[{"data":1,"prerenderedAt":337},["ShallowReactive",2],{"site-data":3,"article-25":143,"article-show-hot-25":171,"article-show-new-25":261},{"settings":4,"categorys":35,"tree":97,"models":118,"search_model_select":128,"nav_list":130},{"changefreq":5,"changyan_app_id":6,"changyan_app_key":6,"copy":7,"description":8,"editor":9,"file":6,"guest_feedback":10,"head_html":6,"icp":11,"index_banner":12,"index_banner_bg":13,"is_excel":14,"is_watermark":10,"keywords":15,"links":16,"logo":17,"lzcms_banner":6,"lzcms_banner_link":18,"member_register_enabled":14,"qq_app_id":6,"qq_app_key":6,"qr_code":6,"search_model":19,"site_closedreason":6,"site_idea":6,"site_idea1":20,"site_idea2":21,"site_idea3":22,"site_name":23,"site_statistice":6,"site_status":14,"site_url":18,"sitemap_model":19,"stationmaster_motto":24,"stationmaster_name":25,"stationmaster_occupation":26,"stationmaster_qq":27,"stationmaster_qqnet":28,"stationmaster_qqnet_code":29,"threshold":14,"title_add":30,"watermark":6,"watermark_alpha":31,"watermark_height":32,"watermark_locate":33,"watermark_width":34},"weekly","","版权所有 © \u003Ca class=\"site_url\" href=\"https://zhl123.com\">2026 zhl123.com\u003C/a>","linux、Python、mysql、docker、k8s技术交流","layedit","0","粤ICP备15054664号-1","/uploads/images/20181109/7a86191de8b8bb60e9c6b54d8b27c5cc.jpg","#xe604","1","linux、Python、mysql、docker、k8s","{\"1\":{\"id\":\"1\",\"link_url\":\"https://linux.org\",\"logo\":\"\",\"name\":\"linux\",\"sort\":\"0\",\"status\":\"1\"}}","/uploads/images/20181109/e7305012448aed257176dd591846f50a.png","https://zhl123.com","2","学无止境\n学习，探索，研究，从不了解到了解，从无知到掌握，到灵活运用，在不断的学习中加深认识。由浅入深，由表及里。","业精于勤\n“业精于勤荒于嬉”，精深的业技靠的是勤学、刻苦努力，靠的是争分夺秒的勤学苦练才会有精深的技术。得在认真，失在随便。","工匠精神\n精益求精，注重细节，追求完美和极致，不惜花费时间精力，孜孜不倦，反复改进产品，把99%提高到99.99%。","linux","业精于勤、学无止境、工匠精神","廖地金","高级Linux运维工程师","1256636645","592958303","\u003Ca target=\"_blank\" href=\"//shang.qq.com/wpa/qunwpa?idkey=09be7d1a682073783fd636102e666393169b8a8aac8f3393da1de57bcaa821a0\">\u003Cimg border=\"0\" src=\"//pub.idqqimg.com/wpa/images/group.png\" alt=\"Linux技术\" title=\"Linux技术\">\u003C/a>"," | Python | mysql | docker | k8s 技术交流","100","300","9","500",{"0":36,"17":51,"18":60,"19":63,"20":67,"21":71,"22":76,"25":80,"26":83,"27":89,"29":94},{"children":37},{"0":38,"25":43,"26":48},[39,40,41,42],25,21,22,26,[44,45,46,47],17,18,19,20,[49,50],27,29,{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},"index",1,"list","article",2,"文章模型","show","/article/lists?category_id=17",{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},"python","/article/lists?category_id=18",{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},"容器技术",3,"/article/lists?category_id=19",{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},"负载均衡",4,"/article/lists?category_id=20",{"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},"分享无价",0,5,"/article/lists?category_id=21",{"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},"随笔",6,"/article/lists?category_id=22",{"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},"学无止境","/article/lists?category_id=25",{"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},"picture","图集模型","关于",8,"/picture/lists?category_id=26",{"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},"page","单页模型","关于博主","/page/27",{"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},"留言","/feedback",[98,108,110,112],{"children":99,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[100,102,104,106],{"children":101,"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},[],{"children":103,"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},[],{"children":105,"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},[],{"children":107,"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},[],{"children":109,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":111,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":113,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[114,116],{"children":115,"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},[],{"children":117,"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},[],{"1":119,"2":120,"3":121,"4":122,"5":125},{"id":53,"index_template":52,"list_template":54,"name":91,"show_template":58,"status":73,"tablename":90},{"id":56,"index_template":52,"list_template":54,"name":57,"show_template":58,"status":73,"tablename":55},{"id":65,"index_template":52,"list_template":54,"name":85,"show_template":58,"status":73,"tablename":84},{"id":69,"index_template":52,"list_template":54,"name":123,"show_template":58,"status":73,"tablename":124},"链接模型","link",{"id":74,"index_template":52,"list_template":54,"name":126,"show_template":58,"status":73,"tablename":127},"下载模型","download",[129],{"id":56,"name":57,"tablename":55},[131,137,139,141],{"children":132,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[133,134,135,136],{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},{"children":138,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":140,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":142,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[],{"article":144,"breadcrumb":154,"category":158,"next":159,"prev":162,"second_categorys":165,"seo":170},{"id":39,"category_id":44,"title":145,"keywords":146,"description":147,"image_url":6,"content":148,"content_md":149,"url":150,"hits":151,"is_recommend":73,"is_top":73,"create_time":152,"update_time":153},"四步16点高效搞定高性能web服务器nginx","高效,搞定,服务器","Nginx(读音engine x)服务器由于性能优秀稳定、配置简单以及跨平台，被越来越多的公司和个人所采用，现已成为市场份额继Apache之后的第二大Web服务器。各大小网站论坛博客也介绍说明了Nginx从安装到优化的各种配置。 不过看了很多这些相关Nginx的文档之后，发现一个比较大的问题，就是这些文档基本也就从两个方面着手，一是修改Nginx的配置文件，二是调整操作系统的相关内核参数；而且文档说明也不够明了，缺乏比较系统级别的优化。 本文将从Nginx源码编译安装开始，到","\u003Cp>\u003Cspan>Nginx(读音engine x)服务器由于性能优秀稳定、配置简单以及跨平台，被越来越多的公司和个人所采用，现已成为市场份额继Apache之后的第二大Web服务器。各大小网站论坛博客也介绍说明了Nginx从安装到优化的各种配置。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>不过看了很多这些相关Nginx的文档之后，发现一个比较大的问题，就是这些文档基本也就从两个方面着手，一是修改Nginx的配置文件，二是调整操作系统的相关内核参数；而且文档说明也不够明了，缺乏比较系统级别的优化。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>本文将从Nginx源码编译安装开始，到修改配置文件，调整系统内核参数以及架构四个方面着手分别介绍如何优化。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>一. &nbsp; &nbsp; 安装\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Chr>\u003Cblockquote>\u003Cb>(1) &nbsp;精简模块\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>Nginx由于不断添加新的功能，附带的模块也越来越多。很多操作系统厂商为了用户方便安装管理，都增加了rpm、deb或者其他自有格式软件包，可以本地甚至在线安装。不过我不太建议使用这种安装方式。这虽然简化了安装，在线安装甚至可以自动解决软件依赖关系，但是安装后软件的文件布局过于分散，不便管理维护；同时也正是由于存在软件包之间的依赖关系，导致当有安全漏洞、或者其它问题，想要通过更新升级Nginx新版本时却发现yum、deb源还未发布新版本(一般都落后于官网发布的软件版本)。最重要的是采用非源码编译安装的方式，默认会添加入许多模块，比如邮件相关、uwsgi、memcache等等，很多网站运行时这些模块根本未用到，虽然平时占用的资源很小，但是仍然可能是压弯骆驼的一根稻草。各种非必需模块默认安装运行的同时，也给Web系统带来了安全隐患。尽量保持软件的轻装上阵，是每个运维应当尽力做到的，所以我建议一般常用的服务器软件使用源码编译安装管理。。我一般使用的编译参数如下，PHP相关模块fastcgi被保留用作后文优化说明，：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>./configure \\&nbsp;\u003Cbr>\"--prefix=/App/nginx\" \\&nbsp;\u003Cbr>\"--with-http_stub_status_module\" \\&nbsp;\u003Cbr>\"--without-http_auth_basic_module\" \\&nbsp;\u003Cbr>\"--without-http_autoindex_module\" \\&nbsp;\u003Cbr>\"--without-http_browser_module\" \\&nbsp;\u003Cbr>\"--without-http_empty_gif_module\" \\&nbsp;\u003Cbr>\"--without-http_geo_module\" \\&nbsp;\u003Cbr>\"--without-http_limit_conn_module\" \\&nbsp;\u003Cbr>\"--without-http_limit_req_module\" \\&nbsp;\u003Cbr>\"--without-http_map_module\" \\&nbsp;\u003Cbr>\"--without-http_memcached_module\" \\&nbsp;\u003Cbr>\"--without-http_proxy_module\" \\&nbsp;\u003Cbr>\"--without-http_referer_module\" \\&nbsp;\u003Cbr>\"--without-http_scgi_module\" \\&nbsp;\u003Cbr>\"--without-http_split_clients_module\" \\&nbsp;\u003Cbr>\"--without-http_ssi_module\" \\&nbsp;\u003Cbr>\"--without-http_upstream_ip_hash_module\" \\&nbsp;\u003Cbr>\"--without-http_upstream_keepalive_module\" \\&nbsp;\u003Cbr>\"--without-http_upstream_least_conn_module\" \\&nbsp;\u003Cbr>\"--without-http_userid_module\" \\&nbsp;\u003Cbr>\"--without-http_uwsgi_module\" \\&nbsp;\u003Cbr>\"--without-mail_imap_module\" \\&nbsp;\u003Cbr>\"--without-mail_pop3_module\" \\&nbsp;\u003Cbr>\"--without-mail_smtp_module\" \\&nbsp;\u003Cbr>\"--without-poll_module\" \\&nbsp;\u003Cbr>\"--without-select_module\" \\&nbsp;\u003Cbr>\"--with-cc-opt='-O2'\"\u003C/blockquote>\u003Cp>\u003Cspan>编译参数根据网站是否真正用到的原则增添或者减少，比如我们公司如果需要用到ssi模块,从而能够实现访问shtml页面，可以将第17行删除，那么Nginx将默认安装。大家可以通过运行 \"./configure --help\" 查看编译帮助，决定是否需要安装哪些模块。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(2) &nbsp;GCC编译参数优化 [可选项】\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>GCC总共提供了5级编译优化级别：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>-O0:\u003C/b>无优化。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>-O和-O1:\u003C/b>使用能减少目标代码尺寸以及执行时间并且不会使编译时间明显增加的优化。在编译大型程序的时候会显著增加编译时内存的使用。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>-O2:\u003C/b>包含-O1的优化并增加了不需要在目标文件大小和执行速度上进行折衷的优化。编译器不执行循环展开以及函数内联。此选项将增加编译时间和目标文件的执行性能。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>-Os:\u003C/b>可以看成 -O2.5，专门优化目标文件大小，执行所有的不增加目标文件大小的-O2优化选项，并且执行专门减小目标文件大小的优化选项。适用于磁盘空间紧张时使用。但有可能有未知的问题发生，况且目前硬盘容量很大，常用程序无必要使用。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>-O3:\u003C/b>打开所有 -O2 的优化选项外增加 -finline-functions、-funswitch-loops、-fgcse-after-reload 优化选项。相对于 -O2 性能并未有较多提高，编译时间也最长，生成的目标文件也更大更占内存，有时性能不增反而降低，甚至产生不可预知的问题(包括错误)，所以并不被大多数软件安装推荐，除非有绝对把握方可使用此优化级别。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>修改GCC编译参数，提高编译优化级别，此方法适用于所有通过GCC编译安装的程序，不止Nginx。稳妥起见用 -O2，这也是大多数软件编译推荐的优化级别。查看Nginx源码文件 auto/cc/gcc，搜索NGX_GCC_OPT，默认GCC编译参数为-O，可以直接修改内容为NGX_GCC_OPT=\"-O2\"或者在 ./configure配置时添加--with-cc-opt='-O2'选项。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>二. &nbsp; &nbsp; &nbsp;配置\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Chr>\u003Cp>\u003Cspan>应用服务器的性能优化主要在合理使用CPU、内存、磁盘IO和网络IO四个方面，现在我们从Nginx配置文件 nginx.conf 入手进行优化：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(1) &nbsp;工作进程数的选择\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>指令：worker_processes\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义了Nginx对外提供web服务时的工作进程数。最优值取决于许多因素，包括（但不限于）CPU核心的数量、存储数据的硬盘数量及负载模式。不能确定的时候，将其设置为可用的CPU内核数将是一个好的开始（设置为“auto”将尝试自动检测它）。Shell执行命令 &nbsp;ps ax | grep \"nginx: worker process\" | grep -v \"grep\" 可以看到运行中的Nginx工作进程数，一般建议设置成服务器逻辑核心数，Shell执行命令 cat /proc/cpuinfo | grep processor | wc -l 可以检测出服务器逻辑核心总数，偷懒可以直接写auto，Nginx自适应。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(2) &nbsp;是否绑定CPU\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：worker_cpu_affinity\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>绑定工作进程到对应CPU核心，Nginx默认未开启CPU绑定。目前的服务器一般为多核CPU，当并发很大时，服务器各个CPU的使用率可能出现严重不均衡的局面，这时候可以考虑使用CPU绑定，以达到CPU使用率相对均匀的状态，充分发挥多核CPU的优势。top、htop等程序可以查看所有CPU核心的使用率状况。绑定样例：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>worker_processes &nbsp; &nbsp;4;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>worker_cpu_affinity 0001 0010 0100 1000;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(3) &nbsp;打开文件数限制\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：worker_rlimit_nofile\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>设定了每个Nginx工作进程打开的最大文件数，受限于系统的用户进程打开文件数限制，未设置则使用系统默认值。理论上应该设置为当前Shell启动进程的最大打开文件数除以Nginx的工作进程数。由于Nginx的工作进程打开文件数并不一完全均匀，所以可以将其设置成Shell启动进程的最大打开文件数。Shell执行命令 ulimit -n 可以查看当前登录Shell会话最大打开文件数数限制。Linux系统用户进程默认同时打开文件最大数为1024，这个值太小，访问量稍大就报“too many open files\"。Shell执行命令先修改用户打开文件数限制：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>echo \"* - nofile 65536\" &gt;&gt; /etc/security/limits.conf\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>然后添加入/etc/profile如下两行内容，修改所有Shell和通过Shell启动的进程打开文件数限制：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>echo \"ulimit -n 65536\" &gt;&gt; /etc/profile\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>Shell执行命令使当前Shell临时会话立即生效：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>ulimit -n 65536\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(4) 惊群问题\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：accept_mutex\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>如果 accept_mutex 指令值为 on 启用，那么将轮流唤醒一个工作进程接收处理新的连接，其余工作进程继续保持睡眠；如果值为 off 关闭，那么将唤醒所有工作进程，由系统通过use指令指定的网络IO模型调度决定由哪个工作进程处理，未接收到连接请求的工作进程继续保持睡眠，这就是所谓的“惊群问题”。Web服务器Apache的进程数很多，成百上千也是时有的事，“惊群问题”也尤为明显。Nginx为了稳定，参数值保守的设置为 on 开启状态。可以将其设置成Off 提高性能和吞吐量，但这样也会带来上下文切换增多或者负载升高等等其它资源更多消耗的后果。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(5) &nbsp;网络IO模型\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：use\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义了Nginx设置用于复用客户端线程的轮询方法(也可称多路复用网络IO模型)。这自然是选择效率更高的优先，Linux 2.6+内核推荐使用epoll，FreeBSD推荐使用kqueue，安装时Nginx会自动选择。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(6) &nbsp;连接数\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：worker_connections\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义了Nginx一个工作进程的最大同时连接数，不仅限于客户端连接，包括了和后端被代理服务器等其他的连接。官网文档还指出了该参数值不能超过 worker_rlimit_nofile 值，所以建议设置成和 worker_rlimit_nofile 值相等。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(7) &nbsp;打开文件缓存\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：open_file_cache\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>开启关闭打开文件缓存，默认值 off 关闭，强烈建议开启，可以避免重新打开同一文件带来的系统开销，节省响应时间。如需开启必须后接参数 max=数字，设置缓存元素的最大数量。当缓存溢出时，使用LRU(最近最少使用)算法删除缓存中的元素；可选参数 inactive=时间 设置超时，在这段时间内缓存元素如果没有被访问，将从缓存中删除。示例：open_file_cache max=65536 &nbsp;inactive=60s。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：open_file_cache_valid\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>设置检查open_file_cache缓存的元素的时间间隔。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：open_file_cache_min_uses\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>设置在由open_file_cache指令的inactive参数配置的超时时间内， 文件应该被访问的最小次数。如果访问次数大于等于此值，文件描述符会保留在缓存中，否则从缓存中删除。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(8) &nbsp;日志相关\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：access_log 和 error_log\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>当并发很大时，Nginx的访问日志和错误日志的保存肯定会造成对磁盘的大量读写，也将影响Nginx的性能。并发量越大，IO越高。这时候可以考虑关闭访问日志和错误日志，或者将日志保存到tmpfs文件系统里，或者减少保存的访问日志条目和错误日志的级别，从而避免磁盘IO的影响。关闭日志使用 access_log\u003Cb>off。如必须保存日志，可以按每日或者每时或者其它时间段对日志做切割，这也可以减小IO，虽然可能效果不是特别大，不过因为日志文件尺寸变小了很多，也方便查阅或归档分析日志。一般线上环境建议错误日志设置为 error 或者 crit。自定义访问日志的条目和错误日志的级别，详细信息可以参阅官网或者网上其它文档，按需修改。\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(9) &nbsp;隐藏Nginx版本号\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：server_tokens\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>开启或关闭“Server”响应头中输出的Nginx版本号。推介设置为 off，关闭显示响应头的版本号，对性能的提高有小小的裨益，主要还是为了安全起见，不被骇客找到版本号对应的漏洞，从而被攻击。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(10) 压缩相关\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：gzip\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>Nginx默认开启了gzip压缩功能。有可能很多人认为，开启gzip压缩会增加CPU的处理时间和负载。但是经过我们网站的测试发现，关闭了gzip压缩功能的Nginx虽然减少了CPU计算，节省了服务器的响应时间，但网站页面总体响应时间反而加长了，原因在于js和css、xml、json、html等等这些静态文件的数据传输时间的增长大大超过了服务器节省出来的响应时间，得不偿失。gzip on 开启压缩后，大约可以减少75%的文件尺寸，不但节省了比较多的带宽流量，也提高了页面的整体响应时间。所有建议还是开启。当然也不是所有的静态文件都需要压缩，比如静态图片和PDF、视频，文件本身就应当做压缩处理后保存到服务器。这些文件再次使用gzip压缩，压缩的比例并不高，甚至适得其反，压缩后文件尺寸增大了。CPU压缩处理这些静态文件增加占用的服务器响应时间绝大部分时候会超过了被压缩减小的文件尺寸减少的数据传输时间，不划算。是否需要对Web网站开启压缩，以及对哪些文件过滤压缩，大家可以通过使用HttpWatch、Firebug等等网络分析工具对比测试。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：\u003C/b>\u003Cb>gzip_comp_level\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>指定压缩等级，其值从1到9，数字越大，压缩率越高，越消耗CPU，负载也越高。9等级无疑压缩率最高，压缩后的文件尺寸也最小，但也是最耗CPU资源，负载最高，速度最慢的，这对于用户访问有时是无法忍受的。一般推荐使用1-4等级，比较折衷的方案。我们公司网站使用等级2。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：\u003C/b>\u003Cb>gzip_min_length\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>指定压缩的文件最小尺寸，单位 bytes 字节，低于该值的不压缩，超过该值的将被压缩。我们网站设置为1k，太小的文件没必要压缩，压缩过小尺寸文件带来增加的CPU消耗时间和压缩减少的文件尺寸降低的数据下载时间互相抵消，并有可能增加总体的响应时间。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：gzip_types\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>指定允许压缩的文件类型，Nginx配置目录 conf 下的 mime.types 文件存放了Nginx支持的文件类型，text/html类型文件，文件后缀为html htm shtml默认压缩。推荐配置：gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(11) 浏览器缓存\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>\u003Cb>指令\u003C/b>：expires\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>设置HTTP应答中的“Expires”和“Cache-Control”头标。\"Expires\"一般结合\"Last-Modified\"使用。当设置了合理的expires配置时，浏览器第一次访问Web页面元素，会下载页面中的的静态文件到本机临时缓存目录下。第二次及之后再次访问相同URL时将发送带头标识\"If-Modified-Since\"和本地缓存文件时间属性值的请求给服务器，服务器比对服务器本地文件时间属性值，如果未修改，服务器直接返回http 304状态码，浏览器直接调用本地已缓存的文件；如果时间属性值修改了，重新发送新文件。这样就避免了从服务器再次传送文件内容，减小了服务器压力，节省了带宽，同时也提高了用户访问速度，一举三得。指令后接数字加时间单位，即为缓存过期时间；-1 表示永远过期，不缓存。强烈建议添加expires配置，过期时间的选择具体分析。我们公司的部分Nginx配置如下：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>location ~ .+\\.(gif|jpg|jpeg|png|bmp|swf)$\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>{\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>expires 30d;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>}\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>location ~ .+\\.(js|css|xml|javascript|txt|csv)$\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>{\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>expires 30d;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>}\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>或者统一将静态文件放在固定目录下再对目录做location和expires，示例：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>location /static/\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>{\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>expires 30d;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>}\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(12) 持久连接\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>指令：keepalive_timeout\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>启用Http的持久连接Keepalive属性，复用之前已建立的TCP连接接收请求、发送回应，减少重新建立TCP连接的资源时间开销。在此的建议是当网站页面内容以静态为主时，开启持久连接；若主要是动态网页，且不能被转化为静态页面，则关闭持久连接。后接数字和时间单位符号。正数为开启持久连接，0关闭。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(13) 减少HTTP请求次数\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>网站页面中存在大量的图片、脚本、样式表、Flash等静态元素，减少访问请求次数最大的优点就是减少用户首次访问页面的加载时间。可以采用合并相同类型文件为一个文件的办法减少请求次数。这其实属于Web前端优化范畴，应当由Web前段工程师做好相关静态文件的规划管理，而不是由运维来做。不过Nginx也可以通过安装阿里巴巴提供的Concat或者Google的PageSpeed模块实现这个合并文件的功能。我们公司并未使用合并功能，具体安装配置信息请查询网上相关文档，这里不再累述。Concat源代码网址：\u003Ca href=\"https://github.com/alibaba/nginx-http-concat/\" target=\"_blank\">https://github.com/alibaba/nginx-http-concat/\u003C/a>，PageSpeed源代码网址：\u003Ca href=\"https://github.com/pagespeed/ngx_pagespeed\" target=\"_blank\">https://github.com/pagespeed/ngx_pagespeed\u003C/a>。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>(14) PHP相关\u003C/b>\u003C/blockquote>\u003Cp>\u003Cspan>Nginx不能直接解析PHP代码文件，需要调用FastCGI接口转给PHP解释器执行，然后将结果返回给Nginx。PHP优化本文暂不介绍。Nginx可以开启FastCGI的缓存功能，从而提高性能。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_temp_path\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义FastCGI缓存文件保存临时路径。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache_path\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义FastCGI缓存文件保存路径和缓存的其它参数。缓存数据以二进制数据文件形式存储，缓存文件名和key都是通过对访问URL使用MD5计算获得的结果。缓存文件先保存至fastcgi_temp_path指定的临时目录下，然后通过重命名操作移至fastcgi_cache_path指定的缓存目录。levels指定了目录结构,子目录数以16为基数；keys_zone指定了共享内存区名和大小，用于保存缓存key和数据信息；inactive指定了缓存数据保存的时间，当这段时间内未被访问，将被移出；max_size指定了缓存使用的最大磁盘空间，超过容量时将最近最少使用数据删除。建议fastcgi_temp_path和fastcgi_cache_path设为同一分区，同分区移动操作效率更高。示例：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>fastcgi_temp_path /tmp/fastcgi_temp;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>fastcgi_cache_path /tmp/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:16m inactive=30m max_size=1g;\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>示例中使用/tmp/fastcgi_temp作为FastCGI缓存的临时目录；/tmp/fastcgi_cache作为FastCGI缓存保存的最终目录；一级子目录为16的一次方16个，二级子目录为16的2次方256个；共享内存区名为cache_fastcgi，占用内存128MB；缓存过期时间为30分钟；缓存数据保存于磁盘的最大空间大小为1GB。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache_key\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>定义FastCGI缓存关键字。启用FastCGI缓存必须加上这个配置，不然访问所有PHP的请求都为访问第一个PHP文件URL的结果。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache_valid\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>为指定的Http状态码指定缓存时间。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache_min_uses\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>指定经过多少次请求相同的URL将被缓存。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache_use_stale\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>指定当连接FastCGI服务器发生错误时，哪些情况使用过期数据回应。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>\u003Cb>指令：fastcgi_cache\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>缓存使用哪个共享内存区。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>我常用nginx.conf模板，大家根据情况做适当修改：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>\u003Cb>[plain]\u003C/b>view plaincopy&nbsp;\u003Cbr>user &nbsp;nginx nginx;&nbsp;\u003Cbr>worker_processes &nbsp;auto;&nbsp;\u003Cbr>error_log &nbsp;logs/error.log error;&nbsp;\u003Cbr>pid &nbsp; &nbsp; &nbsp; &nbsp;logs/nginx.pid;&nbsp;\u003Cbr>worker_rlimit_nofile &nbsp; &nbsp;65536;&nbsp;\u003Cbr>events&nbsp;\u003Cbr>{&nbsp;\u003Cbr>use epoll;&nbsp;\u003Cbr>accept_mutex off;&nbsp;\u003Cbr>worker_connections &nbsp;65536;&nbsp;\u003Cbr>}\u003C/blockquote>\u003Cblockquote>http&nbsp;\u003Cbr>{&nbsp;\u003Cbr>include &nbsp; &nbsp; &nbsp; mime.types;&nbsp;\u003Cbr>default_type &nbsp;text/html;&nbsp;\u003Cbr>charset UTF-8;&nbsp;\u003Cbr>server_names_hash_bucket_size &nbsp; 128;&nbsp;\u003Cbr>client_header_buffer_size &nbsp; &nbsp; &nbsp; 4k;&nbsp;\u003Cbr>large_client_header_buffers &nbsp;4 32k;&nbsp;\u003Cbr>client_max_body_size &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;8m;&nbsp;\u003Cbr>open_file_cache max=65536 &nbsp;inactive=60s;&nbsp;\u003Cbr>open_file_cache_valid &nbsp; &nbsp; &nbsp;80s;&nbsp;\u003Cbr>open_file_cache_min_uses &nbsp; 1;&nbsp;\u003Cbr>log_format &nbsp;main &nbsp;'$remote_addr - $remote_user [$time_local] \"$request\" '&nbsp;\u003Cbr>'$status $body_bytes_sent \"$http_referer\" '&nbsp;\u003Cbr>'\"$http_user_agent\" \"$http_x_forwarded_for\"';&nbsp;\u003Cbr>access_log &nbsp;logs/access.log &nbsp;main;&nbsp;\u003Cbr>sendfile &nbsp; &nbsp;on;&nbsp;\u003Cbr>server_tokens off;&nbsp;\u003Cbr>fastcgi_temp_path &nbsp;/tmp/fastcgi_temp;&nbsp;\u003Cbr>fastcgi_cache_path /tmp/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:128m inactive=30m max_size=1g;\u003C/blockquote>\u003Cblockquote>fastcgi_cache_key &nbsp;$host$request_uri;&nbsp;\u003Cbr>fastcgi_cache_valid 200 302 1h;&nbsp;\u003Cbr>fastcgi_cache_valid 301 &nbsp; &nbsp; 1d;&nbsp;\u003Cbr>fastcgi_cache_valid any &nbsp; &nbsp; 1m;&nbsp;\u003Cbr>fastcgi_cache_min_uses 1;&nbsp;\u003Cbr>fastcgi_cache_use_stale error timeout http_500 http_503 invalid_header;&nbsp;\u003Cbr>keepalive_timeout &nbsp;60;&nbsp;\u003Cbr>gzip &nbsp;on;&nbsp;\u003Cbr>gzip_min_length 1k;&nbsp;\u003Cbr>gzip_buffers &nbsp;4 &nbsp; 64k;&nbsp;\u003Cbr>gzip_http_version &nbsp; 1.1;&nbsp;\u003Cbr>gzip_comp_level 2;&nbsp;\u003Cbr>gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript;&nbsp;\u003Cbr>server&nbsp;\u003Cbr>{&nbsp;\u003Cbr>listen &nbsp; &nbsp; &nbsp; 80;&nbsp;\u003Cbr>server_name &nbsp;localhost;&nbsp;\u003Cbr>index &nbsp; &nbsp; &nbsp; &nbsp;index.html;&nbsp;\u003Cbr>root &nbsp; &nbsp; &nbsp; &nbsp; /App/web;&nbsp;\u003Cbr>location ~ .+\\.(php|php5)$&nbsp;\u003Cbr>{&nbsp;\u003Cbr>fastcgi_pass &nbsp; unix:/tmp/php.sock;&nbsp;\u003Cbr>fastcgi_index &nbsp;index.php;&nbsp;\u003Cbr>include &nbsp; &nbsp; &nbsp; &nbsp;fastcgi.conf;&nbsp;\u003Cbr>fastcgi_cache &nbsp;cache_fastcgi;&nbsp;\u003Cbr>}\u003C/blockquote>\u003Cblockquote>location ~ .+\\.(gif|jpg|jpeg|png|bmp|swf|txt|csv|doc|docx|xls|xlsx|ppt|pptx|flv)$&nbsp;\u003Cbr>{&nbsp;\u003Cbr>expires 30d;&nbsp;\u003Cbr>}\u003C/blockquote>\u003Cblockquote>location ~ .+\\.(js|css|html|xml)$&nbsp;\u003Cbr>{&nbsp;\u003Cbr>expires 30d;&nbsp;\u003Cbr>}\u003C/blockquote>\u003Cblockquote>location /nginx-status&nbsp;\u003Cbr>{&nbsp;\u003Cbr>stub_status on;&nbsp;\u003Cbr>allow 192.168.1.0/24;&nbsp;\u003Cbr>allow 127.0.0.1;&nbsp;\u003Cbr>deny all;&nbsp;\u003Cbr>}\u003C/blockquote>\u003Cblockquote>}\u003C/blockquote>\u003Cblockquote>}\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>三. &nbsp; &nbsp; &nbsp; &nbsp;内核\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Chr>\u003Cp>\u003Cspan>Linux内核参数部分默认值不适合高并发，一般临时方法可以通过调整/Proc文件系统，或者直接修改/etc/sysctl.conf配置文件永久保存。调整/Proc文件系统，系统重启后还原至默认值，所以不推荐。Linux内核调优，主要涉及到网络和文件系统、内存等的优化，下面是我常用的内核调优配置：\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Cblockquote>grep -q \"net.ipv4.tcp_max_tw_buckets\" /etc/sysctl.conf || cat &gt;&gt; /etc/sysctl.conf &lt;&lt; EOF&nbsp;\u003Cbr>########################################&nbsp;\u003Cbr>net.core.rmem_default = 262144&nbsp;\u003Cbr>net.core.rmem_max = 16777216&nbsp;\u003Cbr>net.core.wmem_default = 262144&nbsp;\u003Cbr>net.core.wmem_max = 16777216&nbsp;\u003Cbr>net.core.somaxconn = 262144&nbsp;\u003Cbr>net.core.netdev_max_backlog = 262144&nbsp;\u003Cbr>net.ipv4.tcp_max_orphans = 262144&nbsp;\u003Cbr>net.ipv4.tcp_max_syn_backlog = 262144&nbsp;\u003Cbr>net.ipv4.tcp_max_tw_buckets = 10000&nbsp;\u003Cbr>net.ipv4.ip_local_port_range = 1024 65500&nbsp;\u003Cbr>net.ipv4.tcp_tw_recycle = 1&nbsp;\u003Cbr>net.ipv4.tcp_tw_reuse = 1&nbsp;\u003Cbr>net.ipv4.tcp_syncookies = 1&nbsp;\u003Cbr>net.ipv4.tcp_synack_retries = 1&nbsp;\u003Cbr>net.ipv4.tcp_syn_retries = 1&nbsp;\u003Cbr>net.ipv4.tcp_fin_timeout = 30&nbsp;\u003Cbr>net.ipv4.tcp_keepalive_time = 600&nbsp;\u003Cbr>net.ipv4.tcp_keepalive_intvl = 30&nbsp;\u003Cbr>net.ipv4.tcp_keepalive_probes = 3&nbsp;\u003Cbr>net.ipv4.tcp_mem = 786432 1048576 1572864&nbsp;\u003Cbr>fs.aio-max-nr = 1048576&nbsp;\u003Cbr>fs.file-max = 6815744&nbsp;\u003Cbr>kernel.sem = 250 32000 100 128&nbsp;\u003Cbr>vm.swappiness = 10&nbsp;\u003Cbr>EOF&nbsp;\u003Cbr>sysctl -p\u003C/blockquote>\u003Cp>\u003Cspan>\u003Cb>四.架构\u003C/b>\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003C/p>\u003Chr>\u003Cp>\u003Cspan>Nginx的最大优势在于处理静态文件和代理转发功能，支持7层负载均衡和故障隔离。 动静分离是每个网站发展到一定规模之后必然的结果。静态请求则应当最好将其拆分，并启用独立的域名，既便于管理的需要，也便于今后能够快速支持CDN。如果一台Nginx性能无法满足，则可以考虑在Nginx前端添加LVS负载均衡，或者F5等硬件负载均衡（费用昂贵，适合土豪公司单位），由多台Nginx共同分担网站请求。还可以考虑结合Varnish或者Squid缓存静态文件实现类似CDN功能。\u003C/span>\u003Cspan>&nbsp;\u003C/span>\u003Cbr>\u003Cspan>新版Nginx目前已经支持直接读写Memcache，可以编译安装时候选择添加此类模块，从而节省了转交给PHP或者JPS等动态程序服务器处理时间，提高效率的同时，减小了动态服务器的负载。\u003C/span>\u003C/p>","Nginx(读音engine x)服务器由于性能优秀稳定、配置简单以及跨平台，被越来越多的公司和个人所采用，现已成为市场份额继Apache之后的第二大Web服务器。各大小网站论坛博客也介绍说明了Nginx从安装到优化的各种配置。\n\n \n\n不过看了很多这些相关Nginx的文档之后，发现一个比较大的问题，就是这些文档基本也就从两个方面着手，一是修改Nginx的配置文件，二是调整操作系统的相关内核参数；而且文档说明也不够明了，缺乏比较系统级别的优化。\n\n \n\n本文将从Nginx源码编译安装开始，到修改配置文件，调整系统内核参数以及架构四个方面着手分别介绍如何优化。\n\n \n\n**一.     安装**\n\n \n\n---\n\n> (1)  精简模块\n\nNginx由于不断添加新的功能，附带的模块也越来越多。很多操作系统厂商为了用户方便安装管理，都增加了rpm、deb或者其他自有格式软件包，可以本地甚至在线安装。不过我不太建议使用这种安装方式。这虽然简化了安装，在线安装甚至可以自动解决软件依赖关系，但是安装后软件的文件布局过于分散，不便管理维护；同时也正是由于存在软件包之间的依赖关系，导致当有安全漏洞、或者其它问题，想要通过更新升级Nginx新版本时却发现yum、deb源还未发布新版本(一般都落后于官网发布的软件版本)。最重要的是采用非源码编译安装的方式，默认会添加入许多模块，比如邮件相关、uwsgi、memcache等等，很多网站运行时这些模块根本未用到，虽然平时占用的资源很小，但是仍然可能是压弯骆驼的一根稻草。各种非必需模块默认安装运行的同时，也给Web系统带来了安全隐患。尽量保持软件的轻装上阵，是每个运维应当尽力做到的，所以我建议一般常用的服务器软件使用源码编译安装管理。。我一般使用的编译参数如下，PHP相关模块fastcgi被保留用作后文优化说明，：\n\n \n\n> ./configure \\ \"--prefix=/App/nginx\" \\ \"--with-http_stub_status_module\" \\ \"--without-http_auth_basic_module\" \\ \"--without-http_autoindex_module\" \\ \"--without-http_browser_module\" \\ \"--without-http_empty_gif_module\" \\ \"--without-http_geo_module\" \\ \"--without-http_limit_conn_module\" \\ \"--without-http_limit_req_module\" \\ \"--without-http_map_module\" \\ \"--without-http_memcached_module\" \\ \"--without-http_proxy_module\" \\ \"--without-http_referer_module\" \\ \"--without-http_scgi_module\" \\ \"--without-http_split_clients_module\" \\ \"--without-http_ssi_module\" \\ \"--without-http_upstream_ip_hash_module\" \\ \"--without-http_upstream_keepalive_module\" \\ \"--without-http_upstream_least_conn_module\" \\ \"--without-http_userid_module\" \\ \"--without-http_uwsgi_module\" \\ \"--without-mail_imap_module\" \\ \"--without-mail_pop3_module\" \\ \"--without-mail_smtp_module\" \\ \"--without-poll_module\" \\ \"--without-select_module\" \\ \"--with-cc-opt='-O2'\"\n\n编译参数根据网站是否真正用到的原则增添或者减少，比如我们公司如果需要用到ssi模块,从而能够实现访问shtml页面，可以将第17行删除，那么Nginx将默认安装。大家可以通过运行 \"./configure --help\" 查看编译帮助，决定是否需要安装哪些模块。\n\n \n\n> (2)  GCC编译参数优化 [可选项】\n\nGCC总共提供了5级编译优化级别：\n\n \n\n**-O0:**无优化。\n\n \n\n**-O和-O1:**使用能减少目标代码尺寸以及执行时间并且不会使编译时间明显增加的优化。在编译大型程序的时候会显著增加编译时内存的使用。\n\n \n\n**-O2:**包含-O1的优化并增加了不需要在目标文件大小和执行速度上进行折衷的优化。编译器不执行循环展开以及函数内联。此选项将增加编译时间和目标文件的执行性能。\n\n \n\n**-Os:**可以看成 -O2.5，专门优化目标文件大小，执行所有的不增加目标文件大小的-O2优化选项，并且执行专门减小目标文件大小的优化选项。适用于磁盘空间紧张时使用。但有可能有未知的问题发生，况且目前硬盘容量很大，常用程序无必要使用。\n\n \n\n**-O3:**打开所有 -O2 的优化选项外增加 -finline-functions、-funswitch-loops、-fgcse-after-reload 优化选项。相对于 -O2 性能并未有较多提高，编译时间也最长，生成的目标文件也更大更占内存，有时性能不增反而降低，甚至产生不可预知的问题(包括错误)，所以并不被大多数软件安装推荐，除非有绝对把握方可使用此优化级别。\n\n \n\n修改GCC编译参数，提高编译优化级别，此方法适用于所有通过GCC编译安装的程序，不止Nginx。稳妥起见用 -O2，这也是大多数软件编译推荐的优化级别。查看Nginx源码文件 auto/cc/gcc，搜索NGX_GCC_OPT，默认GCC编译参数为-O，可以直接修改内容为NGX_GCC_OPT=\"-O2\"或者在 ./configure配置时添加--with-cc-opt='-O2'选项。\n\n \n\n**二.      配置**\n\n \n\n---\n\n应用服务器的性能优化主要在合理使用CPU、内存、磁盘IO和网络IO四个方面，现在我们从Nginx配置文件 nginx.conf 入手进行优化：\n\n \n\n> (1)  工作进程数的选择\n\n**指令：worker_processes**\n\n \n\n定义了Nginx对外提供web服务时的工作进程数。最优值取决于许多因素，包括（但不限于）CPU核心的数量、存储数据的硬盘数量及负载模式。不能确定的时候，将其设置为可用的CPU内核数将是一个好的开始（设置为“auto”将尝试自动检测它）。Shell执行命令  ps ax | grep \"nginx: worker process\" | grep -v \"grep\" 可以看到运行中的Nginx工作进程数，一般建议设置成服务器逻辑核心数，Shell执行命令 cat /proc/cpuinfo | grep processor | wc -l 可以检测出服务器逻辑核心总数，偷懒可以直接写auto，Nginx自适应。\n\n \n\n> (2)  是否绑定CPU\n\n**指令**：worker_cpu_affinity\n\n \n\n绑定工作进程到对应CPU核心，Nginx默认未开启CPU绑定。目前的服务器一般为多核CPU，当并发很大时，服务器各个CPU的使用率可能出现严重不均衡的局面，这时候可以考虑使用CPU绑定，以达到CPU使用率相对均匀的状态，充分发挥多核CPU的优势。top、htop等程序可以查看所有CPU核心的使用率状况。绑定样例：\n\n \n\nworker_processes    4;\n\n \n\nworker_cpu_affinity 0001 0010 0100 1000;\n\n \n\n> (3)  打开文件数限制\n\n**指令**：worker_rlimit_nofile\n\n \n\n设定了每个Nginx工作进程打开的最大文件数，受限于系统的用户进程打开文件数限制，未设置则使用系统默认值。理论上应该设置为当前Shell启动进程的最大打开文件数除以Nginx的工作进程数。由于Nginx的工作进程打开文件数并不一完全均匀，所以可以将其设置成Shell启动进程的最大打开文件数。Shell执行命令 ulimit -n 可以查看当前登录Shell会话最大打开文件数数限制。Linux系统用户进程默认同时打开文件最大数为1024，这个值太小，访问量稍大就报“too many open files\"。Shell执行命令先修改用户打开文件数限制：\n\n \n\necho \"* - nofile 65536\" >> /etc/security/limits.conf\n\n \n\n然后添加入/etc/profile如下两行内容，修改所有Shell和通过Shell启动的进程打开文件数限制：\n\n \n\necho \"ulimit -n 65536\" >> /etc/profile\n\n \n\nShell执行命令使当前Shell临时会话立即生效：\n\n \n\nulimit -n 65536\n\n \n\n> (4) 惊群问题\n\n**指令**：accept_mutex\n\n \n\n如果 accept_mutex 指令值为 on 启用，那么将轮流唤醒一个工作进程接收处理新的连接，其余工作进程继续保持睡眠；如果值为 off 关闭，那么将唤醒所有工作进程，由系统通过use指令指定的网络IO模型调度决定由哪个工作进程处理，未接收到连接请求的工作进程继续保持睡眠，这就是所谓的“惊群问题”。Web服务器Apache的进程数很多，成百上千也是时有的事，“惊群问题”也尤为明显。Nginx为了稳定，参数值保守的设置为 on 开启状态。可以将其设置成Off 提高性能和吞吐量，但这样也会带来上下文切换增多或者负载升高等等其它资源更多消耗的后果。\n\n \n\n> (5)  网络IO模型\n\n**指令**：use\n\n \n\n定义了Nginx设置用于复用客户端线程的轮询方法(也可称多路复用网络IO模型)。这自然是选择效率更高的优先，Linux 2.6+内核推荐使用epoll，FreeBSD推荐使用kqueue，安装时Nginx会自动选择。\n\n \n\n> (6)  连接数\n\n**指令**：worker_connections\n\n \n\n定义了Nginx一个工作进程的最大同时连接数，不仅限于客户端连接，包括了和后端被代理服务器等其他的连接。官网文档还指出了该参数值不能超过 worker_rlimit_nofile 值，所以建议设置成和 worker_rlimit_nofile 值相等。\n\n \n\n> (7)  打开文件缓存\n\n**指令**：open_file_cache\n\n \n\n开启关闭打开文件缓存，默认值 off 关闭，强烈建议开启，可以避免重新打开同一文件带来的系统开销，节省响应时间。如需开启必须后接参数 max=数字，设置缓存元素的最大数量。当缓存溢出时，使用LRU(最近最少使用)算法删除缓存中的元素；可选参数 inactive=时间 设置超时，在这段时间内缓存元素如果没有被访问，将从缓存中删除。示例：open_file_cache max=65536  inactive=60s。\n\n \n\n**指令**：open_file_cache_valid\n\n \n\n设置检查open_file_cache缓存的元素的时间间隔。\n\n \n\n**指令**：open_file_cache_min_uses\n\n \n\n设置在由open_file_cache指令的inactive参数配置的超时时间内， 文件应该被访问的最小次数。如果访问次数大于等于此值，文件描述符会保留在缓存中，否则从缓存中删除。\n\n \n\n> (8)  日志相关\n\n**指令**：access_log 和 error_log\n\n \n\n当并发很大时，Nginx的访问日志和错误日志的保存肯定会造成对磁盘的大量读写，也将影响Nginx的性能。并发量越大，IO越高。这时候可以考虑关闭访问日志和错误日志，或者将日志保存到tmpfs文件系统里，或者减少保存的访问日志条目和错误日志的级别，从而避免磁盘IO的影响。关闭日志使用 access_log**off。如必须保存日志，可以按每日或者每时或者其它时间段对日志做切割，这也可以减小IO，虽然可能效果不是特别大，不过因为日志文件尺寸变小了很多，也方便查阅或归档分析日志。一般线上环境建议错误日志设置为 error 或者 crit。自定义访问日志的条目和错误日志的级别，详细信息可以参阅官网或者网上其它文档，按需修改。**\n\n \n\n> (9)  隐藏Nginx版本号\n\n**指令**：server_tokens\n\n \n\n开启或关闭“Server”响应头中输出的Nginx版本号。推介设置为 off，关闭显示响应头的版本号，对性能的提高有小小的裨益，主要还是为了安全起见，不被骇客找到版本号对应的漏洞，从而被攻击。\n\n \n\n> (10) 压缩相关\n\n**指令**：gzip\n\n \n\nNginx默认开启了gzip压缩功能。有可能很多人认为，开启gzip压缩会增加CPU的处理时间和负载。但是经过我们网站的测试发现，关闭了gzip压缩功能的Nginx虽然减少了CPU计算，节省了服务器的响应时间，但网站页面总体响应时间反而加长了，原因在于js和css、xml、json、html等等这些静态文件的数据传输时间的增长大大超过了服务器节省出来的响应时间，得不偿失。gzip on 开启压缩后，大约可以减少75%的文件尺寸，不但节省了比较多的带宽流量，也提高了页面的整体响应时间。所有建议还是开启。当然也不是所有的静态文件都需要压缩，比如静态图片和PDF、视频，文件本身就应当做压缩处理后保存到服务器。这些文件再次使用gzip压缩，压缩的比例并不高，甚至适得其反，压缩后文件尺寸增大了。CPU压缩处理这些静态文件增加占用的服务器响应时间绝大部分时候会超过了被压缩减小的文件尺寸减少的数据传输时间，不划算。是否需要对Web网站开启压缩，以及对哪些文件过滤压缩，大家可以通过使用HttpWatch、Firebug等等网络分析工具对比测试。\n\n \n\n**指令**：**gzip_comp_level**\n\n \n\n指定压缩等级，其值从1到9，数字越大，压缩率越高，越消耗CPU，负载也越高。9等级无疑压缩率最高，压缩后的文件尺寸也最小，但也是最耗CPU资源，负载最高，速度最慢的，这对于用户访问有时是无法忍受的。一般推荐使用1-4等级，比较折衷的方案。我们公司网站使用等级2。\n\n \n\n**指令**：**gzip_min_length**\n\n \n\n指定压缩的文件最小尺寸，单位 bytes 字节，低于该值的不压缩，超过该值的将被压缩。我们网站设置为1k，太小的文件没必要压缩，压缩过小尺寸文件带来增加的CPU消耗时间和压缩减少的文件尺寸降低的数据下载时间互相抵消，并有可能增加总体的响应时间。\n\n \n\n**指令**：gzip_types\n\n \n\n指定允许压缩的文件类型，Nginx配置目录 conf 下的 mime.types 文件存放了Nginx支持的文件类型，text/html类型文件，文件后缀为html htm shtml默认压缩。推荐配置：gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript。\n\n \n\n> (11) 浏览器缓存\n\n**指令**：expires\n\n \n\n设置HTTP应答中的“Expires”和“Cache-Control”头标。\"Expires\"一般结合\"Last-Modified\"使用。当设置了合理的expires配置时，浏览器第一次访问Web页面元素，会下载页面中的的静态文件到本机临时缓存目录下。第二次及之后再次访问相同URL时将发送带头标识\"If-Modified-Since\"和本地缓存文件时间属性值的请求给服务器，服务器比对服务器本地文件时间属性值，如果未修改，服务器直接返回http 304状态码，浏览器直接调用本地已缓存的文件；如果时间属性值修改了，重新发送新文件。这样就避免了从服务器再次传送文件内容，减小了服务器压力，节省了带宽，同时也提高了用户访问速度，一举三得。指令后接数字加时间单位，即为缓存过期时间；-1 表示永远过期，不缓存。强烈建议添加expires配置，过期时间的选择具体分析。我们公司的部分Nginx配置如下：\n\n \n\nlocation ~ .+\\.(gif|jpg|jpeg|png|bmp|swf)$\n\n \n\n{\n\n \n\nexpires 30d;\n\n \n\n}\n\n \n\nlocation ~ .+\\.(js|css|xml|javascript|txt|csv)$\n\n \n\n{\n\n \n\nexpires 30d;\n\n \n\n}\n\n \n\n或者统一将静态文件放在固定目录下再对目录做location和expires，示例：\n\n \n\nlocation /static/\n\n \n\n{\n\n \n\nexpires 30d;\n\n \n\n}\n\n \n\n> (12) 持久连接\n\n指令：keepalive_timeout\n\n \n\n启用Http的持久连接Keepalive属性，复用之前已建立的TCP连接接收请求、发送回应，减少重新建立TCP连接的资源时间开销。在此的建议是当网站页面内容以静态为主时，开启持久连接；若主要是动态网页，且不能被转化为静态页面，则关闭持久连接。后接数字和时间单位符号。正数为开启持久连接，0关闭。\n\n \n\n> (13) 减少HTTP请求次数\n\n网站页面中存在大量的图片、脚本、样式表、Flash等静态元素，减少访问请求次数最大的优点就是减少用户首次访问页面的加载时间。可以采用合并相同类型文件为一个文件的办法减少请求次数。这其实属于Web前端优化范畴，应当由Web前段工程师做好相关静态文件的规划管理，而不是由运维来做。不过Nginx也可以通过安装阿里巴巴提供的Concat或者Google的PageSpeed模块实现这个合并文件的功能。我们公司并未使用合并功能，具体安装配置信息请查询网上相关文档，这里不再累述。Concat源代码网址：[https://github.com/alibaba/nginx-http-concat/](https://github.com/alibaba/nginx-http-concat/)，PageSpeed源代码网址：[https://github.com/pagespeed/ngx_pagespeed](https://github.com/pagespeed/ngx_pagespeed)。\n\n \n\n> (14) PHP相关\n\nNginx不能直接解析PHP代码文件，需要调用FastCGI接口转给PHP解释器执行，然后将结果返回给Nginx。PHP优化本文暂不介绍。Nginx可以开启FastCGI的缓存功能，从而提高性能。\n\n \n\n**指令：fastcgi_temp_path**\n\n \n\n定义FastCGI缓存文件保存临时路径。\n\n \n\n**指令：fastcgi_cache_path**\n\n \n\n定义FastCGI缓存文件保存路径和缓存的其它参数。缓存数据以二进制数据文件形式存储，缓存文件名和key都是通过对访问URL使用MD5计算获得的结果。缓存文件先保存至fastcgi_temp_path指定的临时目录下，然后通过重命名操作移至fastcgi_cache_path指定的缓存目录。levels指定了目录结构,子目录数以16为基数；keys_zone指定了共享内存区名和大小，用于保存缓存key和数据信息；inactive指定了缓存数据保存的时间，当这段时间内未被访问，将被移出；max_size指定了缓存使用的最大磁盘空间，超过容量时将最近最少使用数据删除。建议fastcgi_temp_path和fastcgi_cache_path设为同一分区，同分区移动操作效率更高。示例：\n\n \n\nfastcgi_temp_path /tmp/fastcgi_temp;\n\n \n\nfastcgi_cache_path /tmp/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:16m inactive=30m max_size=1g;\n\n \n\n示例中使用/tmp/fastcgi_temp作为FastCGI缓存的临时目录；/tmp/fastcgi_cache作为FastCGI缓存保存的最终目录；一级子目录为16的一次方16个，二级子目录为16的2次方256个；共享内存区名为cache_fastcgi，占用内存128MB；缓存过期时间为30分钟；缓存数据保存于磁盘的最大空间大小为1GB。\n\n \n\n**指令：fastcgi_cache_key**\n\n \n\n定义FastCGI缓存关键字。启用FastCGI缓存必须加上这个配置，不然访问所有PHP的请求都为访问第一个PHP文件URL的结果。\n\n \n\n**指令：fastcgi_cache_valid**\n\n \n\n为指定的Http状态码指定缓存时间。\n\n \n\n**指令：fastcgi_cache_min_uses**\n\n \n\n指定经过多少次请求相同的URL将被缓存。\n\n \n\n**指令：fastcgi_cache_use_stale**\n\n \n\n指定当连接FastCGI服务器发生错误时，哪些情况使用过期数据回应。\n\n \n\n**指令：fastcgi_cache**\n\n \n\n缓存使用哪个共享内存区。\n\n \n\n我常用nginx.conf模板，大家根据情况做适当修改：\n\n \n\n> [plain]view plaincopy user  nginx nginx; worker_processes  auto; error_log  logs/error.log error; pid        logs/nginx.pid; worker_rlimit_nofile    65536; events { use epoll; accept_mutex off; worker_connections  65536; }\n\n> http { include       mime.types; default_type  text/html; charset UTF-8; server_names_hash_bucket_size   128; client_header_buffer_size       4k; large_client_header_buffers  4 32k; client_max_body_size            8m; open_file_cache max=65536  inactive=60s; open_file_cache_valid      80s; open_file_cache_min_uses   1; log_format  main  '$remote_addr - $remote_user [$time_local] \"$request\" ' '$status $body_bytes_sent \"$http_referer\" ' '\"$http_user_agent\" \"$http_x_forwarded_for\"'; access_log  logs/access.log  main; sendfile    on; server_tokens off; fastcgi_temp_path  /tmp/fastcgi_temp; fastcgi_cache_path /tmp/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:128m inactive=30m max_size=1g;\n\n> fastcgi_cache_key  $host$request_uri; fastcgi_cache_valid 200 302 1h; fastcgi_cache_valid 301     1d; fastcgi_cache_valid any     1m; fastcgi_cache_min_uses 1; fastcgi_cache_use_stale error timeout http_500 http_503 invalid_header; keepalive_timeout  60; gzip  on; gzip_min_length 1k; gzip_buffers  4   64k; gzip_http_version   1.1; gzip_comp_level 2; gzip_types text/plain text/css application/json application/x-javascript text/xml application/xml application/xml+rss text/javascript; server { listen       80; server_name  localhost; index        index.html; root         /App/web; location ~ .+\\.(php|php5)$ { fastcgi_pass   unix:/tmp/php.sock; fastcgi_index  index.php; include        fastcgi.conf; fastcgi_cache  cache_fastcgi; }\n\n> location ~ .+\\.(gif|jpg|jpeg|png|bmp|swf|txt|csv|doc|docx|xls|xlsx|ppt|pptx|flv)$ { expires 30d; }\n\n> location ~ .+\\.(js|css|html|xml)$ { expires 30d; }\n\n> location /nginx-status { stub_status on; allow 192.168.1.0/24; allow 127.0.0.1; deny all; }\n\n> }\n\n> }\n\n**三.        内核**\n\n \n\n---\n\nLinux内核参数部分默认值不适合高并发，一般临时方法可以通过调整/Proc文件系统，或者直接修改/etc/sysctl.conf配置文件永久保存。调整/Proc文件系统，系统重启后还原至默认值，所以不推荐。Linux内核调优，主要涉及到网络和文件系统、内存等的优化，下面是我常用的内核调优配置：\n\n \n\n> grep -q \"net.ipv4.tcp_max_tw_buckets\" /etc/sysctl.conf || cat >> /etc/sysctl.conf\n\n**四.架构**\n\n \n\n---\n\nNginx的最大优势在于处理静态文件和代理转发功能，支持7层负载均衡和故障隔离。 动静分离是每个网站发展到一定规模之后必然的结果。静态请求则应当最好将其拆分，并启用独立的域名，既便于管理的需要，也便于今后能够快速支持CDN。如果一台Nginx性能无法满足，则可以考虑在Nginx前端添加LVS负载均衡，或者F5等硬件负载均衡（费用昂贵，适合土豪公司单位），由多台Nginx共同分担网站请求。还可以考虑结合Varnish或者Squid缓存静态文件实现类似CDN功能。\n\n \n\n新版Nginx目前已经支持直接读写Memcache，可以编译安装时候选择添加此类模块，从而节省了转交给PHP或者JPS等动态程序服务器处理时间，提高效率的同时，减小了动态服务器的负载。","/article/25",4459,"2017-07-18 16:38:48","2018-10-18 17:35:35",[155,156,157],{"id":39,"name":81,"url":82},{"id":44,"name":23,"url":59},{"id":39,"name":145,"url":150},{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"title":160,"url":161},"在CentOS 7上安装phpPgAdmin ","/article/26",{"title":163,"url":164},"Linux VPS实用工具路由追踪测试","/article/24",[166,167,168,169],{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},{"description":147,"keywords":146,"title":145},[172,181,190,199,208,217,226,235,244,252],{"id":173,"category_id":44,"title":174,"keywords":175,"description":176,"image_url":6,"url":177,"hits":178,"is_recommend":73,"is_top":73,"create_time":179,"update_time":180},101,"开启 HTTPS 并获得 ssllabs 满分的过程","开启,获得,满分,过程","准备工作确保你要申请证书的域名都解析到了这台服务器上，且能直接通过域名访问。使用官网推荐的CertBot获取证书。在CertBot官网选择一下环境(比如我选Nginx on Ubuntu 17.04)就可以看到入门教程了。安装CertBot12345apt-get updateapt-get install software-properties-commonadd-apt-repository ppa:certbot/certbotapt-get updateapt-get","/article/101",18546,"2019-11-26 16:12:11","2019-11-26 16:23:16",{"id":182,"category_id":44,"title":183,"keywords":184,"description":185,"image_url":6,"url":186,"hits":187,"is_recommend":73,"is_top":73,"create_time":188,"update_time":189},113,"在CentOS 7中添加命令自动补全功能","命令自动补全,centos","在CentOS 7中，默认情况下并不会安装命令补全包，需要手动安装才能使用命令补全功能。以下是在CentOS 7中安装命令补全包的方法：1. bash-completion：这是一个针对Bash shell的命令补全软件包，可以提供对系统命令、用户自定义命令和文件路径的自动补全功能。可以通过以下命令安装：```sudo yum install bash-completion```安装完成后，需要在/etc/profile配置文件中添加以下内容：```if [ -f /etc/bash_compl","/article/113",14948,"2023-05-16 10:54:01","2023-05-16 10:57:28",{"id":191,"category_id":44,"title":192,"keywords":193,"description":194,"image_url":6,"url":195,"hits":196,"is_recommend":53,"is_top":73,"create_time":197,"update_time":198},94,"Centos7 安装 openvas ","openvas,开放式漏洞评估系统，installing openvas centos-7","一、描述OpenVAS，即开放式漏洞评估系统，是一个用于评估目标漏洞的杰出框架。功能十分强大，最重要的是，它是“开源”的——就是免费的意思啦～它与著名的Nessus“本是同根生”，在Nessus商业化之后仍然坚持开源，号称“当前最好用的开源漏洞扫描工具”。最新版的Kali Linux(kali 3.0)不再自带OpenVAS了，所以我们要自己部署OpenVAS漏洞检测系统。其核心部件是一个服务器，包括一套网络漏洞测试程序，可以检测远程系统和应用程序中的安全问题。但是它的最常用用途是检测目标网络或","/article/94",14690,"2019-01-14 17:43:42","2019-01-14 18:16:36",{"id":200,"category_id":44,"title":201,"keywords":202,"description":203,"image_url":6,"url":204,"hits":205,"is_recommend":73,"is_top":73,"create_time":206,"update_time":207},99,"Centos7 利用iptables防止nmap工具防端口扫描","iptables","一、Nmap介绍       Nmap（NetworkMapper）是一款开放源代码的网络探测和安全审核工具。它用于快速扫描一个网络和一台主机开放的端口，还能使用TCP/IP协议栈特征探测远程主机的操作系统类型。nmap支持很多扫描技术，例如：UDP、TCPconnect()、TCPSYN(半开扫描)、ftp代理(bounce攻击)、反向标志、ICMP、FIN、ACK扫描、圣诞树(XmasTree)、SYN扫描和null扫描。Nmap最初是用于Unix系统","/article/99",14415,"2019-07-09 21:27:00","2019-07-09 21:57:53",{"id":209,"category_id":46,"title":210,"keywords":211,"description":212,"image_url":6,"url":213,"hits":214,"is_recommend":73,"is_top":73,"create_time":215,"update_time":216},61,"Docker 推荐的启动方式","推荐,启动,方式","# cat DockerfileFROM openjdk:8-alpineWORKDIR /ADD ./target/*.jar app.jarEXPOSE 9999COPY docker-entrypoint.sh /RUN chmod +x /docker-entrypoint.shENTRYPOINT [“/docker-entrypoint.sh”]CMD [“java”,”-server”,”-Duser.timezone=GMT+08″,”-jar”,”/app.jar”]# cat","/article/61",14347,"2018-10-22 13:55:47","2018-10-22 13:56:10",{"id":218,"category_id":44,"title":219,"keywords":220,"description":221,"image_url":6,"url":222,"hits":223,"is_recommend":73,"is_top":73,"create_time":224,"update_time":225},107,"Acme.sh 给 SSL 证书自动续期失败的解决方法","HTTP/1.1 200 OK,Server: Bayou Tech Web Srv 1.0,Content-Encoding: none,Content-Length: 5,Content-Type","一、Acme.sh 自动续期失败的症状问题描述如下，续期的时候，提示如下错误：root@dc:~# \"/data/acme.sh\"/acme.sh --cron --home \"/data/acme.sh\" &gt; /dev/null[Sun Nov 10 23:52:17 CST 2020] Error, can not get domain token entry example.com[Sun Nov 10 23:52:17 CST 2020] Please check log file","/article/107",12618,"2021-09-03 10:44:18","2021-09-03 10:46:23",{"id":227,"category_id":44,"title":228,"keywords":229,"description":230,"image_url":6,"url":231,"hits":232,"is_recommend":53,"is_top":73,"create_time":233,"update_time":234},93,"ELK+Filebeat+Kafka+ZooKeeper 构建海量日志分析平台","Filebeat,Kafka","一、说明1.Filebeat是一个日志文件托运工具，在你的服务器上安装客户端后，filebeat会监控日志目录或者指定的日志文件，追踪读取这些文件（追踪文件的变化，不停的读）2.Kafka是一种高吞吐量的分布式发布订阅消息系统，它可以处理消费者规模的网站中的所有动作流数据3.Logstash是一根具备实时数据传输能力的管道，负责将数据信息从管道的输入端传输到管道的输出端；与此同时这根管道还可以让你根据自己的需求在中间加上滤网，Logstash提供里很多功能强大的滤网以满足你的各种应用场景4.El","/article/93",12190,"2018-12-24 16:40:08","2018-12-26 11:53:38",{"id":236,"category_id":46,"title":237,"keywords":238,"description":239,"image_url":6,"url":240,"hits":241,"is_recommend":53,"is_top":73,"create_time":242,"update_time":243},81,"kubernetes 1.12.1 高可用安装之部署Dashboard","安装Dashboard","创建Dashboard需要CoreDNS部署成功之后再安装Dashboard。[root@master01 ~]# wget https://zhl123.com/download/k8s/Dashboard.tgz[root@master01 ~]# tar xf Dashboard.tgz[root@master01 ~]# kubectl create -f Dashboard/[root@master01 Dashboard]# kubectl get svc -n kube-syste","/article/81",12037,"2018-10-26 09:54:41","2018-10-26 16:59:19",{"id":245,"category_id":44,"title":246,"keywords":6,"description":247,"image_url":6,"url":248,"hits":249,"is_recommend":73,"is_top":73,"create_time":250,"update_time":251},100,"用 Nginx 给 Cookie 增加 Secure 和 HttpOnly","在 nginx 的 location 中配置12# 只支持 proxy 模式下设置，SameSite 不需要可删除，如果想更安全可以把 SameSite 设置为 Strictproxy_cookie_path / \"/; httponly; secure; SameSite=Lax\";示例1234567891011121314151617181920212223242526server {    listen 443 ssl http2;    server_name www.zhl123.cn","/article/100",11848,"2019-11-26 16:10:57","2019-11-26 16:23:45",{"id":253,"category_id":44,"title":254,"keywords":255,"description":256,"image_url":6,"url":257,"hits":258,"is_recommend":73,"is_top":73,"create_time":259,"update_time":260},41,"Tomcat 安全配置与性能优化","tomcat，性能优化","1. JVM&nbsp;1.1. 使用 Server JRE 替代JDK。&nbsp;服务器上不要安装JDK，请使用 Server JRE. 服务器上根本不需要编译器，代码应该在Release服务器上完成编译打包工作。&nbsp;理由：一旦服务器被控制，可以防止在其服务器上编译其他恶意代码并植入到你的程序中。&nbsp;1.2. JAVA_OPTS&nbsp;export JAVA_OPTS=\"-server -Xms512m -Xmx4096m &nbsp;-XX:PermSize=64M -","/article/41",11623,"2016-09-01 17:06:36","2018-10-18 17:06:58",[262,270,278,286,294,302,310,318,327,336],{"id":263,"category_id":40,"title":264,"keywords":6,"description":265,"image_url":6,"url":266,"hits":267,"is_recommend":73,"is_top":73,"create_time":268,"update_time":269},123,"Agent Skill 精选集：最值得收藏的 Agent Skills Top 10","如果你正在用 Claude Code 或 Codex，一定对&nbsp;Agent Skills&nbsp;不陌生。通过安装&nbsp;Agent Skills，你可以让这些 AI 助手变得更强——不用每次都解释你的需求，它们直接就知道该怎么做。最近有人在 GitHub 上做了一个采样调查，统计了哪些 Skills 的质量最佳和最受欢迎。我整理了这份&nbsp;Top 10 榜单，加上使用场景和适合人群，帮你快速找到最有用的那几个。Top 10 最受欢迎的 Agent Skills1. Skil","/article/123",270,"2026-01-19 18:49:12","2026-01-19 18:52:01",{"id":271,"category_id":44,"title":272,"keywords":6,"description":273,"image_url":6,"url":274,"hits":275,"is_recommend":73,"is_top":73,"create_time":276,"update_time":277},122,"Nginx性能调优18条黄金法则：支撑10万并发的配置模板","一、概述1.1 背景介绍说实话，Nginx调优这事儿我踩过无数坑。记得2019年双11，我们电商平台流量暴涨，Nginx直接扛不住了，QPS从平时的2万飙升到8万，响应时间从50ms飙到了2秒，最后还是靠临时加机器扛过去的。那次事故之后，我花了大半年时间专门研究Nginx的性能极限，总结出了这20条黄金法则。Nginx作为目前最流行的Web服务器和反向代理，官方数据显示单机可以轻松处理10万+的并发连接。但实际生产环境中，很多同学拿到默认配置就直接上了，结果发现连1万并发都扛不住。问题不在Ngi","/article/122",337,"2026-01-12 11:11:50","2026-01-12 11:12:28",{"id":279,"category_id":46,"title":280,"keywords":6,"description":281,"image_url":6,"url":282,"hits":283,"is_recommend":73,"is_top":73,"create_time":284,"update_time":285},121,"Docker 镜像优化与安全扫描：将镜像体积压缩 70%","1. 适用场景 & 前置条件项目要求适用场景容器化应用镜像体积过大（> 500MB），构建时间长（> 10分钟），存在安全漏洞（CVE高危）OSRHEL/CentOS 7.9+ 或 Ubuntu 20.04+内核Linux Kernel 3.10+软件版本Docker 20.10+ 或 Podman 3.0+，Trivy 0.40+（安全扫描工具）资源规格2C4G（最小）/ 4C8G（推荐），磁盘 50GB+（存储镜像与缓存）网络可访问 Docker Hub/阿里云镜像仓库（","/article/121",309,"2026-01-06 11:54:35","2026-01-06 12:01:59",{"id":287,"category_id":44,"title":288,"keywords":6,"description":289,"image_url":6,"url":290,"hits":291,"is_recommend":73,"is_top":73,"create_time":292,"update_time":293},120,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(二)","五、故障排查和监控5.1 故障排查◆ 5.1.1 日志查看# 查看 Prometheus 日志中的规则评估错误journalctl -u prometheus | grep -i&nbsp;\"rule\"&nbsp;|&nbsp;tail&nbsp;-50# 查看规则评估耗时curl -s http://localhost:9090/api/v1/rules | jq&nbsp;'.data.groups[].rules[] | select(.health != \"ok\")'# Kubernet","/article/120",282,"2026-01-06 11:53:50","2026-01-06 11:54:33",{"id":295,"category_id":44,"title":296,"keywords":6,"description":297,"image_url":6,"url":298,"hits":299,"is_recommend":73,"is_top":73,"create_time":300,"update_time":301},119,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(一)","一、概述1.1 背景介绍在大规模微服务架构下，Prometheus 告警系统往往会陷入一个尴尬的境地：告警太多，运维团队开始选择性忽略；告警太少，真正的故障又可能漏掉。我在某电商平台负责监控体系建设时，团队每天要处理超过 2000 条告警，其中 70% 以上是重复的、关联的或者短暂抖动产生的噪声。Recording Rules 是 Prometheus 提供的预计算机制，可以将复杂的查询表达式预先计算并存储为新的时间序列。通过合理设计 Recording Rules，我们不仅能显著降低 Prom","/article/119",301,"2026-01-06 11:51:58","2026-01-06 11:53:45",{"id":303,"category_id":44,"title":304,"keywords":6,"description":305,"image_url":6,"url":306,"hits":307,"is_recommend":73,"is_top":73,"create_time":308,"update_time":309},118,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(二)","四、最佳实践和注意事项4.1 最佳实践4.1.1 性能优化优化点一：减少 Git 轮询频率# argocd-cm ConfigMapapiVersion:&nbsp;v1kind:&nbsp;ConfigMapmetadata:&nbsp;&nbsp;name:&nbsp;argocd-cm&nbsp;&nbsp;namespace:&nbsp;argocddata:&nbsp;&nbsp;timeout.reconciliation:&nbsp;300s&nbsp;&nbsp;# 默认 180","/article/118",305,"2026-01-06 11:49:00","2026-01-06 11:49:34",{"id":311,"category_id":44,"title":312,"keywords":6,"description":313,"image_url":6,"url":314,"hits":315,"is_recommend":73,"is_top":73,"create_time":316,"update_time":317},117,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(一)","一、概述1.1 背景介绍GitOps 作为云原生时代的运维范式，将 Git 作为基础设施和应用配置的单一事实来源，通过声明式配置和自动化同步机制，实现了配置管理的版本控制、审计追溯和快速回滚。ArgoCD 作为 CNCF 毕业项目，提供了完整的 GitOps 工作流，支持多集群管理、RBAC 权限控制、SSO 集成等企业级特性。结合 Kustomize 的配置管理能力，能够优雅地解决多环境配置差异、敏感信息管理、配置复用等问题。在传统的 CI/CD 流程中，往往由 CI 工具直接执行 kubec","/article/117",310,"2026-01-06 11:45:03","2026-01-06 11:48:56",{"id":319,"category_id":40,"title":320,"keywords":321,"description":322,"image_url":6,"url":323,"hits":324,"is_recommend":73,"is_top":73,"create_time":325,"update_time":326},116,"运维部门年度2025工作总结与2026工作规划应该如何写？","运维部门年度2025工作总结,2026工作规划","2025年，运维部在公司“数字化转型深化”战略引领下，以“稳定为基、效率为纲、安全为盾、创新为翼”为核心导向，全面支撑核心业务系统运行、推动技术架构迭代、强化团队能力建设。 全年实现核心业务系统可用性99.985%，较2024年提升0.02个百分点；故障平均恢复时间（MTTR）从42分钟压缩至29分钟，下降31%；云资源成本同比降低16.8%，自动化运维覆盖率从65%提升至83%，未发生重大生产安全事故，圆满完成年度目标。现将全年工作及2026年规划汇报如下：2025年核心工作成果（数","/article/116",297,"2026-01-06 11:20:58","2026-01-06 11:44:04",{"id":328,"category_id":40,"title":329,"keywords":330,"description":331,"image_url":6,"url":332,"hits":333,"is_recommend":73,"is_top":73,"create_time":334,"update_time":335},115,"Kubernetes 100个常用命令","100 个 Kubectl 命令","这篇文章是关于使用 Kubectl 进行 Kubernetes 诊断的指南。列出了 100 个 Kubectl 命令，这些命令对于诊断 Kubernetes 集群中的问题非常有用。这些问题包括但不限于：•&nbsp;集群信息•&nbsp;Pod 诊断•&nbsp;服务诊断•&nbsp;部署诊断•&nbsp;网络诊断•&nbsp;持久卷和持久卷声明诊断•&nbsp;资源使用情况•&nbsp;安全和授权•&nbsp;节点故障排除•&nbsp;其他诊断命令：文章还提到了许多其他命令，如资源扩展和自动扩","/article/115",3642,"2023-11-02 14:09:30","2023-11-02 14:10:05",{"id":182,"category_id":44,"title":183,"keywords":184,"description":185,"image_url":6,"url":186,"hits":187,"is_recommend":73,"is_top":73,"create_time":188,"update_time":189},1784716029472]