You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker+Nginx+php-fpm部署Kirby时upstream连接被拒问题求助

问题核心原因

  1. 镜像缓存异常:Dockerfile声明使用php:7.4-fpm基础镜像,但实际运行的容器启动了Apache2服务,说明使用了未清理的旧镜像缓存,镜像实际行为和定义不符。
  2. 端口映射不匹配:
    • nfs_subdomain容器内Apache实际监听80端口,但docker-compose中配置暴露、映射的是9001端口,上游转发指向9001必然连接失败
    • 自定义Nginx配置中server块监听9001,但给jwilder反向代理设置的VIRTUAL_PORT=80,代理转发请求到nfs_nginx的80端口无响应,直接报Connection refused
  3. 转发逻辑错误:如果nfs_subdomain运行的是Apache HTTP服务,Nginx配置中使用fastcgi_pass转发PHP请求逻辑错误,fastcgi协议仅用于对接php-fpm服务,对接HTTP服务需要使用proxy_pass。
  4. 伪静态规则缺失:原有Nginx配置的location规则不支持Kirby的动态路由,即使连通也会出现二级路径404问题。

修复方案(推荐使用php-fpm + Nginx架构,性能优于Apache)

  1. 清理旧镜像缓存,避免加载历史错误镜像
docker-compose down --rmi local
  1. 修改docker-compose.yml配置
    调整nfs_subdomain服务端口配置,php-fpm默认监听9000端口,无需对外映射:
version: '2'

services:

  nfs_subdomain:
    build:
      context: .
      dockerfile: Dockerfile
    image: my-image
    restart: always
    networks:
      - kirby
    volumes:
      - ./:/var/www/html


  nfs_nginx:
    image: nginx
    restart: always
    volumes:
      - ./nginx/nginx.conf:/etc/nginx/nginx.conf:ro
    links:
      - nfs_subdomain
    volumes_from:
      - nfs_subdomain
    environment:
      - VIRTUAL_HOST=sub.domain.tld
      - VIRTUAL_NETWORK=nginx-proxy
      - VIRTUAL_PORT=80
      - LETSENCRYPT_HOST=sub.domain.tld
      - LETSENCRYPT_EMAIL=myemail@gmail.com
    networks:
      - kirby
      - proxy-tier

networks:
  kirby:
  proxy-tier:
    external:
      name: nginxproxy_default
  1. 修改自定义nginx.conf配置
user www-data;

events {
  worker_connections 768;
}

http {
  upstream kirby_server {
    server nfs_subdomain:9000; # 对应php-fpm默认端口
  }

  include /etc/nginx/mime.types;
  default_type application/octet-stream;
  gzip on;
  gzip_disable "msie6";

  server {
    listen 80; # 和VIRTUAL_PORT配置一致
    root /var/www/html/;
    index index.php index.html index.htm;

    location / {
      try_files $uri $uri/ /index.php?$query_string; # 适配Kirby伪静态规则
    }

    error_page 404 /404.html;
    error_page 500 502 503 504 /50x.html;
    location = /50x.html {
      root /usr/share/nginx/html;
    }

    location = /favicon.ico {
      log_not_found off;
      access_log off;
    }

    # CSS and Javascript
    location ~* \.(?:css|js)$ {
      expires 1y;
      access_log off;
      add_header Cache-Control "public";
    }

    location ~ \.php$ {
      fastcgi_param  GATEWAY_INTERFACE  CGI/1.1;
      fastcgi_param  SERVER_SOFTWARE    nginx;
      fastcgi_param  QUERY_STRING       $query_string;
      fastcgi_param  REQUEST_METHOD     $request_method;
      fastcgi_param  CONTENT_TYPE       $content_type;
      fastcgi_param  CONTENT_LENGTH     $content_length;
      fastcgi_param  SCRIPT_FILENAME    $document_root$fastcgi_script_name;
      fastcgi_param  SCRIPT_NAME        $fastcgi_script_name;
      fastcgi_param  REQUEST_URI        $request_uri;
      fastcgi_param  DOCUMENT_URI       $document_uri;
      fastcgi_param  DOCUMENT_ROOT      $document_root;
      fastcgi_param  SERVER_PROTOCOL    $server_protocol;
      fastcgi_param  REMOTE_ADDR        $remote_addr;
      fastcgi_param  REMOTE_PORT        $remote_port;
      fastcgi_param  SERVER_ADDR        $server_addr;
      fastcgi_param  SERVER_PORT        $server_port;
      fastcgi_param  SERVER_NAME        $server_name;
      fastcgi_intercept_errors on;
      fastcgi_pass kirby_server;
    }
  }
}
  1. 重新构建启动服务
docker-compose up -d --build

内容的提问来源于stack exchange,提问作者buchstabe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 08:36:03