log_not_found off; deny all; } }
内容的提问来源于stack exchange,提问作者benehil
相关产品推荐
相关产品推荐

