[{"data":1,"prerenderedAt":333},["ShallowReactive",2],{"site-data":3,"article-89":143,"article-show-hot-89":167,"article-show-new-89":257},{"settings":4,"categorys":35,"tree":97,"models":118,"search_model_select":128,"nav_list":130},{"changefreq":5,"changyan_app_id":6,"changyan_app_key":6,"copy":7,"description":8,"editor":9,"file":6,"guest_feedback":10,"head_html":6,"icp":11,"index_banner":12,"index_banner_bg":13,"is_excel":14,"is_watermark":10,"keywords":15,"links":16,"logo":17,"lzcms_banner":6,"lzcms_banner_link":18,"member_register_enabled":14,"qq_app_id":6,"qq_app_key":6,"qr_code":6,"search_model":19,"site_closedreason":6,"site_idea":6,"site_idea1":20,"site_idea2":21,"site_idea3":22,"site_name":23,"site_statistice":6,"site_status":14,"site_url":18,"sitemap_model":19,"stationmaster_motto":24,"stationmaster_name":25,"stationmaster_occupation":26,"stationmaster_qq":27,"stationmaster_qqnet":28,"stationmaster_qqnet_code":29,"threshold":14,"title_add":30,"watermark":6,"watermark_alpha":31,"watermark_height":32,"watermark_locate":33,"watermark_width":34},"weekly","","版权所有 © \u003Ca class=\"site_url\" href=\"https://zhl123.com\">2026 zhl123.com\u003C/a>","linux、Python、mysql、docker、k8s技术交流","layedit","0","粤ICP备15054664号-1","/uploads/images/20181109/7a86191de8b8bb60e9c6b54d8b27c5cc.jpg","#xe604","1","linux、Python、mysql、docker、k8s","{\"1\":{\"id\":\"1\",\"link_url\":\"https://linux.org\",\"logo\":\"\",\"name\":\"linux\",\"sort\":\"0\",\"status\":\"1\"}}","/uploads/images/20181109/e7305012448aed257176dd591846f50a.png","https://zhl123.com","2","学无止境\n学习，探索，研究，从不了解到了解，从无知到掌握，到灵活运用，在不断的学习中加深认识。由浅入深，由表及里。","业精于勤\n“业精于勤荒于嬉”，精深的业技靠的是勤学、刻苦努力，靠的是争分夺秒的勤学苦练才会有精深的技术。得在认真，失在随便。","工匠精神\n精益求精，注重细节，追求完美和极致，不惜花费时间精力，孜孜不倦，反复改进产品，把99%提高到99.99%。","linux","业精于勤、学无止境、工匠精神","廖地金","高级Linux运维工程师","1256636645","592958303","\u003Ca target=\"_blank\" href=\"//shang.qq.com/wpa/qunwpa?idkey=09be7d1a682073783fd636102e666393169b8a8aac8f3393da1de57bcaa821a0\">\u003Cimg border=\"0\" src=\"//pub.idqqimg.com/wpa/images/group.png\" alt=\"Linux技术\" title=\"Linux技术\">\u003C/a>"," | Python | mysql | docker | k8s 技术交流","100","300","9","500",{"0":36,"17":51,"18":60,"19":63,"20":67,"21":71,"22":76,"25":80,"26":83,"27":89,"29":94},{"children":37},{"0":38,"25":43,"26":48},[39,40,41,42],25,21,22,26,[44,45,46,47],17,18,19,20,[49,50],27,29,{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},"index",1,"list","article",2,"文章模型","show","/article/lists?category_id=17",{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},"python","/article/lists?category_id=18",{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},"容器技术",3,"/article/lists?category_id=19",{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},"负载均衡",4,"/article/lists?category_id=20",{"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},"分享无价",0,5,"/article/lists?category_id=21",{"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},"随笔",6,"/article/lists?category_id=22",{"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},"学无止境","/article/lists?category_id=25",{"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},"picture","图集模型","关于",8,"/picture/lists?category_id=26",{"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},"page","单页模型","关于博主","/page/27",{"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},"留言","/feedback",[98,108,110,112],{"children":99,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[100,102,104,106],{"children":101,"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},[],{"children":103,"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},[],{"children":105,"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},[],{"children":107,"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},[],{"children":109,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":111,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":113,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[114,116],{"children":115,"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},[],{"children":117,"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},[],{"1":119,"2":120,"3":121,"4":122,"5":125},{"id":53,"index_template":52,"list_template":54,"name":91,"show_template":58,"status":73,"tablename":90},{"id":56,"index_template":52,"list_template":54,"name":57,"show_template":58,"status":73,"tablename":55},{"id":65,"index_template":52,"list_template":54,"name":85,"show_template":58,"status":73,"tablename":84},{"id":69,"index_template":52,"list_template":54,"name":123,"show_template":58,"status":73,"tablename":124},"链接模型","link",{"id":74,"index_template":52,"list_template":54,"name":126,"show_template":58,"status":73,"tablename":127},"下载模型","download",[129],{"id":56,"name":57,"tablename":55},[131,137,139,141],{"children":132,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[133,134,135,136],{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},{"children":138,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":140,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":142,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[],{"article":144,"breadcrumb":155,"category":158,"next":159,"prev":162,"second_categorys":165,"seo":166},{"id":145,"category_id":40,"title":146,"keywords":147,"description":148,"image_url":6,"content":149,"content_md":150,"url":151,"hits":152,"is_recommend":73,"is_top":73,"create_time":153,"update_time":154},89,"10大Nginx优化配置项","Nginx,优化","（1）nginx运行工作进程个数，一般设置cpu的核心或者核心数x2如果不了解cpu的核数，可以top命令之后按1看出来，也可以查看/proc/cpuinfo文件 grep ^processor /proc/cpuinfo | wc -l [root@lx~]# vi/usr/local/nginx1.10/conf/nginx.confworker_processes  4;[root@lx~]# /usr/local/nginx1.10/sbin/nginx-s","\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cstrong>\u003Cspan>（1）nginx运行工作进程个数，一般设置cpu的核心或者核心数x2\u003C/span>\u003C/strong>\u003C/span>\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>如果不了解cpu的核数，可以top命令之后按1看出来，也可以查看/proc/cpuinfo文件 grep ^processor /proc/cpuinfo | wc -l&nbsp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>[root@lx~]#&nbsp;vi/usr/local/nginx1.10/conf/nginx.conf\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_processes&nbsp; 4;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>[root@lx~]# /usr/local/nginx1.10/sbin/nginx-s reload\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>[root@lx~]# ps -aux | grep nginx |grep -v grep\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>root&nbsp;9834&nbsp; 0.0&nbsp; 0.0&nbsp;47556&nbsp; 1948 ?&nbsp; &nbsp; &nbsp; Ss&nbsp; 22:36&nbsp; 0:00 nginx: master processnginx\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>www 10135&nbsp; 0.0&nbsp;0.0&nbsp; 50088&nbsp; 2004 ?&nbsp; &nbsp; &nbsp; &nbsp;S&nbsp; &nbsp; 22:58&nbsp; 0:00 nginx: worker process\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>www&nbsp;10136&nbsp; 0.0&nbsp; 0.0&nbsp;50088&nbsp; 2004 ?&nbsp; &nbsp; &nbsp; &nbsp; S&nbsp; &nbsp;22:58&nbsp; 0:00 nginx: worker process\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>www&nbsp;10137&nbsp; 0.0&nbsp; 0.0&nbsp;50088&nbsp; 2004 ?&nbsp; &nbsp; &nbsp; &nbsp; S&nbsp; &nbsp;22:58&nbsp; 0:00 nginx: worker process\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>www&nbsp;10138&nbsp; 0.0&nbsp; 0.0&nbsp;50088&nbsp; 2004 ?&nbsp; &nbsp; &nbsp; &nbsp; S&nbsp; &nbsp;22:58&nbsp; 0:00 nginx: worker process\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>Nginx运行CPU亲和力\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>比如4核配置\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_processes&nbsp; 4;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_cpu_affinity&nbsp;0001 0010 0100 1000\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>比如8核配置\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_processes 8;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_cpu_affinity 00000001 00000010 00000100 0000100000010000 00100000 01000000 10000000;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_processes最多开启8个，8个以上性能提升不会再提升了，而且稳定性变得更低，所以8个进程够用了。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>Nginx最多可以打开文件数\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_rlimit_nofile 65535;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>这个指令是指当一个nginx进程打开的最多文件描述符数目，理论值应该是最多打开文件数（ulimit -n）与nginx进程数相除，但是nginx分配请求并不是那么均匀，所以最好与ulimit -n的值保持一致。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注：\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>文件资源限制的配置可以在/etc/security/limits.conf设置，针对root/user等各个用户或者*代表所有用户来设置。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp;&nbsp;&nbsp;soft&nbsp;&nbsp;&nbsp;nofile&nbsp;&nbsp;&nbsp;65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp;&nbsp;&nbsp;hard&nbsp;&nbsp;nofile&nbsp;&nbsp;&nbsp;65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>用户重新登录生效（ulimit -n）\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cbr>\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cstrong>\u003Cspan>（2）Nginx事件处理模型\u003C/span>\u003C/strong>\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>events {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>use epoll;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>worker_connections 65535;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>multi_accept&nbsp;on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>}\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>nginx采用epoll事件模型，处理效率高\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>work_connections是单个worker进程允许客户端最大连接数，这个数值一般根据服务器性能和内存来制定，实际最大值就是worker进程数乘以work_connections\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>实际我们填入一个65535，足够了，这些都算并发值，一个网站的并发达到这么大的数量，也算一个大站了！\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>multi_accept&nbsp;告诉nginx收到一个新连接通知后接受尽可能多的连接，默认是on，设置为on后，多个worker按串行方式来处理连接，也就是一个连接只有一个worker被唤醒，其他的处于休眠状态，设置为off后，多个worker按并行方式来处理连接，也就是一个连接会唤醒所有的worker，直到连接分配完毕，没有取得连接的继续休眠。当你的服务器连接数不多时，开启这个参数会让负载有一定的降低，但是当服务器的吞吐量很大时，为了效率，可以关闭这个参数。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（3）开启高效传输模式\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>http {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>include mime.types;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>default_type application/octet-stream;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>……\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>sendfile on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>tcp_nopush on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>……\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>Include mime.types; //媒体类型,include&nbsp;只是一个在当前文件中包含另一个文件内容的指令\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>default_type application/octet-stream;&nbsp; //默认媒体类型足够\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>sendfile on；//开启高效文件传输模式，sendfile指令指定nginx是否调用sendfile函数来输出文件，对于普通应用设为 on，如果用来进行下载等应用磁盘IO重负载应用，可设置为off，以平衡磁盘与网络I/O处理速度，降低系统的负载。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注意：如果图片显示不正常把这个改成off。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>tcp_nopush on；必须在sendfile开启模式才有效，防止网路阻塞，积极的减少网络报文段的数量（将响应头和正文的开始部分一起发送，而不一个接一个的发送。）\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cstrong>\u003Cspan>（4）连接超时时间\u003C/span>\u003C/strong>\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>主要目的是保护服务器资源，CPU，内存，控制连接数，因为建立连接也是需要消耗资源的\u003C/span>\u003C/p>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>keepalive_timeout 60;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>tcp_nodelay on;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>client_header_buffer_size 4k;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>open_file_cache max=102400 inactive=20s;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>open_file_cache_valid 30s;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>open_file_cache_min_uses 1;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>client_header_timeout 15;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>client_body_timeout 15;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>reset_timedout_connection&nbsp;on;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>send_timeout 15;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>server_tokens&nbsp;off;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cpre style=\"text-align: justify;\">\u003Cp>\u003Cspan>client_max_body_size 10m;\u003Cbr>\u003C/span>\u003C/p>\u003C/pre>\u003Cp style=\"text-align: justify;\">\u003Cspan>keepalived_timeout客户端连接保持会话超时时间，超过这个时间，服务器断开这个链接\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>tcp_nodelay；也是防止网络阻塞，不过要包涵在keepalived参数才有效\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>client_header_buffer_size 4k;\u003Cbr>客户端请求头部的缓冲区大小，这个可以根据你的系统分页大小来设置，一般一个请求头的大小不会超过 1k，不过由于一般系统分页都要大于1k，所以这里设置为分页大小。分页大小可以用命令getconf PAGESIZE取得。\u003Cbr>open_file_cache max=102400 inactive=20s;\u003Cbr>这个将为打开文件指定缓存，默认是没有启用的，max指定缓存数量，建议和打开文件\u003Cbr>数一致，inactive 是指经过多长时间文件没被请求后删除缓存。\u003Cbr>open_file_cache_valid 30s;\u003Cbr>这个是指多长时间检查一次缓存的有效信息。\u003Cbr>open_file_cache_min_uses 1;\u003Cbr>open_file_cache指令中的inactive 参数时间内文件的最少使用次数，如果超过这个数字，文\u003Cbr>件描述符一直是在缓存中打开的，如上例，如果有一个文件在inactive 时间内一次没被使用，它将被移除。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>client_header_timeout设置请求头的超时时间。我们也可以把这个设置低些，如果超过这个时间没有发送任何数据，nginx将返回request time out的错误\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>client_body_timeout设置请求体的超时时间。我们也可以把这个设置低些，超过这个时间没有发送任何数据，和上面一样的错误提示\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>reset_timeout_connection&nbsp;告诉nginx关闭不响应的客户端连接。这将会释放那个客户端所占有的内存空间。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>send_timeout响应客户端超时时间，这个超时时间仅限于两个活动之间的时间，如果超过这个时间，客户端没有任何活动，nginx关闭连接\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>server_tokens&nbsp;&nbsp;并不会让nginx执行的速度更快，但它可以关闭在错误页面中的nginx版本数字，这样对于安全性是有好处的。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>client_max_body_size上传文件大小限制\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cbr>\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（5）fastcgi调优\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_connect_timeout&nbsp; &nbsp; 600;\u003C/span>\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_send_timeout 600;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_read_timeout 600;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_buffer_size 64k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_buffers 4 64k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_busy_buffers_size 128k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_temp_file_write_size 128k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_temp_path/usr/local/nginx1.10/nginx_tmp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_intercept_errors on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_path/usr/local/nginx1.10/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:128minactive=1d max_size=10g;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_connect_timeout 600; #指定连接到后端FastCGI的超时时间。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_send_timeout 600; #向FastCGI传送请求的超时时间。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_read_timeout 600; #指定接收FastCGI应答的超时时间。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_buffer_size 64k; #指定读取FastCGI应答第一部分需要用多大的缓冲区，默认的缓冲区大小为fastcgi_buffers指令中的每块大小，可以将这个值设置更小。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_buffers 4 64k; #指定本地需要用多少和多大的缓冲区来缓冲FastCGI的应答请求，如果一个php脚本所产生的页面大小为256KB，那么会分配4个64KB的缓冲区来缓存，如果页面大小大于256KB，那么大于256KB的部分会缓存到fastcgi_temp_path指定的路径中，但是这并不是好方法，因为内存中的数据处理速度要快于磁盘。一般这个值应该为站点中php脚本所产生的页面大小的中间值，如果站点大部分脚本所产生的页面大小为256KB，那么可以把这个值设置为“8 32K”、“4 64k”等。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_busy_buffers_size 128k; #建议设置为fastcgi_buffers的两倍，繁忙时候的buffer\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_temp_file_write_size 128k;&nbsp; #在写入fastcgi_temp_path时将用多大的数据块，默认值是fastcgi_buffers的两倍，该数值设置小时若负载上来时可能报502BadGateway\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_temp_path&nbsp;#缓存临时目录\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_intercept_errors on;#这个指令指定是否传递4xx和5xx错误信息到客户端，或者允许nginx使用error_page处理错误信息。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注：静态文件不存在会返回404页面，但是php页面则返回空白页！！\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_path /usr/local/nginx1.10/fastcgi_cachelevels=1:2&nbsp;keys_zone=cache_fastcgi:128minactive=1d max_size=10g;# fastcgi_cache缓存目录，可以设置目录层级，比如1:2会生成16*256个子目录，cache_fastcgi是这个缓存空间的名字，cache是用多少内存（这样热门的内容nginx直接放内存，提高访问速度），inactive表示默认失效时间，如果缓存数据在失效时间内没有被访问,将被删除，max_size表示最多用多少硬盘空间。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache&nbsp;cache_fastcgi;&nbsp; #表示开启FastCGI缓存并为其指定一个名称。开启缓存非常有用，可以有效降低CPU的负载，并且防止502的错误放生。cache_fastcgi为proxy_cache_path指令创建的缓存区名称\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_valid 200 302 1h;&nbsp;#用来指定应答代码的缓存时间，实例中的值表示将200和302应答缓存一小时，要和fastcgi_cache配合使用\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_valid 301 1d;&nbsp; &nbsp; &nbsp;#将301应答缓存一天\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_valid any 1m;&nbsp; &nbsp; &nbsp;#将其他应答缓存为1分钟\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_min_uses 1;&nbsp; &nbsp; &nbsp; &nbsp;#该指令用于设置经过多少次请求的相同URL将被缓存。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_cache_key http://$host$request_uri; #该指令用来设置web缓存的Key值,nginx根据Key值md5哈希存储.一般根据$host(域名)、$request_uri(请求的路径)等变量组合成proxy_cache_key 。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fastcgi_pass #指定FastCGI服务器监听端口与地址，可以是本机或者其它\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>总结：\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>nginx的缓存功能有：proxy_cache / fastcgi_cache\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>proxy_cache的作用是缓存后端服务器的内容，可能是任何内容，包括静态的和动态。\u003Cbr>fastcgi_cache的作用是缓存fastcgi生成的内容，很多情况是php生成的动态的内容。\u003Cbr>proxy_cache缓存减少了nginx与后端通信的次数，节省了传输时间和后端宽带。\u003Cbr>fastcgi_cache缓存减少了nginx与php的通信的次数，更减轻了php和数据库(mysql)的压力。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（6）gzip调优\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>使用gzip压缩功能，可能为我们节约带宽，加快传输速度，有更好的体验，也为我们节约成本，所以说这是一个重点。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>Nginx启用压缩功能需要你来ngx_http_gzip_module模块，apache使用的是mod_deflate\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>一般我们需要压缩的内容有：文本，js，html，css，对于图片，视频，flash什么的不压缩，同时也要注意，我们使用gzip的功能是需要消耗CPU的！\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_min_length&nbsp;2k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_buffers&nbsp; &nbsp; 4 32k;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_http_version 1.1;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_comp_level 6;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_typestext/plain text/css text/javascriptapplication/json application/javascript application/x-javascriptapplication/xml;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_vary on;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_proxied any;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip on;&nbsp; &nbsp; #开启压缩功能\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_min_length 1k; #设置允许压缩的页面最小字节数，页面字节数从header头的Content-Length中获取，默认值是0，不管页面多大都进行压缩，建议设置成大于1K，如果小与1K可能会越压越大。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_buffers 4 32k; #压缩缓冲区大小，表示申请4个单位为32K的内存作为压缩结果流缓存，默认值是申请与原始数据大小相同的内存空间来存储gzip压缩结果。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_http_version 1.1; #压缩版本，用于设置识别HTTP协议版本，默认是1.1，目前大部分浏览器已经支持GZIP解压，使用默认即可\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_comp_level 6; #压缩比例，用来指定GZIP压缩比，1压缩比最小，处理速度最快，9压缩比最大，传输速度快，但是处理慢，也比较消耗CPU资源。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_types text/css text/xml application/javascript; #用来指定压缩的类型，‘text/html’类型总是会被压缩。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>默认值: gzip_types text/html (默认不对js/css文件进行压缩)\u003Cbr># 压缩类型，匹配MIME��型进行压缩\u003Cbr># 不能用通配符 text/*\u003Cbr># (无论是否指定)text/html默认已经压缩&nbsp;\u003Cbr># 设置哪压缩种文本文件可参考 conf/mime.types\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>gzip_vary on;&nbsp; #varyheader支持，改选项可以让前端的缓存服务器缓存经过GZIP压缩的页面，例如用Squid缓存经过nginx压缩的数据\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（7）expires缓存调优\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>缓存，主要针对于图片，css，js等元素更改机会比较少的情况下使用，特别是图片，占用带宽大，我们完全可以设置图片在浏览器本地缓存365d，css，js，html可以缓存个10来天，这样用户第一次打开加载慢一点，第二次，就非常快了！缓存的时候，我们需要将需要缓存的拓展名列出来， Expires缓存配置在server字段里面\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>location ~* \\.(ico|jpe?g|gif|png|bmp|swf|flv)$ {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; expires 30d;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; #log_not_found off;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; access_log off;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>}\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>location ~* \\.(js|css)$ {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; expires 7d;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; log_not_found off;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; access_log off;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>}&nbsp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注：log_not_found off;是否在error_log中记录不存在的错误。默认是。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>总结：\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>expire功能优点&nbsp;（1）expires可以降低网站购买的带宽，节约成本（2）同时提升用户访问体验（3）减轻服务的压力，节约服务器成本，是web服务非常重要的功能。 expire功能缺点：被缓存的页面或数据更新了，用户看到的可能还是旧的内容，反而影响用户体验。解决办法：第一个缩短缓存时间，例如：1天，但不彻底，除非更新频率大于1天；第二个对缓存的对象改名。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>网站不希望被缓存的内容 1）网站流量统计工具2）更新频繁的文件（google的logo）\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（8）防盗链\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>防止别人直接从你网站引用图片等链接，消耗了你的资源和网络流量，那么我们的解决办法由几种： 1：水印，品牌宣传，你的带宽，服务器足够 2：防火墙，直接控制，前提是你知道IP来源 3：防盗链策略下面的方法是直接给予404的错误提示\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>location ~*^.+\\.(jpg|gif|png|swf|flv|wma|wmv|asf|mp3|mmf|zip|rar)$ {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; valid_referers noneblocked&nbsp; www.benet.com benet.com;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; if($invalid_referer) {\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; &nbsp; #return 302&nbsp; http://www.benet.com/img/nolink.jpg;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; &nbsp; return 404;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; &nbsp; &nbsp; break;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; }\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp; &nbsp; access_log off;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp;}\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>参数可以使如下形式：\u003Cbr>none 意思是不存在的Referer头(表示空的，也就是直接访问，比如直接在浏览器打开一个图片)\u003Cbr>blocked 意为根据防火墙伪装Referer头，如：“Referer:XXXXXXX”。\u003Cbr>server_names 为一个或多个服务器的列表，0.5.33版本以后可以在名称中使用“*”通配符。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cstrong>\u003Cspan>（9）内核参数优化\u003C/span>\u003C/strong>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fs.file-max = 999999：这个参数表示进程（比如一个worker进程）可以同时打开的最大句柄数，这个参数直线限制最大并发连接数，需根据实际情况配置。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_max_tw_buckets = 6000&nbsp;#这个参数表示\u003C/span>\u003Cspan>操作系统\u003C/span>\u003Cspan>允许TIME_WAIT套接字数量的最大值，如果超过这个数字，TIME_WAIT套接字将立刻被清除并打印警告信息。该参数默认为180000，过多的TIME_WAIT套接字会使Web服务器变慢。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注：主动关闭连接的服务端会产生TIME_WAIT状态的连接\u003Cbr>net.ipv4.ip_local_port_range = 1024 65000&nbsp;#允许系统打开的端口范围。\u003Cbr>net.ipv4.tcp_tw_recycle = 1#启用timewait快速回收。\u003Cbr>net.ipv4.tcp_tw_reuse = 1#开启重用。允许将TIME-WAIT sockets重新用于新的TCP连接。这对于服务器来说很有意义，因为服务器上总会有大量TIME-WAIT状态的连接。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_keepalive_time = 30：这个参数表示当keepalive启用时，TCP发送keepalive消息的频度。默认是2小时，若将其设置的小一些，可以更快地清理无效的连接。\u003Cbr>net.ipv4.tcp_syncookies = 1#开启SYN Cookies，当出现SYN等待队列溢出时，启用cookies来处理。\u003Cbr>net.core.somaxconn = 40960&nbsp;#web 应用中 listen 函数的 backlog 默认会给我们内核参数的 net.core.somaxconn 限制到128，而nginx定义的NGX_LISTEN_BACKLOG 默认为511，所以有必要调整这个值。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>注：对于一个TCP连接，Server与Client需要通过三次握手来建立网络连接.当三次握手成功后,我们可以看到端口的状态由LISTEN转变为ESTABLISHED,接着这条链路上就可以开始传送数据了.每一个处于监听(Listen)状态的端口,都有自己的监听队列.监听队列的长度与如somaxconn参数和使用该端口的程序中listen()函数有关\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>somaxconn参数:定义了系统中每一个端口最大的监听队列的长度,这是个全局的参数,默认值为128，对于一个经常处理新连接的高负载 web服务环境来说，默认的 128 太小了。大多数环境这个值建议增加到 1024 或者更多。大的侦听队列对防止拒绝服务 DoS 攻击也会有所帮助。\u003Cbr>net.core.netdev_max_backlog = 262144&nbsp;#每个网络接口接收数据包的速率比内核处理这些包的速率快时，允许送到队列的数据包的最大数目。\u003Cbr>net.ipv4.tcp_max_syn_backlog = 262144&nbsp;#这个参数标示TCP三次握手建立阶段接受SYN请求队列的最大长度，默认为1024，将其设置得大一些可以使出现Nginx繁忙来不及accept新连接的情况时，Linux不至于丢失客户端发起的连接请求。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_rmem = 10240 87380 12582912#这个参数定义了TCP接受缓存（用于TCP接受滑动窗口）的最小值、默认值、最大值。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_wmem&nbsp;= 10240&nbsp;87380 12582912：这个参数定义了TCP发送缓存（用于TCP发送滑动窗口）的最小值、默认值、最大值。\u003Cbr>net.core.rmem_default&nbsp;= 6291456：这个参数表示内核套接字接受缓存区默认的大小。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.wmem_default&nbsp;= 6291456：这个参数表示内核套接字发送缓存区默认的大小。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.rmem_max&nbsp;= 12582912：这个参数表示内核套接字接受缓存区的最大大小。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.wmem_max&nbsp;= 12582912：这个参数表示内核套接字发送缓存区的最大大小。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_syncookies = 1：该参数与性能无关，用于解决TCP的SYN攻击。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>下面贴一个完整的内核优化设置：\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>fs.file-max = 999999\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.ip_forward = 0\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.conf.default.rp_filter = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.conf.default.accept_source_route = 0\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.sysrq = 0\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.core_uses_pid = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_syncookies = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.msgmnb = 65536\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.msgmax = 65536\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.shmmax = 68719476736\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>kernel.shmall = 4294967296\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_max_tw_buckets = 6000\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_sack = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_window_scaling = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_rmem = 10240 87380 12582912\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_wmem = 10240 87380 12582912\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.wmem_default = 8388608\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.rmem_default = 8388608\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.rmem_max = 16777216\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.wmem_max = 16777216\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.netdev_max_backlog = 262144\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.core.somaxconn = 40960\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_max_orphans = 3276800\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_max_syn_backlog = 262144\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_timestamps = 0\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_synack_retries = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_syn_retries = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_tw_recycle = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_tw_reuse = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_mem = 94500000 915000000 927000000\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_fin_timeout = 1\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.tcp_keepalive_time = 30\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>net.ipv4.ip_local_port_range = 1024 65000\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>执行sysctl&nbsp; -p使内核修改生效\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>&nbsp;\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>\u003Cstrong>\u003Cspan>（10）关于系统连接数的优化：\u003C/span>\u003C/strong>\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>linux 默认值 open files为1024\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>#ulimit -n\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>1024\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>说明server只允许同时打开1024个文件\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>使用ulimit -a 可以查看当前系统的所有限制值，使用ulimit -n 可以查看当前的最大打开文件数。\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>新装的linux 默认只有1024 ，当作负载较大的服务器时，很容易遇到error: too many open files。因此，需要将其改大\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>在/etc/security/limits.conf最后增加：\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;soft&nbsp; &nbsp; nofile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;hard&nbsp; &nbsp; nofile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;soft&nbsp; &nbsp; noproc&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cspan>*&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; hard&nbsp; &nbsp; noproc&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 65535\u003C/span>\u003C/p>\u003Cp style=\"text-align: justify;\">\u003Cbr>\u003C/p>\u003Cblockquote style=\"text-align: justify;\">\u003Cp>\u003Cspan>作者：liuxiong\u003C/span>\u003C/p>\u003Cp>\u003Cspan>来源：http://www.linuxidc.com/Linux/2017-06/144493.htm\u003C/span>\u003C/p>\u003C/blockquote>","**\n（1）nginx运行工作进程个数，一般设置cpu的核心或者核心数x2\n**\n\n如果不了解cpu的核数，可以top命令之后按1看出来，也可以查看/proc/cpuinfo文件 grep ^processor /proc/cpuinfo | wc -l \n\n[root@lx~]# vi/usr/local/nginx1.10/conf/nginx.conf\n\nworker_processes  4;\n\n[root@lx~]# /usr/local/nginx1.10/sbin/nginx-s reload\n\n[root@lx~]# ps -aux | grep nginx |grep -v grep\n\nroot 9834  0.0  0.0 47556  1948 ?      Ss  22:36  0:00 nginx: master processnginx\n\nwww 10135  0.0 0.0  50088  2004 ?       S    22:58  0:00 nginx: worker process\n\nwww 10136  0.0  0.0 50088  2004 ?        S   22:58  0:00 nginx: worker process\n\nwww 10137  0.0  0.0 50088  2004 ?        S   22:58  0:00 nginx: worker process\n\nwww 10138  0.0  0.0 50088  2004 ?        S   22:58  0:00 nginx: worker process\n\n**\nNginx运行CPU亲和力\n**\n\n比如4核配置\n\nworker_processes  4;\n\nworker_cpu_affinity 0001 0010 0100 1000\n\n比如8核配置\n\nworker_processes 8;\n\nworker_cpu_affinity 00000001 00000010 00000100 0000100000010000 00100000 01000000 10000000;\n\nworker_processes最多开启8个，8个以上性能提升不会再提升了，而且稳定性变得更低，所以8个进程够用了。\n\n**\nNginx最多可以打开文件数\n**\n\nworker_rlimit_nofile 65535;\n\n这个指令是指当一个nginx进程打开的最多文件描述符数目，理论值应该是最多打开文件数（ulimit -n）与nginx进程数相除，但是nginx分配请求并不是那么均匀，所以最好与ulimit -n的值保持一致。\n\n注：\n\n文件资源限制的配置可以在/etc/security/limits.conf设置，针对root/user等各个用户或者*代表所有用户来设置。\n\n*   soft   nofile   65535\n\n*   hard  nofile   65535\n\n用户重新登录生效（ulimit -n）\n\n**\n（2）Nginx事件处理模型\n**\n\nevents {\n\nuse epoll;\n\nworker_connections 65535;\n\nmulti_accept on;\n\n}\n\nnginx采用epoll事件模型，处理效率高\n\nwork_connections是单个worker进程允许客户端最大连接数，这个数值一般根据服务器性能和内存来制定，实际最大值就是worker进程数乘以work_connections\n\n实际我们填入一个65535，足够了，这些都算并发值，一个网站的并发达到这么大的数量，也算一个大站了！\n\nmulti_accept 告诉nginx收到一个新连接通知后接受尽可能多的连接，默认是on，设置为on后，多个worker按串行方式来处理连接，也就是一个连接只有一个worker被唤醒，其他的处于休眠状态，设置为off后，多个worker按并行方式来处理连接，也就是一个连接会唤醒所有的worker，直到连接分配完毕，没有取得连接的继续休眠。当你的服务器连接数不多时，开启这个参数会让负载有一定的降低，但是当服务器的吞吐量很大时，为了效率，可以关闭这个参数。\n\n**\n（3）开启高效传输模式\n**\n\nhttp {\n\ninclude mime.types;\n\ndefault_type application/octet-stream;\n\n……\n\nsendfile on;\n\ntcp_nopush on;\n\n……\n\nInclude mime.types; //媒体类型,include 只是一个在当前文件中包含另一个文件内容的指令\n\ndefault_type application/octet-stream;  //默认媒体类型足够\n\nsendfile on；//开启高效文件传输模式，sendfile指令指定nginx是否调用sendfile函数来输出文件，对于普通应用设为 on，如果用来进行下载等应用磁盘IO重负载应用，可设置为off，以平衡磁盘与网络I/O处理速度，降低系统的负载。\n\n注意：如果图片显示不正常把这个改成off。\n\ntcp_nopush on；必须在sendfile开启模式才有效，防止网路阻塞，积极的减少网络报文段的数量（将响应头和正文的开始部分一起发送，而不一个接一个的发送。）\n\n**\n（4）连接超时时间\n**\n\n主要目的是保护服务器资源，CPU，内存，控制连接数，因为建立连接也是需要消耗资源的\n\n```\nkeepalive_timeout 60;\n```\n\n```\ntcp_nodelay on;\n```\n\n```\nclient_header_buffer_size 4k;\n```\n\n```\nopen_file_cache max=102400 inactive=20s;\n```\n\n```\nopen_file_cache_valid 30s;\n```\n\n```\nopen_file_cache_min_uses 1;\n```\n\n```\nclient_header_timeout 15;\n```\n\n```\nclient_body_timeout 15;\n```\n\n```\nreset_timedout_connection on;\n```\n\n```\nsend_timeout 15;\n```\n\n```\nserver_tokens off;\n```\n\n```\nclient_max_body_size 10m;\n```\n\nkeepalived_timeout客户端连接保持会话超时时间，超过这个时间，服务器断开这个链接\n\ntcp_nodelay；也是防止网络阻塞，不过要包涵在keepalived参数才有效\n\nclient_header_buffer_size 4k;\n客户端请求头部的缓冲区大小，这个可以根据你的系统分页大小来设置，一般一个请求头的大小不会超过 1k，不过由于一般系统分页都要大于1k，所以这里设置为分页大小。分页大小可以用命令getconf PAGESIZE取得。\nopen_file_cache max=102400 inactive=20s;\n这个将为打开文件指定缓存，默认是没有启用的，max指定缓存数量，建议和打开文件\n数一致，inactive 是指经过多长时间文件没被请求后删除缓存。\nopen_file_cache_valid 30s;\n这个是指多长时间检查一次缓存的有效信息。\nopen_file_cache_min_uses 1;\nopen_file_cache指令中的inactive 参数时间内文件的最少使用次数，如果超过这个数字，文\n件描述符一直是在缓存中打开的，如上例，如果有一个文件在inactive 时间内一次没被使用，它将被移除。\n\nclient_header_timeout设置请求头的超时时间。我们也可以把这个设置低些，如果超过这个时间没有发送任何数据，nginx将返回request time out的错误\n\nclient_body_timeout设置请求体的超时时间。我们也可以把这个设置低些，超过这个时间没有发送任何数据，和上面一样的错误提示\n\nreset_timeout_connection 告诉nginx关闭不响应的客户端连接。这将会释放那个客户端所占有的内存空间。\n\nsend_timeout响应客户端超时时间，这个超时时间仅限于两个活动之间的时间，如果超过这个时间，客户端没有任何活动，nginx关闭连接\n\nserver_tokens  并不会让nginx执行的速度更快，但它可以关闭在错误页面中的nginx版本数字，这样对于安全性是有好处的。\n\nclient_max_body_size上传文件大小限制\n\n**\n（5）fastcgi调优\n**\n\nfastcgi_connect_timeout    600;\n\nfastcgi_send_timeout 600;\n\nfastcgi_read_timeout 600;\n\nfastcgi_buffer_size 64k;\n\nfastcgi_buffers 4 64k;\n\nfastcgi_busy_buffers_size 128k;\n\nfastcgi_temp_file_write_size 128k;\n\nfastcgi_temp_path/usr/local/nginx1.10/nginx_tmp;\n\nfastcgi_intercept_errors on;\n\nfastcgi_cache_path/usr/local/nginx1.10/fastcgi_cache levels=1:2 keys_zone=cache_fastcgi:128minactive=1d max_size=10g;\n\nfastcgi_connect_timeout 600; #指定连接到后端FastCGI的超时时间。\n\nfastcgi_send_timeout 600; #向FastCGI传送请求的超时时间。\n\nfastcgi_read_timeout 600; #指定接收FastCGI应答的超时时间。\n\nfastcgi_buffer_size 64k; #指定读取FastCGI应答第一部分需要用多大的缓冲区，默认的缓冲区大小为fastcgi_buffers指令中的每块大小，可以将这个值设置更小。\n\nfastcgi_buffers 4 64k; #指定本地需要用多少和多大的缓冲区来缓冲FastCGI的应答请求，如果一个php脚本所产生的页面大小为256KB，那么会分配4个64KB的缓冲区来缓存，如果页面大小大于256KB，那么大于256KB的部分会缓存到fastcgi_temp_path指定的路径中，但是这并不是好方法，因为内存中的数据处理速度要快于磁盘。一般这个值应该为站点中php脚本所产生的页面大小的中间值，如果站点大部分脚本所产生的页面大小为256KB，那么可以把这个值设置为“8 32K”、“4 64k”等。\n\nfastcgi_busy_buffers_size 128k; #建议设置为fastcgi_buffers的两倍，繁忙时候的buffer\n\nfastcgi_temp_file_write_size 128k;  #在写入fastcgi_temp_path时将用多大的数据块，默认值是fastcgi_buffers的两倍，该数值设置小时若负载上来时可能报502BadGateway\n\nfastcgi_temp_path #缓存临时目录\n\nfastcgi_intercept_errors on;#这个指令指定是否传递4xx和5xx错误信息到客户端，或者允许nginx使用error_page处理错误信息。\n\n注：静态文件不存在会返回404页面，但是php页面则返回空白页！！\n\nfastcgi_cache_path /usr/local/nginx1.10/fastcgi_cachelevels=1:2 keys_zone=cache_fastcgi:128minactive=1d max_size=10g;# fastcgi_cache缓存目录，可以设置目录层级，比如1:2会生成16*256个子目录，cache_fastcgi是这个缓存空间的名字，cache是用多少内存（这样热门的内容nginx直接放内存，提高访问速度），inactive表示默认失效时间，如果缓存数据在失效时间内没有被访问,将被删除，max_size表示最多用多少硬盘空间。\n\nfastcgi_cache cache_fastcgi;  #表示开启FastCGI缓存并为其指定一个名称。开启缓存非常有用，可以有效降低CPU的负载，并且防止502的错误放生。cache_fastcgi为proxy_cache_path指令创建的缓存区名称\n\nfastcgi_cache_valid 200 302 1h; #用来指定应答代码的缓存时间，实例中的值表示将200和302应答缓存一小时，要和fastcgi_cache配合使用\n\nfastcgi_cache_valid 301 1d;     #将301应答缓存一天\n\nfastcgi_cache_valid any 1m;     #将其他应答缓存为1分钟\n\nfastcgi_cache_min_uses 1;       #该指令用于设置经过多少次请求的相同URL将被缓存。\n\nfastcgi_cache_key http://$host$request_uri; #该指令用来设置web缓存的Key值,nginx根据Key值md5哈希存储.一般根据$host(域名)、$request_uri(请求的路径)等变量组合成proxy_cache_key 。\n\nfastcgi_pass #指定FastCGI服务器监听端口与地址，可以是本机或者其它\n\n**\n总结：\n**\n\nnginx的缓存功能有：proxy_cache / fastcgi_cache\n\nproxy_cache的作用是缓存后端服务器的内容，可能是任何内容，包括静态的和动态。\nfastcgi_cache的作用是缓存fastcgi生成的内容，很多情况是php生成的动态的内容。\nproxy_cache缓存减少了nginx与后端通信的次数，节省了传输时间和后端宽带。\nfastcgi_cache缓存减少了nginx与php的通信的次数，更减轻了php和数据库(mysql)的压力。\n\n**\n（6）gzip调优\n**\n\n使用gzip压缩功能，可能为我们节约带宽，加快传输速度，有更好的体验，也为我们节约成本，所以说这是一个重点。\n\nNginx启用压缩功能需要你来ngx_http_gzip_module模块，apache使用的是mod_deflate\n\n一般我们需要压缩的内容有：文本，js，html，css，对于图片，视频，flash什么的不压缩，同时也要注意，我们使用gzip的功能是需要消耗CPU的！\n\ngzip on;\n\ngzip_min_length 2k;\n\ngzip_buffers    4 32k;\n\ngzip_http_version 1.1;\n\ngzip_comp_level 6;\n\ngzip_typestext/plain text/css text/javascriptapplication/json application/javascript application/x-javascriptapplication/xml;\n\ngzip_vary on;\n\ngzip_proxied any;\n\ngzip on;    #开启压缩功能\n\ngzip_min_length 1k; #设置允许压缩的页面最小字节数，页面字节数从header头的Content-Length中获取，默认值是0，不管页面多大都进行压缩，建议设置成大于1K，如果小与1K可能会越压越大。\n\ngzip_buffers 4 32k; #压缩缓冲区大小，表示申请4个单位为32K的内存作为压缩结果流缓存，默认值是申请与原始数据大小相同的内存空间来存储gzip压缩结果。\n\ngzip_http_version 1.1; #压缩版本，用于设置识别HTTP协议版本，默认是1.1，目前大部分浏览器已经支持GZIP解压，使用默认即可\n\ngzip_comp_level 6; #压缩比例，用来指定GZIP压缩比，1压缩比最小，处理速度最快，9压缩比最大，传输速度快，但是处理慢，也比较消耗CPU资源。\n\ngzip_types text/css text/xml application/javascript; #用来指定压缩的类型，‘text/html’类型总是会被压缩。\n\n默认值: gzip_types text/html (默认不对js/css文件进行压缩)\n# 压缩类型，匹配MIME��型进行压缩\n# 不能用通配符 text/*\n# (无论是否指定)text/html默认已经压缩 \n# 设置哪压缩种文本文件可参考 conf/mime.types\n\ngzip_vary on;  #varyheader支持，改选项可以让前端的缓存服务器缓存经过GZIP压缩的页面，例如用Squid缓存经过nginx压缩的数据\n\n**\n（7）expires缓存调优\n**\n\n缓存，主要针对于图片，css，js等元素更改机会比较少的情况下使用，特别是图片，占用带宽大，我们完全可以设置图片在浏览器本地缓存365d，css，js，html可以缓存个10来天，这样用户第一次打开加载慢一点，第二次，就非常快了！缓存的时候，我们需要将需要缓存的拓展名列出来， Expires缓存配置在server字段里面\n\nlocation ~* \\.(ico|jpe?g|gif|png|bmp|swf|flv)$ {\n\n  expires 30d;\n\n  #log_not_found off;\n\n  access_log off;\n\n}\n\nlocation ~* \\.(js|css)$ {\n\n  expires 7d;\n\n  log_not_found off;\n\n  access_log off;\n\n} \n\n注：log_not_found off;是否在error_log中记录不存在的错误。默认是。\n\n总结：\n\nexpire功能优点 （1）expires可以降低网站购买的带宽，节约成本（2）同时提升用户访问体验（3）减轻服务的压力，节约服务器成本，是web服务非常重要的功能。 expire功能缺点：被缓存的页面或数据更新了，用户看到的可能还是旧的内容，反而影响用户体验。解决办法：第一个缩短缓存时间，例如：1天，但不彻底，除非更新频率大于1天；第二个对缓存的对象改名。\n\n网站不希望被缓存的内容 1）网站流量统计工具2）更新频繁的文件（google的logo）\n\n \n\n**\n（8）防盗链\n**\n\n防止别人直接从你网站引用图片等链接，消耗了你的资源和网络流量，那么我们的解决办法由几种： 1：水印，品牌宣传，你的带宽，服务器足够 2：防火墙，直接控制，前提是你知道IP来源 3：防盗链策略下面的方法是直接给予404的错误提示\n\nlocation ~*^.+\\.(jpg|gif|png|swf|flv|wma|wmv|asf|mp3|mmf|zip|rar)$ {\n\n    valid_referers noneblocked  www.benet.com benet.com;\n\n    if($invalid_referer) {\n\n      #return 302  http://www.benet.com/img/nolink.jpg;\n\n      return 404;\n\n        break;\n\n    }\n\n    access_log off;\n\n }\n\n参数可以使如下形式：\nnone 意思是不存在的Referer头(表示空的，也就是直接访问，比如直接在浏览器打开一个图片)\nblocked 意为根据防火墙伪装Referer头，如：“Referer:XXXXXXX”。\nserver_names 为一个或多个服务器的列表，0.5.33版本以后可以在名称中使用“*”通配符。\n\n**\n（9）内核参数优化\n**\n\nfs.file-max = 999999：这个参数表示进程（比如一个worker进程）可以同时打开的最大句柄数，这个参数直线限制最大并发连接数，需根据实际情况配置。\n\nnet.ipv4.tcp_max_tw_buckets = 6000 #这个参数表示\n\n操作系统\n\n允许TIME_WAIT套接字数量的最大值，如果超过这个数字，TIME_WAIT套接字将立刻被清除并打印警告信息。该参数默认为180000，过多的TIME_WAIT套接字会使Web服务器变慢。\n\n注：主动关闭连接的服务端会产生TIME_WAIT状态的连接\nnet.ipv4.ip_local_port_range = 1024 65000 #允许系统打开的端口范围。\nnet.ipv4.tcp_tw_recycle = 1#启用timewait快速回收。\nnet.ipv4.tcp_tw_reuse = 1#开启重用。允许将TIME-WAIT sockets重新用于新的TCP连接。这对于服务器来说很有意义，因为服务器上总会有大量TIME-WAIT状态的连接。\n\nnet.ipv4.tcp_keepalive_time = 30：这个参数表示当keepalive启用时，TCP发送keepalive消息的频度。默认是2小时，若将其设置的小一些，可以更快地清理无效的连接。\nnet.ipv4.tcp_syncookies = 1#开启SYN Cookies，当出现SYN等待队列溢出时，启用cookies来处理。\nnet.core.somaxconn = 40960 #web 应用中 listen 函数的 backlog 默认会给我们内核参数的 net.core.somaxconn 限制到128，而nginx定义的NGX_LISTEN_BACKLOG 默认为511，所以有必要调整这个值。\n\n注：对于一个TCP连接，Server与Client需要通过三次握手来建立网络连接.当三次握手成功后,我们可以看到端口的状态由LISTEN转变为ESTABLISHED,接着这条链路上就可以开始传送数据了.每一个处于监听(Listen)状态的端口,都有自己的监听队列.监听队列的长度与如somaxconn参数和使用该端口的程序中listen()函数有关\n\nsomaxconn参数:定义了系统中每一个端口最大的监听队列的长度,这是个全局的参数,默认值为128，对于一个经常处理新连接的高负载 web服务环境来说，默认的 128 太小了。大多数环境这个值建议增加到 1024 或者更多。大的侦听队列对防止拒绝服务 DoS 攻击也会有所帮助。\nnet.core.netdev_max_backlog = 262144 #每个网络接口接收数据包的速率比内核处理这些包的速率快时，允许送到队列的数据包的最大数目。\nnet.ipv4.tcp_max_syn_backlog = 262144 #这个参数标示TCP三次握手建立阶段接受SYN请求队列的最大长度，默认为1024，将其设置得大一些可以使出现Nginx繁忙来不及accept新连接的情况时，Linux不至于丢失客户端发起的连接请求。\n\nnet.ipv4.tcp_rmem = 10240 87380 12582912#这个参数定义了TCP接受缓存（用于TCP接受滑动窗口）的最小值、默认值、最大值。\n\nnet.ipv4.tcp_wmem = 10240 87380 12582912：这个参数定义了TCP发送缓存（用于TCP发送滑动窗口）的最小值、默认值、最大值。\nnet.core.rmem_default = 6291456：这个参数表示内核套接字接受缓存区默认的大小。\n\nnet.core.wmem_default = 6291456：这个参数表示内核套接字发送缓存区默认的大小。\n\nnet.core.rmem_max = 12582912：这个参数表示内核套接字接受缓存区的最大大小。\n\nnet.core.wmem_max = 12582912：这个参数表示内核套接字发送缓存区的最大大小。\n\nnet.ipv4.tcp_syncookies = 1：该参数与性能无关，用于解决TCP的SYN攻击。\n\n \n\n下面贴一个完整的内核优化设置：\n\nfs.file-max = 999999\n\nnet.ipv4.ip_forward = 0\n\nnet.ipv4.conf.default.rp_filter = 1\n\nnet.ipv4.conf.default.accept_source_route = 0\n\nkernel.sysrq = 0\n\nkernel.core_uses_pid = 1\n\nnet.ipv4.tcp_syncookies = 1\n\nkernel.msgmnb = 65536\n\nkernel.msgmax = 65536\n\nkernel.shmmax = 68719476736\n\nkernel.shmall = 4294967296\n\nnet.ipv4.tcp_max_tw_buckets = 6000\n\nnet.ipv4.tcp_sack = 1\n\nnet.ipv4.tcp_window_scaling = 1\n\nnet.ipv4.tcp_rmem = 10240 87380 12582912\n\nnet.ipv4.tcp_wmem = 10240 87380 12582912\n\nnet.core.wmem_default = 8388608\n\nnet.core.rmem_default = 8388608\n\nnet.core.rmem_max = 16777216\n\nnet.core.wmem_max = 16777216\n\nnet.core.netdev_max_backlog = 262144\n\nnet.core.somaxconn = 40960\n\nnet.ipv4.tcp_max_orphans = 3276800\n\nnet.ipv4.tcp_max_syn_backlog = 262144\n\nnet.ipv4.tcp_timestamps = 0\n\nnet.ipv4.tcp_synack_retries = 1\n\nnet.ipv4.tcp_syn_retries = 1\n\nnet.ipv4.tcp_tw_recycle = 1\n\nnet.ipv4.tcp_tw_reuse = 1\n\nnet.ipv4.tcp_mem = 94500000 915000000 927000000\n\nnet.ipv4.tcp_fin_timeout = 1\n\nnet.ipv4.tcp_keepalive_time = 30\n\nnet.ipv4.ip_local_port_range = 1024 65000\n\n执行sysctl  -p使内核修改生效\n\n \n\n**\n（10）关于系统连接数的优化：\n**\n\nlinux 默认值 open files为1024\n\n#ulimit -n\n\n1024\n\n说明server只允许同时打开1024个文件\n\n使用ulimit -a 可以查看当前系统的所有限制值，使用ulimit -n 可以查看当前的最大打开文件数。\n\n新装的linux 默认只有1024 ，当作负载较大的服务器时，很容易遇到error: too many open files。因此，需要将其改大\n\n在/etc/security/limits.conf最后增加：\n\n*               soft    nofile          65535\n\n*               hard    nofile          65535\n\n*               soft    noproc          65535\n\n*                hard    noproc          65535\n\n> 作者：liuxiong来源：http://www.linuxidc.com/Linux/2017-06/144493.htm","/article/89",4625,"2018-11-15 10:44:30","2018-11-16 09:31:43",[156,157],{"id":40,"name":72,"url":75},{"id":145,"name":146,"url":151},{"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},{"title":160,"url":161},"10 个 MySQL 经典错误","/article/91",{"title":163,"url":164},"rabbitmq集群安装","/article/71",[],{"description":148,"keywords":147,"title":146},[168,177,186,195,204,213,222,231,240,248],{"id":169,"category_id":44,"title":170,"keywords":171,"description":172,"image_url":6,"url":173,"hits":174,"is_recommend":73,"is_top":73,"create_time":175,"update_time":176},101,"开启 HTTPS 并获得 ssllabs 满分的过程","开启,获得,满分,过程","准备工作确保你要申请证书的域名都解析到了这台服务器上，且能直接通过域名访问。使用官网推荐的CertBot获取证书。在CertBot官网选择一下环境(比如我选Nginx on Ubuntu 17.04)就可以看到入门教程了。安装CertBot12345apt-get updateapt-get install software-properties-commonadd-apt-repository ppa:certbot/certbotapt-get updateapt-get","/article/101",18546,"2019-11-26 16:12:11","2019-11-26 16:23:16",{"id":178,"category_id":44,"title":179,"keywords":180,"description":181,"image_url":6,"url":182,"hits":183,"is_recommend":73,"is_top":73,"create_time":184,"update_time":185},113,"在CentOS 7中添加命令自动补全功能","命令自动补全,centos","在CentOS 7中，默认情况下并不会安装命令补全包，需要手动安装才能使用命令补全功能。以下是在CentOS 7中安装命令补全包的方法：1. bash-completion：这是一个针对Bash shell的命令补全软件包，可以提供对系统命令、用户自定义命令和文件路径的自动补全功能。可以通过以下命令安装：```sudo yum install bash-completion```安装完成后，需要在/etc/profile配置文件中添加以下内容：```if [ -f /etc/bash_compl","/article/113",14948,"2023-05-16 10:54:01","2023-05-16 10:57:28",{"id":187,"category_id":44,"title":188,"keywords":189,"description":190,"image_url":6,"url":191,"hits":192,"is_recommend":53,"is_top":73,"create_time":193,"update_time":194},94,"Centos7 安装 openvas ","openvas,开放式漏洞评估系统，installing openvas centos-7","一、描述OpenVAS，即开放式漏洞评估系统，是一个用于评估目标漏洞的杰出框架。功能十分强大，最重要的是，它是“开源”的——就是免费的意思啦～它与著名的Nessus“本是同根生”，在Nessus商业化之后仍然坚持开源，号称“当前最好用的开源漏洞扫描工具”。最新版的Kali Linux(kali 3.0)不再自带OpenVAS了，所以我们要自己部署OpenVAS漏洞检测系统。其核心部件是一个服务器，包括一套网络漏洞测试程序，可以检测远程系统和应用程序中的安全问题。但是它的最常用用途是检测目标网络或","/article/94",14690,"2019-01-14 17:43:42","2019-01-14 18:16:36",{"id":196,"category_id":44,"title":197,"keywords":198,"description":199,"image_url":6,"url":200,"hits":201,"is_recommend":73,"is_top":73,"create_time":202,"update_time":203},99,"Centos7 利用iptables防止nmap工具防端口扫描","iptables","一、Nmap介绍       Nmap（NetworkMapper）是一款开放源代码的网络探测和安全审核工具。它用于快速扫描一个网络和一台主机开放的端口，还能使用TCP/IP协议栈特征探测远程主机的操作系统类型。nmap支持很多扫描技术，例如：UDP、TCPconnect()、TCPSYN(半开扫描)、ftp代理(bounce攻击)、反向标志、ICMP、FIN、ACK扫描、圣诞树(XmasTree)、SYN扫描和null扫描。Nmap最初是用于Unix系统","/article/99",14415,"2019-07-09 21:27:00","2019-07-09 21:57:53",{"id":205,"category_id":46,"title":206,"keywords":207,"description":208,"image_url":6,"url":209,"hits":210,"is_recommend":73,"is_top":73,"create_time":211,"update_time":212},61,"Docker 推荐的启动方式","推荐,启动,方式","# cat DockerfileFROM openjdk:8-alpineWORKDIR /ADD ./target/*.jar app.jarEXPOSE 9999COPY docker-entrypoint.sh /RUN chmod +x /docker-entrypoint.shENTRYPOINT [“/docker-entrypoint.sh”]CMD [“java”,”-server”,”-Duser.timezone=GMT+08″,”-jar”,”/app.jar”]# cat","/article/61",14347,"2018-10-22 13:55:47","2018-10-22 13:56:10",{"id":214,"category_id":44,"title":215,"keywords":216,"description":217,"image_url":6,"url":218,"hits":219,"is_recommend":73,"is_top":73,"create_time":220,"update_time":221},107,"Acme.sh 给 SSL 证书自动续期失败的解决方法","HTTP/1.1 200 OK,Server: Bayou Tech Web Srv 1.0,Content-Encoding: none,Content-Length: 5,Content-Type","一、Acme.sh 自动续期失败的症状问题描述如下，续期的时候，提示如下错误：root@dc:~# \"/data/acme.sh\"/acme.sh --cron --home \"/data/acme.sh\" &gt; /dev/null[Sun Nov 10 23:52:17 CST 2020] Error, can not get domain token entry example.com[Sun Nov 10 23:52:17 CST 2020] Please check log file","/article/107",12618,"2021-09-03 10:44:18","2021-09-03 10:46:23",{"id":223,"category_id":44,"title":224,"keywords":225,"description":226,"image_url":6,"url":227,"hits":228,"is_recommend":53,"is_top":73,"create_time":229,"update_time":230},93,"ELK+Filebeat+Kafka+ZooKeeper 构建海量日志分析平台","Filebeat,Kafka","一、说明1.Filebeat是一个日志文件托运工具，在你的服务器上安装客户端后，filebeat会监控日志目录或者指定的日志文件，追踪读取这些文件（追踪文件的变化，不停的读）2.Kafka是一种高吞吐量的分布式发布订阅消息系统，它可以处理消费者规模的网站中的所有动作流数据3.Logstash是一根具备实时数据传输能力的管道，负责将数据信息从管道的输入端传输到管道的输出端；与此同时这根管道还可以让你根据自己的需求在中间加上滤网，Logstash提供里很多功能强大的滤网以满足你的各种应用场景4.El","/article/93",12190,"2018-12-24 16:40:08","2018-12-26 11:53:38",{"id":232,"category_id":46,"title":233,"keywords":234,"description":235,"image_url":6,"url":236,"hits":237,"is_recommend":53,"is_top":73,"create_time":238,"update_time":239},81,"kubernetes 1.12.1 高可用安装之部署Dashboard","安装Dashboard","创建Dashboard需要CoreDNS部署成功之后再安装Dashboard。[root@master01 ~]# wget https://zhl123.com/download/k8s/Dashboard.tgz[root@master01 ~]# tar xf Dashboard.tgz[root@master01 ~]# kubectl create -f Dashboard/[root@master01 Dashboard]# kubectl get svc -n kube-syste","/article/81",12037,"2018-10-26 09:54:41","2018-10-26 16:59:19",{"id":241,"category_id":44,"title":242,"keywords":6,"description":243,"image_url":6,"url":244,"hits":245,"is_recommend":73,"is_top":73,"create_time":246,"update_time":247},100,"用 Nginx 给 Cookie 增加 Secure 和 HttpOnly","在 nginx 的 location 中配置12# 只支持 proxy 模式下设置，SameSite 不需要可删除，如果想更安全可以把 SameSite 设置为 Strictproxy_cookie_path / \"/; httponly; secure; SameSite=Lax\";示例1234567891011121314151617181920212223242526server {    listen 443 ssl http2;    server_name www.zhl123.cn","/article/100",11848,"2019-11-26 16:10:57","2019-11-26 16:23:45",{"id":249,"category_id":44,"title":250,"keywords":251,"description":252,"image_url":6,"url":253,"hits":254,"is_recommend":73,"is_top":73,"create_time":255,"update_time":256},41,"Tomcat 安全配置与性能优化","tomcat，性能优化","1. JVM&nbsp;1.1. 使用 Server JRE 替代JDK。&nbsp;服务器上不要安装JDK，请使用 Server JRE. 服务器上根本不需要编译器，代码应该在Release服务器上完成编译打包工作。&nbsp;理由：一旦服务器被控制，可以防止在其服务器上编译其他恶意代码并植入到你的程序中。&nbsp;1.2. JAVA_OPTS&nbsp;export JAVA_OPTS=\"-server -Xms512m -Xmx4096m &nbsp;-XX:PermSize=64M -","/article/41",11623,"2016-09-01 17:06:36","2018-10-18 17:06:58",[258,266,274,282,290,298,306,314,323,332],{"id":259,"category_id":40,"title":260,"keywords":6,"description":261,"image_url":6,"url":262,"hits":263,"is_recommend":73,"is_top":73,"create_time":264,"update_time":265},123,"Agent Skill 精选集：最值得收藏的 Agent Skills Top 10","如果你正在用 Claude Code 或 Codex，一定对&nbsp;Agent Skills&nbsp;不陌生。通过安装&nbsp;Agent Skills，你可以让这些 AI 助手变得更强——不用每次都解释你的需求，它们直接就知道该怎么做。最近有人在 GitHub 上做了一个采样调查，统计了哪些 Skills 的质量最佳和最受欢迎。我整理了这份&nbsp;Top 10 榜单，加上使用场景和适合人群，帮你快速找到最有用的那几个。Top 10 最受欢迎的 Agent Skills1. Skil","/article/123",270,"2026-01-19 18:49:12","2026-01-19 18:52:01",{"id":267,"category_id":44,"title":268,"keywords":6,"description":269,"image_url":6,"url":270,"hits":271,"is_recommend":73,"is_top":73,"create_time":272,"update_time":273},122,"Nginx性能调优18条黄金法则：支撑10万并发的配置模板","一、概述1.1 背景介绍说实话，Nginx调优这事儿我踩过无数坑。记得2019年双11，我们电商平台流量暴涨，Nginx直接扛不住了，QPS从平时的2万飙升到8万，响应时间从50ms飙到了2秒，最后还是靠临时加机器扛过去的。那次事故之后，我花了大半年时间专门研究Nginx的性能极限，总结出了这20条黄金法则。Nginx作为目前最流行的Web服务器和反向代理，官方数据显示单机可以轻松处理10万+的并发连接。但实际生产环境中，很多同学拿到默认配置就直接上了，结果发现连1万并发都扛不住。问题不在Ngi","/article/122",337,"2026-01-12 11:11:50","2026-01-12 11:12:28",{"id":275,"category_id":46,"title":276,"keywords":6,"description":277,"image_url":6,"url":278,"hits":279,"is_recommend":73,"is_top":73,"create_time":280,"update_time":281},121,"Docker 镜像优化与安全扫描：将镜像体积压缩 70%","1. 适用场景 & 前置条件项目要求适用场景容器化应用镜像体积过大（> 500MB），构建时间长（> 10分钟），存在安全漏洞（CVE高危）OSRHEL/CentOS 7.9+ 或 Ubuntu 20.04+内核Linux Kernel 3.10+软件版本Docker 20.10+ 或 Podman 3.0+，Trivy 0.40+（安全扫描工具）资源规格2C4G（最小）/ 4C8G（推荐），磁盘 50GB+（存储镜像与缓存）网络可访问 Docker Hub/阿里云镜像仓库（","/article/121",309,"2026-01-06 11:54:35","2026-01-06 12:01:59",{"id":283,"category_id":44,"title":284,"keywords":6,"description":285,"image_url":6,"url":286,"hits":287,"is_recommend":73,"is_top":73,"create_time":288,"update_time":289},120,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(二)","五、故障排查和监控5.1 故障排查◆ 5.1.1 日志查看# 查看 Prometheus 日志中的规则评估错误journalctl -u prometheus | grep -i&nbsp;\"rule\"&nbsp;|&nbsp;tail&nbsp;-50# 查看规则评估耗时curl -s http://localhost:9090/api/v1/rules | jq&nbsp;'.data.groups[].rules[] | select(.health != \"ok\")'# Kubernet","/article/120",282,"2026-01-06 11:53:50","2026-01-06 11:54:33",{"id":291,"category_id":44,"title":292,"keywords":6,"description":293,"image_url":6,"url":294,"hits":295,"is_recommend":73,"is_top":73,"create_time":296,"update_time":297},119,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(一)","一、概述1.1 背景介绍在大规模微服务架构下，Prometheus 告警系统往往会陷入一个尴尬的境地：告警太多，运维团队开始选择性忽略；告警太少，真正的故障又可能漏掉。我在某电商平台负责监控体系建设时，团队每天要处理超过 2000 条告警，其中 70% 以上是重复的、关联的或者短暂抖动产生的噪声。Recording Rules 是 Prometheus 提供的预计算机制，可以将复杂的查询表达式预先计算并存储为新的时间序列。通过合理设计 Recording Rules，我们不仅能显著降低 Prom","/article/119",301,"2026-01-06 11:51:58","2026-01-06 11:53:45",{"id":299,"category_id":44,"title":300,"keywords":6,"description":301,"image_url":6,"url":302,"hits":303,"is_recommend":73,"is_top":73,"create_time":304,"update_time":305},118,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(二)","四、最佳实践和注意事项4.1 最佳实践4.1.1 性能优化优化点一：减少 Git 轮询频率# argocd-cm ConfigMapapiVersion:&nbsp;v1kind:&nbsp;ConfigMapmetadata:&nbsp;&nbsp;name:&nbsp;argocd-cm&nbsp;&nbsp;namespace:&nbsp;argocddata:&nbsp;&nbsp;timeout.reconciliation:&nbsp;300s&nbsp;&nbsp;# 默认 180","/article/118",305,"2026-01-06 11:49:00","2026-01-06 11:49:34",{"id":307,"category_id":44,"title":308,"keywords":6,"description":309,"image_url":6,"url":310,"hits":311,"is_recommend":73,"is_top":73,"create_time":312,"update_time":313},117,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(一)","一、概述1.1 背景介绍GitOps 作为云原生时代的运维范式，将 Git 作为基础设施和应用配置的单一事实来源，通过声明式配置和自动化同步机制，实现了配置管理的版本控制、审计追溯和快速回滚。ArgoCD 作为 CNCF 毕业项目，提供了完整的 GitOps 工作流，支持多集群管理、RBAC 权限控制、SSO 集成等企业级特性。结合 Kustomize 的配置管理能力，能够优雅地解决多环境配置差异、敏感信息管理、配置复用等问题。在传统的 CI/CD 流程中，往往由 CI 工具直接执行 kubec","/article/117",310,"2026-01-06 11:45:03","2026-01-06 11:48:56",{"id":315,"category_id":40,"title":316,"keywords":317,"description":318,"image_url":6,"url":319,"hits":320,"is_recommend":73,"is_top":73,"create_time":321,"update_time":322},116,"运维部门年度2025工作总结与2026工作规划应该如何写？","运维部门年度2025工作总结,2026工作规划","2025年，运维部在公司“数字化转型深化”战略引领下，以“稳定为基、效率为纲、安全为盾、创新为翼”为核心导向，全面支撑核心业务系统运行、推动技术架构迭代、强化团队能力建设。 全年实现核心业务系统可用性99.985%，较2024年提升0.02个百分点；故障平均恢复时间（MTTR）从42分钟压缩至29分钟，下降31%；云资源成本同比降低16.8%，自动化运维覆盖率从65%提升至83%，未发生重大生产安全事故，圆满完成年度目标。现将全年工作及2026年规划汇报如下：2025年核心工作成果（数","/article/116",297,"2026-01-06 11:20:58","2026-01-06 11:44:04",{"id":324,"category_id":40,"title":325,"keywords":326,"description":327,"image_url":6,"url":328,"hits":329,"is_recommend":73,"is_top":73,"create_time":330,"update_time":331},115,"Kubernetes 100个常用命令","100 个 Kubectl 命令","这篇文章是关于使用 Kubectl 进行 Kubernetes 诊断的指南。列出了 100 个 Kubectl 命令，这些命令对于诊断 Kubernetes 集群中的问题非常有用。这些问题包括但不限于：•&nbsp;集群信息•&nbsp;Pod 诊断•&nbsp;服务诊断•&nbsp;部署诊断•&nbsp;网络诊断•&nbsp;持久卷和持久卷声明诊断•&nbsp;资源使用情况•&nbsp;安全和授权•&nbsp;节点故障排除•&nbsp;其他诊断命令：文章还提到了许多其他命令，如资源扩展和自动扩","/article/115",3642,"2023-11-02 14:09:30","2023-11-02 14:10:05",{"id":178,"category_id":44,"title":179,"keywords":180,"description":181,"image_url":6,"url":182,"hits":183,"is_recommend":73,"is_top":73,"create_time":184,"update_time":185},1784716028642]