You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker Compose部署Nginx+PHP环境下的Nginx性能优化配置咨询

Docker环境Nginx性能优化建议

一、Docker Compose配置优化

1. 镜像与基础参数优化

  • 避免使用latest标签,固定轻量稳定的镜像版本,推荐使用alpine变体减少资源占用,例如nginx:1.25-alpine,避免版本自动更新带来的兼容性问题
  • 新增资源限制与文件描述符配置,防止Nginx异常占用宿主机资源,同时满足高并发场景下的文件打开数要求:
nginx:
    image: nginx:1.25-alpine
    container_name: nginx
    restart: always
    # 新增资源限制
    deploy:
      resources:
        limits:
          cpus: '1.0'
          memory: 512M
        reservations:
          cpus: '0.5'
          memory: 256M
    # 新增文件描述符配置
    ulimits:
      nofile:
        soft: 65535
        hard: 65535
    # 移除废弃的links配置,同internal网络下服务可直接通信
    volumes:
      - ./www:/www:cached # 新增cached参数减少文件同步开销
      - ./apps/nginx/nginx.conf:/etc/nginx/nginx.conf:ro # 新增全局配置挂载,只读更安全
      - ./apps/nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
    # 新增tmpfs挂载,将临时目录放入内存提升读写速度
    tmpfs:
      - /var/cache/nginx
      - /var/run/nginx
    networks:
      - proxy
      - internal
    labels:
      - "traefik.enable=true"
      - "traefik.docker.network=proxy"
      - "traefik.http.routers.nginx.entrypoints=websecure"
      - "traefik.http.routers.nginx.rule=Host(`domain.com`) || Host(`www.domain.com`)"

2. 其他优化点

  • 所有配置文件挂载统一加:ro只读属性,避免容器内进程篡改配置提升安全性
  • 若静态资源访问量极高,可将常用静态资源目录单独挂载并使用volume驱动而非bind mount,进一步提升IO性能

二、Nginx配置优化

1. 全局nginx.conf配置优化

新增全局配置文件挂载,调整核心参数适配容器环境:

user nginx;
worker_processes auto; # 自动匹配宿主机CPU核心数
worker_rlimit_nofile 65535; # 匹配容器ulimit配置

events {
    use epoll; # 启用高效事件模型
    worker_connections 10240; # 调高单进程最大连接数
    multi_accept on; # 允许同时接受多个连接
}

http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    # 开启高效文件传输
    sendfile on;
    tcp_nopush on;
    tcp_nodelay on;

    # 调整长连接配置,减少TCP握手开销
    keepalive_timeout 65;
    keepalive_requests 1000;

    # 开启gzip压缩
    gzip on;
    gzip_vary on;
    gzip_comp_level 5;
    gzip_types text/plain text/css text/xml text/javascript application/javascript application/xml+rss application/json;

    # 开启文件元数据缓存,减少磁盘IO
    open_file_cache max=10240 inactive=60s;
    open_file_cache_valid 80s;
    open_file_cache_min_uses 2;
    open_file_cache_errors on;

    # 日志写入加缓冲,减少磁盘IO频率
    log_format main '$remote_addr - $remote_user [$time_local] "$request" '
                    '$status $body_bytes_sent "$http_referer" '
                    '"$http_user_agent" "$http_x_forwarded_for"';
    access_log /var/log/nginx/access.log main buffer=32k flush=1m;
    error_log /var/log/nginx/error.log warn;

    include /etc/nginx/conf.d/*.conf;
}

2. 站点配置优化

修改你现有的default.conf配置:

server {
    server_tokens off;
    server_name_in_redirect off;

    listen 80;
    server_name domain.com www.domain.com; # 补充所有匹配域名

    error_log  /www/log/error.log warn;
    access_log /www/log/access.log main buffer=32k flush=1m;

    root /www;
    index index.php index.html;

    # 统一域名,可选301跳转
    if ($host = 'domain.com') {
        return 301 https://www.domain.com$request_uri;
    }

    location / {
        try_files $uri $uri/ /index.php?$query_string; # 补充伪静态规则,适配多数PHP框架
    }

    location ~* \.(jpg|jpeg|gif|png|css|js|ico|xml|woff|woff2|ttf|eot)$ {
        access_log        off;
        log_not_found     off;
        expires           360d;
        add_header Cache-Control "public, immutable, no-transform"; # 新增缓存头,避免中间代理篡改
    }

    location ~* \.php$ {
        try_files $uri =404; # 新增防路径解析漏洞
        fastcgi_pass php-fpm:9000;
        fastcgi_index index.php;
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        fastcgi_param PATH_INFO $fastcgi_path_info;
        # 若有不需要实时更新的页面,可新增fastcgi缓存规则,缓存到tmpfs目录减少PHP调用
    }

    location ~ /\. {
        access_log off;
        log_not_found off;
        deny all;
    }
}

内容的提问来源于stack exchange,提问作者benehil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 07:57:04