Docker+Nginx+php-fpm部署Kirby时upstream连接被拒问题求助
问题核心原因
- 镜像缓存异常:Dockerfile声明使用
php:7.4-fpm基础镜像,但实际运行的容器启动了Apache2服务,说明使用了未清理的旧镜像缓存,镜像实际行为和定义不符。 - 端口映射不匹配:
- nfs_subdomain容器内Apache实际监听80端口,但docker-compose中配置暴露、映射的是9001端口,上游转发指向9001必然连接失败
- 自定义Nginx配置中server块监听9001,但给jwilder反向代理设置的
VIRTUAL_PORT=80,代理转发请求到nfs_nginx的80端口无响应,直接报Connection refused
- 转发逻辑错误:如果nfs_subdomain运行的是Apache HTTP服务,Nginx配置中使用
fastcgi_pass转发PHP请求逻辑错误,fastcgi协议仅用于对接php-fpm服务,对接HTTP服务需要使用proxy_pass。 - 伪静态规则缺失:原有Nginx配置的location规则不支持Kirby的动态路由,即使连通也会出现二级路径404问题。
修复方案(推荐使用php-fpm + Nginx架构,性能优于Apache)
- 清理旧镜像缓存,避免加载历史错误镜像
docker-compose down --rmi local
- 修改
docker-compose.yml配置
调整nfs_subdomain服务端口配置,php-fpm默认监听9000端口,无需对外映射:
version: '2' services: nfs_subdomain: build: context: . dockerfile: Dockerfile image: my-image restart: always networks: - kirby volumes: - ./:/var/www/html nfs_nginx: image: nginx restart: always volumes: - ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro links: - nfs_subdomain volumes_from: - nfs_subdomain environment: - VIRTUAL_HOST=sub.domain.tld - VIRTUAL_NETWORK=nginx-proxy - VIRTUAL_PORT=80 - LETSENCRYPT_HOST=sub.domain.tld - LETSENCRYPT_EMAIL=myemail@gmail.com networks: - kirby - proxy-tier networks: kirby: proxy-tier: external: name: nginxproxy_default
- 修改自定义
nginx.conf配置
user www-data; events { worker_connections 768; } http { upstream kirby_server { server nfs_subdomain:9000; # 对应php-fpm默认端口 } include /etc/nginx/mime.types; default_type application/octet-stream; gzip on; gzip_disable "msie6"; server { listen 80; # 和VIRTUAL_PORT配置一致 root /var/www/html/; index index.php index.html index.htm; location / { try_files $uri $uri/ /index.php?$query_string; # 适配Kirby伪静态规则 } error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } location = /favicon.ico { log_not_found off; access_log off; } # CSS and Javascript location ~* \.(?:css|js)$ { expires 1y; access_log off; add_header Cache-Control "public"; } location ~ \.php$ { fastcgi_param GATEWAY_INTERFACE CGI/1.1; fastcgi_param SERVER_SOFTWARE nginx; fastcgi_param QUERY_STRING $query_string; fastcgi_param REQUEST_METHOD $request_method; fastcgi_param CONTENT_TYPE $content_type; fastcgi_param CONTENT_LENGTH $content_length; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_param SCRIPT_NAME $fastcgi_script_name; fastcgi_param REQUEST_URI $request_uri; fastcgi_param DOCUMENT_URI $document_uri; fastcgi_param DOCUMENT_ROOT $document_root; fastcgi_param SERVER_PROTOCOL $server_protocol; fastcgi_param REMOTE_ADDR $remote_addr; fastcgi_param REMOTE_PORT $remote_port; fastcgi_param SERVER_ADDR $server_addr; fastcgi_param SERVER_PORT $server_port; fastcgi_param SERVER_NAME $server_name; fastcgi_intercept_errors on; fastcgi_pass kirby_server; } } }
- 重新构建启动服务
docker-compose up -d --build
内容的提问来源于stack exchange,提问作者buchstabe
相关产品推荐
相关产品推荐

