踩坑时记下的命令和配置。点开可以复制。
# 看浏览器实际拿到的是哪张证书
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null \
| openssl x509 -noout -subject -ext subjectAltName
# 对应 server 块要写全域名,并且 listen 443 ssl
server_name example.com www.example.com;limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;
location / {
limit_req zone=perip burst=20 nodelay; # 允许突发 20 个,不排队
limit_req_status 429;
}详见:Nginx 限流实战:用 limit_req 防 CC 攻击,误伤正常用户怎么办?# 不要在 if 里写 access_log,用 map + if= 参数
map $request_uri $loggable {
~^/health 0;
default 1;
}
access_log /var/log/nginx/access.log combined if=$loggable;# 请求 /api/users,location /api/ { ... }
proxy_pass http://127.0.0.1:3000; # 后端收到 /api/users
proxy_pass http://127.0.0.1:3000/; # 后端收到 /users(/api/ 被替换掉)gzip on;
gzip_types text/css application/javascript application/json image/svg+xml;# 域名写死在 proxy_pass 里只在启动时解析一次,IP 变了就 502
resolver 223.5.5.5 valid=300s;
set $oss bucket.oss-cn-hangzhou.aliyuncs.com;
proxy_pass https://$oss;ssl_protocols TLSv1.2 TLSv1.3;-- 找出最大的自动加载项(WP 6.6 起 autoload 值是 on/off)
SELECT option_name, LENGTH(option_value) AS bytes
FROM wp_options WHERE autoload IN ('yes','on')
ORDER BY bytes DESC LIMIT 20;
UPDATE wp_options SET autoload = 'off' WHERE option_name = '某个大选项';-- 只要个大概数,不用全表扫描
SELECT TABLE_ROWS FROM information_schema.TABLES
WHERE TABLE_SCHEMA = 'db' AND TABLE_NAME = 'orders';
-- 或 EXPLAIN SELECT COUNT(*) FROM orders; 看 rows 列SET GLOBAL wait_timeout = 600;
-- 永久生效:写进 my.cnf 的 [mysqld]
-- wait_timeout = 600pt-online-schema-change \
--alter "ADD COLUMN status TINYINT NOT NULL DEFAULT 0" \
D=db,t=orders --execute# my.cnf [mysqld]
innodb_buffer_pool_size = 512M
# 检查命中率:Innodb_buffer_pool_reads 越小越好
# SHOW GLOBAL STATUS LIKE 'Innodb_buffer_pool_read%';详见:MySQL 慢查询排查实录:从 PROCESSLIST 到 EXPLAIN 完整流程# 找出还占着空间的已删除文件
lsof +L1
# 重启对应进程,或者直接清空句柄
: > /proc/<PID>/fd/<FD>grep -a 'keyword' file.log# crontab -e 顶部加上
SHELL=/bin/bash
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin详见:systemd timer 替代 cron 实战:从 crontab 静默清空到全量迁移find /var/log/app -name '*.log' -mtime +30 -print0 | xargs -0 gzipossutil sync /www/wwwroot/example.com oss://bucket/backup/ --update// wp-config.php
define('DISABLE_WP_CRON', true);
# 再用 systemd timer 每 5 分钟跑一次:
wp cron event run --due-now --path=/www/wwwroot/example.com详见:WP-Cron 替代方案:systemd timer 和宝塔计划任务实战$ctx = stream_context_create(['http' => ['timeout' => 5]]);
$body = file_get_contents($url, false, $ctx);; php.ini —— 两个都要改,post_max_size 要大于等于 upload_max_filesize
upload_max_filesize = 64M
post_max_size = 64Mwp rewrite flush --hard
# nginx 还要有这一行
# location / { try_files $uri $uri/ /index.php?$args; }git rm -r --cached vendor
git commit -m "stop tracking vendor"git add 漏掉的文件
git commit --amend --no-edit
# 已经 push 过就别这么做git remote -v
git remote set-url origin git@新服务器:repo.gittimedatectl set-timezone Asia/Shanghai# Debian 12 镜像(bookworm 起源在 debian.sources)
sed -i 's/deb.debian.org/mirrors.aliyun.com/g' /etc/apt/sources.list.d/debian.sources
apt update