≡articles //snippets ./categories $uses ~about /search
$ find ./snippets/ -type f

代码片段

踩坑时记下的命令和配置。点开可以复制。

nginxWeb 服务器

#21nginx -t 没报错,浏览器却说证书和域名对不上。请求进了 default_server,拿的是别的站的证书.conf
# 看浏览器实际拿到的是哪张证书
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
  | openssl x509 -noout -subject -ext subjectAltName

# 对应 server 块要写全域名,并且 listen 443 ssl
server_name example.com www.example.com;
#12limit_req 把正常用户也拦了,burst 和 nodelay 这样配.conf
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;

location / {
    limit_req zone=perip burst=20 nodelay;   # 允许突发 20 个,不排队
    limit_req_status 429;
}
详见:Nginx 限流实战:用 limit_req 防 CC 攻击,误伤正常用户怎么办?
#11/health 的访问日志关不掉。别在 if 里写 access_log,用 map 加 if=.conf
# 不要在 if 里写 access_log,用 map + if= 参数
map $request_uri $loggable {
    ~^/health  0;
    default    1;
}
access_log /var/log/nginx/access.log combined if=$loggable;
#10proxy_pass 末尾有没有斜杠,后端收到的路径不一样.conf
# 请求 /api/users,location /api/ { ... }
proxy_pass http://127.0.0.1:3000;    # 后端收到 /api/users
proxy_pass http://127.0.0.1:3000/;   # 后端收到 /users(/api/ 被替换掉)
#9接口返回的 JSON 没压缩,gzip_types 里漏了 application/json.conf
gzip on;
gzip_types text/css application/javascript application/json image/svg+xml;
#8proxy_pass 到 OSS 域名,隔几天就 502 一次,要配 resolver.conf
# 域名写死在 proxy_pass 里只在启动时解析一次,IP 变了就 502
resolver 223.5.5.5 valid=300s;
set $oss bucket.oss-cn-hangzhou.aliyuncs.com;
proxy_pass https://$oss;
#4安全扫描报 TLS 1.0/1.1,只留 1.2 和 1.3.conf
ssl_protocols TLSv1.2 TLSv1.3;

mysql数据库

#22wp_options 表涨到 500MB,大头是 autoload=yes 的过期 transient.sql
-- 找出最大的自动加载项(WP 6.6 起 autoload 值是 on/off)
SELECT option_name, LENGTH(option_value) AS bytes
FROM wp_options WHERE autoload IN ('yes','on')
ORDER BY bytes DESC LIMIT 20;

UPDATE wp_options SET autoload = 'off' WHERE option_name = '某个大选项';
#14千万行的表 COUNT(*) 要跑 3 分钟,只要大概数就看 EXPLAIN.sql
-- 只要个大概数,不用全表扫描
SELECT TABLE_ROWS FROM information_schema.TABLES
WHERE TABLE_SCHEMA = 'db' AND TABLE_NAME = 'orders';
-- 或 EXPLAIN SELECT COUNT(*) FROM orders;  看 rows 列
#13半夜报 Too many connections,wait_timeout 从 28800 改成 600.sql
SET GLOBAL wait_timeout = 600;
-- 永久生效:写进 my.cnf 的 [mysqld]
-- wait_timeout = 600
#6ALTER TABLE 锁了 4 小时,后来改用 pt-online-schema-change.sql
pt-online-schema-change \
  --alter "ADD COLUMN status TINYINT NOT NULL DEFAULT 0" \
  D=db,t=orders --execute
#5innodb_buffer_pool_size 从 256M 调到 512M 之后,慢查询日志没再出现.sql
# my.cnf [mysqld]
innodb_buffer_pool_size = 512M
# 检查命中率:Innodb_buffer_pool_reads 越小越好
# SHOW GLOBAL STATUS LIKE 'Innodb_buffer_pool_read%';
详见:MySQL 慢查询排查实录:从 PROCESSLIST 到 EXPLAIN 完整流程

bash脚本 & 命令

#23df -h 说磁盘满了,du -sh 找不到大文件:删掉的文件还被进程占着.sh
# 找出还占着空间的已删除文件
lsof +L1
# 重启对应进程,或者直接清空句柄
: > /proc/<PID>/fd/<FD>
#16grep 搜二进制文件没结果,加 -a 当文本搜.sh
grep -a 'keyword' file.log
#15脚本手动能跑,放进 crontab 就不跑:没设 SHELL 和 PATH.sh
# crontab -e 顶部加上
SHELL=/bin/bash
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
详见:systemd timer 替代 cron 实战:从 crontab 静默清空到全量迁移
#7压缩 30 天前的日志,那次腾出了 8G.sh
find /var/log/app -name '*.log' -mtime +30 -print0 | xargs -0 gzip
#3每天用 ossutil sync 把 WordPress 增量备份到阿里云 OSS.sh
ossutil sync /www/wwwroot/example.com oss://bucket/backup/ --update

phpPHP / WordPress

#24WP-Cron 每次打开页面都会触发,换成 systemd timer 后 CPU 降了 40%.php
// wp-config.php
define('DISABLE_WP_CRON', true);

# 再用 systemd timer 每 5 分钟跑一次:
wp cron event run --due-now --path=/www/wwwroot/example.com
详见:WP-Cron 替代方案:systemd timer 和宝塔计划任务实战
#18file_get_contents() 请求外部接口卡住,default_socket_timeout 默认是 60 秒.php
$ctx = stream_context_create(['http' => ['timeout' => 5]]);
$body = file_get_contents($url, false, $ctx);
#17上传提示文件太大。改了 upload_max_filesize,post_max_size 也要改.php
; php.ini —— 两个都要改,post_max_size 要大于等于 upload_max_filesize
upload_max_filesize = 64M
post_max_size = 64M
#2WordPress 搬家后全站 404,重新保存一次固定链接.php
wp rewrite flush --hard
# nginx 还要有这一行
# location / { try_files $uri $uri/ /index.php?$args; }

git版本控制

#25vendor 写进 .gitignore 还在被跟踪,之前 add 过,要先 git rm --cached.sh
git rm -r --cached vendor
git commit -m "stop tracking vendor"
#19commit 完发现漏了个文件,用 --amend --no-edit 补进去.sh
git add 漏掉的文件
git commit --amend --no-edit
# 已经 push 过就别这么做
#1git push 被拒,remote 还是旧服务器的 IP.sh
git remote -v
git remote set-url origin git@新服务器:repo.git

linux系统 & 容器

#26服务器时间差 8 小时,时区改成 Asia/Shanghai.sh
timedatectl set-timezone Asia/Shanghai
#20容器里 apt update 很慢,换成阿里云的源.sh
# Debian 12 镜像(bookworm 起源在 debian.sources)
sed -i 's/deb.debian.org/mirrors.aliyun.com/g' /etc/apt/sources.list.d/debian.sources
apt update