Nginx连接PHP-FPM套接字时遭遇Permission Denied权限问题求助
Nginx连接PHP-FPM套接字时遭遇Permission Denied权限问题求助
各位大佬好,我最近部署Laravel项目时碰到了个棘手的权限问题——尝试访问项目页面时直接报错,查Nginx错误日志发现是连接PHP-FPM的Unix套接字时被拒绝了,具体日志内容如下:
2024/10/05 22:09:56 [crit] 135537#135537: *3 connect() to unix:/run/php/php-fpm.sock failed (13: Permission denied) while connecting to upstream, client: 127.0.0.1, server: _, request: "GET / HTTP/1.1", upstream: "fastcgi://unix:/run/php/php-fpm.sock:", host: "telfoot.test"
我也查看了PHP-FPM的主配置文件(/etc/php/8.3/fpm/php-fpm.conf),能看到的全局配置段内容如下:
;;;;;;;;;;;;;;;;;;;;; ; FPM Configuration ; ;;;;;;;;;;;;;;;;;;;;; ; All relative paths in this configuration file are relative to PHP's install ; prefix (/usr). This prefix can be dynamically changed by using the ; '-p' argument from the command line. ;;;;;;;;;;;;;;;;;; ; Global Options ; ;;;;;;;;;;;;;;;;;; [global] ; Pid file ; Note: the default prefix is /var ; Default Value: none ; Warning: if you change the value here, you need to modify systemd ; service file accordingly. pid = /run/php/php8.3-fpm.pid
我已经试过重启Nginx和PHP-FPM服务,但问题依然存在,有没有大佬能指点下该怎么排查和修复这个权限问题呀?
我自己整理的一些可能解决思路(供参考,也期待大佬补充)
- 检查套接字文件的权限和所属:先执行
ls -l /run/php/php-fpm.sock查看该文件的用户、组和权限,正常情况下需要让Nginx的运行用户(通常是www-data)拥有读写权限。 - 修改PHP-FPM的套接字权限配置:找到PHP-FPM的pool配置文件(一般在
/etc/php/8.3/fpm/pool.d/www.conf),设置listen.owner和listen.group为www-data,同时配置listen.mode = 0660,确保同组用户能访问套接字。 - 将Nginx用户加入PHP-FPM的用户组:如果套接字的所属组是
php-fpm这类,执行usermod -aG php-fpm www-data,之后重启Nginx和PHP-FPM服务。 - 排查SELinux限制:如果是RHEL/CentOS系列系统,可能是SELinux阻止了Nginx访问套接字,可以临时执行
setenforce 0关闭SELinux测试,若问题解决再配置SELinux规则放行。
备注:内容来源于stack exchange,提问作者Amir
相关产品推荐
相关产品推荐

