远程DigitalOcean上Lando(Drupal8)站点的PHPStorm+Xdebug调试问题
Let's break down what's going wrong and fix it step by step:
1. Fix YAML Configuration Overlap
First, your .lando.local.yml has duplicate config: blocks—YAML will overwrite the first block with the second, so your initial Xdebug enable setting wasn't actually being applied. Merge them into a single block:
# .lando.local.yml config: xdebug: true php: .lando.php.ini
2. Update Xdebug Host for Container-to-Droplet Communication
Inside your Lando container, localhost refers to the container itself—not your local machine or the Droplet host. Since you're using a reverse SSH tunnel to forward Droplet port 9002 to your local machine, we need to point Xdebug to the Droplet host from inside the container.
Option A: Use host.docker.internal (Recommended for Modern Docker)
Add an extra_hosts entry to your .lando.local.yml to map host.docker.internal to your Droplet's public IP, so the container can reach the Droplet host:
# .lando.local.yml (updated) config: xdebug: true php: .lando.php.ini services: appserver: extra_hosts: - "host.docker.internal:165.xxx.xxx.xxx"
Then update your .lando.php.ini to use this host:
xdebug.remote_enable = 1 xdebug.remote_autostart = 1 xdebug.remote_connect_back = 0 xdebug.remote_host = host.docker.internal xdebug.remote_port = 9002 xdebug.remote_log = /xdebug.log xdebug.remote_mode = req xdebug.idekey = PHPSTORM
Option B: Use Droplet's Gateway IP
If host.docker.internal doesn't work (older Docker versions on Linux), find your Droplet's Docker gateway IP by running docker network inspect lando_default on the Droplet—look for the Gateway value (usually something like 172.18.0.1). Replace host.docker.internal with this IP in .lando.php.ini.
3. Rebuild Lando to Apply Changes
Run this command on your Droplet to apply the new service and config settings:
lando rebuild -y
4. Verify Tunnel and Network Connectivity
- Confirm SSH Tunnel is Active: On your local machine, keep the reverse tunnel running:
ssh -R 9002:localhost:9002 root@165.xxx.xxx.xxx. On the Droplet, runnc -zv localhost 9002—you should see a successful connection message. - Test Container-to-Droplet Connection: SSH into your Lando appserver with
lando ssh -s appserver, then runnc -zv host.docker.internal 9002(or your gateway IP). If this connects, the network path is working.
5. Tweak Firewall Rules (Avoid Overly Broad Access)
Your current iptables rule opens port 9002 to everyone, which is unnecessary. Restrict it to only allow connections from your Docker container subnet (find the subnet with docker network inspect lando_default):
sudo iptables -A INPUT -p tcp -s 172.18.0.0/16 --dport 9002 -j ACCEPT sudo iptables -D INPUT -p tcp -d 0/0 -s 0/0 --dport 9002 -j ACCEPT # Remove the old broad rule
6. Double-Check PHPStorm Settings
- Ensure the debug listener is active (green phone icon in the toolbar).
- Confirm path mappings: Your local project root should map to
/app(matches Lando's mount point). - Verify IDE key matches
xdebug.idekey = PHPSTORM.
After following these steps, reload your site and check if PHPStorm picks up the debug connection. If you still see issues, check the /xdebug.log in the container again—you should now see a successful connection to host.docker.internal:9002 instead of the error you got before.
内容的提问来源于stack exchange,提问作者drupalphil

