Nginx报502 Bad Gateway完整排查思路(PHP-FPM场景)

Nginx 出现 502 Bad Gateway 是最常见的报错之一,90% 的情况都是 PHP-FPM 出了问题。下面是完整的排查思路,按顺序一步步来,基本都能解决。

1. 先看 PHP-FPM 是否在运行

systemctl status php-fpm

如果显示 failed 或 inactive,直接重启:

systemctl restart php-fpm

注意:CentOS 7 一般是 php-fpm,Ubuntu 可能是 php7.4-fpm 之类的,看你装的版本。

2. 看 Nginx 错误日志(最关键)

tail -f /var/log/nginx/error.log

常见错误信息:

错误1:connect() failed (111: Connection refused) while connecting to upstream
说明 PHP-FPM 没启动,或者监听地址不对。

错误2:upstream timed out
PHP 脚本执行超时了,或者 PHP-FPM 进程不够用。

错误3:Primary script unknown
Nginx 配置里的 SCRIPT_FILENAME 路径不对,找不到 PHP 文件。

3. 检查 Nginx 配置是否正确

nginx -t

如果显示 test is successful 说明配置语法没问题。

重点检查 fastcgi_pass 这一行:

location ~ \.php$ {
    fastcgi_pass   127.0.0.1:9000;  # 或者 unix:/run/php-fpm/www.sock
    fastcgi_index  index.php;
    fastcgi_param  SCRIPT_FILENAME  $document_root$fastcgi_script_name;
    include        fastcgi_params;
}

常见问题:

  • fastcgi_pass 地址和 PHP-FPM 实际监听地址不一致
  • SCRIPT_FILENAME 路径写错了

4. 检查 PHP-FPM 监听地址

netstat -tlnp | grep php-fpm

或者:

ss -tlnp | grep php-fpm

看 PHP-FPM 是监听在 9000 端口还是 unix sock 文件,然后和 Nginx 配置里的 fastcgi_pass 对应上。

5. 检查 PHP-FPM 进程数是否够

看 PHP-FPM 配置:

vi /etc/php-fpm.d/www.conf

重点参数:

pm = dynamic
pm.max_children = 50
pm.start_servers = 20
pm.min_spare_servers = 10
pm.max_spare_servers = 30

如果访问量大,进程数不够就会 502。

6. 检查 PHP 错误日志

tail -f /var/log/php-fpm/www-error.log

有时候 PHP 代码本身报错,也会导致 502。

7. 其他常见原因

磁盘满了

df -h

内存不够

free -h

如果内存不足,PHP-FPM 进程会被杀掉,也会 502。

SELinux 没关
参考我之前的文章,关掉 SELinux 试试。

排查顺序总结

  1. 重启 PHP-FPM → 看能不能恢复
  2. 看 Nginx 错误日志 → 定位具体错误
  3. 检查 Nginx 配置 → fastcgi_pass 和 SCRIPT_FILENAME
  4. 检查 PHP-FPM 状态 → 监听地址、进程数
  5. 检查系统资源 → 磁盘、内存
  6. 检查 SELinux

遇到服务器、Nginx、MySQL 报错,可以加微信远程协助排查问题。


emer 发布于  2026-10-4 19:27 

Nginx 日志分析技巧

Nginx 日志分析技巧

Nginx 日志是排查问题、分析流量的重要工具。学会看日志,网站问题排查效率翻倍。

1. 日志位置

# 默认访问日志
/var/log/nginx/access.log

# 默认错误日志
/var/log/nginx/error.log

可以在 nginx.conf 里自定义:

access_log /var/log/nginx/www.access.log;
error_log /var/log/nginx/www.error.log;

2. 日志格式

默认日志格式:

127.0.0.1 - - [04/Oct/2026:10:00:00 +0800] "GET / HTTP/1.1" 200 612 "https://www.baidu.com/" "Mozilla/5.0..."

各字段含义:

  • IP 地址
  • 请求时间
  • 请求方法和路径
  • 状态码
  • 响应大小
  • 来源页面
  • User-Agent

3. 常用分析命令

# 查看访问量前10的IP
awk '{print $1}' access.log | sort | uniq -c | sort -nr | head 10

# 查看访问量前10的页面
awk '{print $7}' access.log | sort | uniq -c | sort -nr | head 10

# 查看状态码分布
awk '{print $9}' access.log | sort | uniq -c | sort -nr

# 查看 404 请求
grep ' 404 ' access.log

# 查看 502 错误
grep ' 502 ' access.log

4. 排查问题

排查 502 错误:

grep ' 502 ' access.log | tail 20

排查慢请求:
开启慢日志:

slow_request_log /var/log/nginx/slow.log;
slow_request_time 5s;

排查爬虫:

grep 'Baiduspider' access.log
grep 'Googlebot' access.log

5. 流量统计

# 今天总访问量
grep '04/Oct/2026' access.log | wc -l

# 今天总流量
grep '04/Oct/2026' access.log | awk '{sum+=$10} END {print sum/1024/1024 " MB"}'

# 每小时访问量
awk '{print $4}' access.log | cut -d: -f2 | uniq -c

6. 日志切割

日志太大要切割,用 logrotate:

# /etc/logrotate.d/nginx
/var/log/nginx/*.log {
    daily
    missingok
    rotate 30
    compress
    notifempty
    create 0640 nginx adm
    postrotate
        systemctl reload nginx
    endscript
}

7. 常用工具

  • GoAccess:实时日志分析工具
  • ELK:Elasticsearch + Logstash + Kibana
  • Zabbix:监控告警

总结

Nginx 日志分析核心:

  • 位置:/var/log/nginx/
  • 命令:awk + sort + uniq
  • 排查:看状态码、看慢请求
  • 切割:用 logrotate

学会这些,日常日志分析基本够用了。


emer 发布于  2026-10-4 11:08 

Nginx 负载均衡配置

Nginx 负载均衡配置实战

网站流量大了,单台服务器扛不住,就得用负载均衡。Nginx 做负载均衡很简单,几行配置就行。

1. 基本配置

http {
    upstream backend {
        server 192.168.1.101:80;
        server 192.168.1.102:80;
        server 192.168.1.103:80;
    }

    server {
        listen 80;
        server_name www.example.com;

        location / {
            proxy_pass http://backend;
        }
    }
}

默认是轮询(round robin),请求轮流分到三台服务器。

2. 四种分配策略

轮询(默认):一个一个来。

权重(weight):按比例分配,性能好的服务器多分担。

upstream backend {
    server 192.168.1.101 weight=3;
    server 192.168.1.102 weight=2;
    server 192.168.1.103 weight=1;
}

3:2:1 的比例,第一台分一半请求。

ip_hash:同一个 IP 固定分到同一台服务器,解决 session 问题。

upstream backend {
    ip_hash;
    server 192.168.1.101;
    server 192.168.1.102;
}

least_conn:最少连接数优先,分给当前最闲的服务器。

upstream backend {
    least_conn;
    server 192.168.1.101;
    server 192.168.1.102;
}

3. 健康检查

upstream backend {
    server 192.168.1.101 max_fails=3 fail_timeout=30s;
    server 192.168.1.102 max_fails=3 fail_timeout=30s;
}

一台服务器挂了,自动从列表里摘掉,恢复了再加回来。

4. 常用参数

  • max_fails:失败几次算挂了,默认1次
  • fail_timeout:挂了多久再重试,默认10秒
  • down:标记服务器下线,不分配请求
  • backup:备用服务器,其他都挂了才用

5. 完整示例

upstream backend {
    server 192.168.1.101 weight=3 max_fails=3 fail_timeout=30s;
    server 192.168.1.102 weight=2 max_fails=3 fail_timeout=30s;
    server 192.168.1.103 backup;
}

server {
    listen 80;
    location / {
        proxy_pass http://backend;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

总结

Nginx 负载均衡核心:

  • upstream 定义服务器组
  • 四种策略:轮询、权重、ip_hash、最少连接
  • 健康检查自动摘除故障节点
  • 生产环境用权重 + 健康检查就够了

搞懂这些,多台服务器集群就跑起来了。


emer 发布于  2026-10-4 10:51 

Nginx 反向代理配置

Nginx 反向代理配置详解

Nginx 反向代理是最常用的服务器配置之一,把请求转发给后端服务。本文讲清楚核心配置。

1. 基本配置

server {
    listen 80;
    server_name example.com;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

2. 传递真实IP

后端服务要拿到用户真实IP,需要配置:

proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

3. 负载均衡

多台后端服务器,用 upstream 做负载均衡:

upstream backend {
    server 127.0.0.1:8080 weight=1;
    server 127.0.0.1:8081 weight=2;
}

server {
    location / {
        proxy_pass http://backend;
    }
}

4. 超时设置

proxy_connect_timeout 60s;
proxy_read_timeout 60s;
proxy_send_timeout 60s;

5. 静态文件处理

静态文件直接由 Nginx 处理,不用转发给后端:

location ~* \.(js|css|png|jpg|gif)$ {
    root /data/www;
    expires 30d;
}

6. HTTPS 反向代理

server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate /path/to/cert.pem;
    ssl_certificate_key /path/to/key.pem;

    location / {
        proxy_pass http://127.0.0.1:8080;
    }
}

总结

Nginx 反向代理的核心就是 proxy_pass,配上 proxy_set_header 传递必要信息,再加上超时和静态文件处理,基本够用了。


emer 发布于  2026-10-4 10:42 

Nginx 日志分析技巧

Nginx 日志分析常用命令

Nginx 日志是排查问题、分析流量的重要工具。掌握几个常用命令,线上排查效率翻倍。

1. 查看访问量

# 总请求数
wc -l access.log

# 今天的请求数
grep "04/Oct/2026" access.log | wc -l

2. 分析 IP 访问量

# 访问最多的前10个IP
awk '{print $1}' access.log | sort | uniq -c | sort -nr | head -10

3. 分析 URL 访问量

# 访问最多的前10个URL
awk '{print $7}' access.log | sort | uniq -c | sort -nr | head -10

4. 分析状态码

# 统计各状态码数量
awk '{print $9}' access.log | sort | uniq -c | sort -nr

# 404错误数量
grep " 404 " access.log | wc -l

5. 分析流量

# 总流量
awk '{sum += $10} END {print sum/1024/1024 " MB"}' access.log

6. 实时监控

# 实时查看最新日志
tail -f access.log

# 实时查看502错误
tail -f access.log | grep " 502 "

7. 查找慢请求

# 响应时间超过1秒的请求
awk '$NF > 1' access.log | head -10

8. 排查爬虫

# 百度爬虫访问量
grep "Baiduspider" access.log | wc -l

总结

Nginx 日志分析主要靠 awk + sort + uniq 组合,掌握这几个命令,日常排查基本够用。复杂分析可以用 GoAccess 等可视化工具。


emer 发布于  2026-10-4 10:31 

Nginx 配置实战:反向代理、负载均衡与缓存

前言

Nginx 是目前最流行的 Web 服务器和反向代理软件。很多人会写简单的配置,但对反向代理、负载均衡、缓存这些高级用法并不熟悉。本文带你从零开始,掌握 Nginx 的核心配置技巧。

一、反向代理基础

反向代理是 Nginx 最常用的功能之一。用户请求 Nginx,Nginx 再把请求转发给后端应用服务器。

server {
    listen 80;
    server_name example.com;

    location / {
        proxy_pass http://127.0.0.1:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

关键说明:

  • proxy_pass:后端服务地址
  • proxy_set_header:传递真实的客户端信息给后端,否则后端拿到的都是 Nginx 的信息

二、负载均衡

当后端有多台服务器时,可以用 Nginx 做负载均衡。

1. 轮询(默认)

upstream backend {
    server 127.0.0.1:8080;
    server 127.0.0.1:8081;
    server 127.0.0.1:8082;
}

server {
    listen 80;
    server_name example.com;

    location / {
        proxy_pass http://backend;
    }
}

2. 加权轮询

upstream backend {
    server 127.0.0.1:8080 weight=3;
    server 127.0.0.1:8081 weight=2;
    server 127.0.0.1:8082 weight=1;
}

weight 值越大,分配的请求越多。适合配置不同的服务器。

3. ip_hash 会话保持

upstream backend {
    ip_hash;
    server 127.0.0.1:8080;
    server 127.0.0.1:8081;
}

同一个 IP 的请求总是分配到同一台后端服务器,适合有 session 的场景。

三、缓存配置

Nginx 缓存可以大幅减轻后端压力,提升响应速度。

1. 配置缓存路径

http {
    # 定义缓存路径和参数
    proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=my_cache:10m max_size=10g inactive=60m use_temp_path=off;

    server {
        listen 80;
        server_name example.com;

        location / {
            proxy_pass http://backend;
            proxy_cache my_cache;
            proxy_cache_valid 200 302 10m;
            proxy_cache_valid 404 1m;
            proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504;
            add_header X-Cache-Status $upstream_cache_status;
        }
    }
}

关键参数说明:

  • keys_zone:缓存共享内存区大小
  • max_size:缓存最大占用空间
  • inactive:多久没访问就自动清理
  • proxy_cache_valid:不同状态码的缓存时间
  • X-Cache-Status:查看是否命中缓存(HIT/MISS/BYPASS)

2. 不缓存特定请求

location /admin/ {
    proxy_pass http://backend;
    proxy_cache off;  # 后台页面不缓存
}

四、HTTPS 配置

server {
    listen 443 ssl http2;
    server_name example.com;

    ssl_certificate /path/to/cert.pem;
    ssl_certificate_key /path/to/key.pem;
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;

    location / {
        proxy_pass http://127.0.0.1:8080;
    }
}

# HTTP 跳转 HTTPS
server {
    listen 80;
    server_name example.com;
    return 301 https://$host$request_uri;
}

五、常见问题排查

1. 502 Bad Gateway

通常是后端服务挂了或者端口不对:

# 检查后端服务是否在运行
netstat -tlnp | grep 8080

# 查看 Nginx 错误日志
tail -f /var/log/nginx/error.log

2. 上传文件大小限制

http {
    client_max_body_size 50M;
}

3. 超时设置

location / {
    proxy_connect_timeout 60s;
    proxy_read_timeout 60s;
    proxy_send_timeout 60s;
}

总结

Nginx 配置的核心思路:

  1. 反向代理:把请求转发给后端应用
  2. 负载均衡:多台后端服务器分担流量
  3. 缓存:静态内容缓存,减少后端压力
  4. HTTPS:加密传输,安全第一

掌握这些配置,你就能应对大部分 Web 服务器场景了。Nginx 配置文件改完记得执行 nginx -t 检查语法,然后 nginx -s reload 重载生效。


emer 发布于  2026-10-4 09:56