三台独立主机部署Apache、PHP、MySQL的跨主机配置咨询
Alright, let's walk through setting up your distributed LAMP stack—Apache on pc1, PHP-FPM on pc2, MySQL on pc3. I’ve deployed similar split architectures a few times, so here’s a practical, step-by-step guide to get everything talking to each other:
All three machines need to communicate freely (or at least over required ports). Here’s what to do:
- Verify you can ping each PC from the others: run
ping pc1-ipfrom pc2 and pc3, and vice versa. If pings fail, check firewall settings or network routing first. - Open necessary ports on each machine’s firewall:
- pc2: Allow traffic on port 9000 (default for PHP-FPM). Use
ufw allow 9000/tcp(Debian/Ubuntu) orfirewall-cmd --add-port=9000/tcp --permanent && firewall-cmd --reload(RHEL/CentOS). - pc3: Allow traffic on port 3306 (MySQL default). Use the same firewall commands but swap 9000 for 3306.
- pc1: Keep ports 80 (HTTP) and 443 (HTTPS) open for Apache traffic.
- pc2: Allow traffic on port 9000 (default for PHP-FPM). Use
Apache relies on PHP-FPM to process PHP files these days, so we need to set up pc2’s PHP-FPM to listen for connections from pc1:
- Install PHP-FPM if you haven’t already:
apt install php-fpm(Debian/Ubuntu) oryum install php-fpm(RHEL/CentOS). - Edit the PHP-FPM pool config file—usually located at
/etc/php/{your-php-version}/fpm/pool.d/www.conf(replace{your-php-version}with 7.4, 8.2, etc.):- Change
listen = 127.0.0.1:9000tolisten = 0.0.0.0:9000(this makes PHP-FPM listen on all network interfaces). - Add or update
listen.allowed_clients = pc1-ip-address(restricts access to only pc1, which is more secure than allowing everyone).
- Change
- Restart PHP-FPM to apply changes:
systemctl restart php-fpm.
Now we need to tell Apache on pc1 to send all .php file requests to pc2’s PHP-FPM service:
- Enable the required Apache modules:
a2enmod proxy proxy_fcgi(Debian/Ubuntu) or edit your Apache config to loadmod_proxyandmod_proxy_fcgi(RHEL/CentOS). Then restart Apache:systemctl restart apache2. - Open your Apache site config file (e.g.,
/etc/apache2/sites-available/your-site.conf) and add this block inside the<Directory /var/www/html>section:<FilesMatch \.php$> # Replace pc2-ip-address with your actual pc2 IP SetHandler "proxy:fcgi://pc2-ip-address:9000" </FilesMatch> - Test your Apache config for errors:
apache2ctl configtest. If it returnsSyntax OK, restart Apache again. - To test this, create a file called
info.phpin pc1’s web root (/var/www/html) with this content:
Later, visiting<?php phpinfo(); ?>http://pc1-ip/info.phpshould show you PHP’s info page—confirm theSERVER_ADDRis pc1’s IP and the FPM connection points to pc2.
MySQL defaults to only accepting local connections, so we need to grant access to pc1 and pc2:
- Log into MySQL as root:
mysql -u root -p. - Create a database user that can connect from pc1 and pc2 (replace placeholders with your details):
Pro tip: If all PCs are on a local subnet (like 192.168.1.x), you can use-- Create user for pc1 CREATE USER 'web-app-user'@'pc1-ip-address' IDENTIFIED BY 'strong-password-here'; -- Create user for pc2 (if your PHP app runs code that connects directly to MySQL) CREATE USER 'web-app-user'@'pc2-ip-address' IDENTIFIED BY 'strong-password-here'; -- Grant privileges to your app's database GRANT ALL PRIVILEGES ON your-app-db.* TO 'web-app-user'@'pc1-ip-address'; GRANT ALL PRIVILEGES ON your-app-db.* TO 'web-app-user'@'pc2-ip-address'; FLUSH PRIVILEGES;192.168.1.%instead of individual IPs to allow the whole subnet. - Edit MySQL’s config file (e.g.,
/etc/mysql/mysql.conf.d/mysqld.cnfor/etc/my.cnf):- Change
bind-address = 127.0.0.1tobind-address = 0.0.0.0(lets MySQL listen on all interfaces).
- Change
- Restart MySQL:
systemctl restart mysql.
- PHP Forwarding Test: Visit
http://pc1-ip/info.php—you should see the PHP info page, which confirms Apache is successfully sending requests to pc2’s PHP-FPM. - MySQL Connection Test: Create a file
db-test.phpin pc1’s web root:
Visit<?php $dbHost = 'pc3-ip-address'; $dbUser = 'web-app-user'; $dbPass = 'strong-password-here'; $dbName = 'your-app-db'; $conn = new mysqli($dbHost, $dbUser, $dbPass, $dbName); if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } echo "Successfully connected to MySQL on pc3!"; $conn->close(); ?>http://pc1-ip/db-test.php—if you see the success message, your entire stack is working.
- Security: Avoid using
0.0.0.0for listening addresses unless necessary—restrict to specific IPs/subnets. Use strong passwords, and consider enabling SSL for MySQL connections and Apache-PHP-FPM communication in production. - Performance: Adjust PHP-FPM’s process pool settings (in
www.conf) based on pc2’s resources. For Apache, set a reasonableProxyTimeoutto avoid early timeouts during slow PHP requests.
内容的提问来源于stack exchange,提问作者Abdul Rahman

