在 Debian 里,ulimit 用来限制单个 shell / 进程的资源使用(如打开文件数、进程数、内存等)。按“作用范围”不同,设置方式也不一样。下面按常见场景说明。
直接在终端执行:
ulimit -n 65536 # 打开文件数
ulimit -u 4096 # 最大进程数
ulimit -c unlimited # core dump 大小
查看当前限制:
ulimit -a
⚠️ 只对当前 shell 及其子进程有效。
/etc/security/limits.conf编辑:
sudo vim /etc/security/limits.conf
示例(针对用户 www):
www soft nofile 65536
www hard nofile 65536
www soft nproc 4096
www hard nproc 4096
格式说明:
<用户> <soft/hard> <资源类型> <值>
常见资源:
nofile:打开文件数nproc:进程数core:core 文件大小memlock:锁内存✅ 需要重新登录才生效
⚠️ 依赖 PAM,确保:
grep pam_limits /etc/pam.d/common-session
grep pam_limits /etc/pam.d/common-session-noninteractive
有:
session required pam_limits.so
limits.conf 对 systemd 服务不生效!
例如 Nginx / MySQL / Docker:
systemctl edit nginx
[Service]
LimitNOFILE=65536
LimitNPROC=4096
然后:
systemctl daemon-reload
systemctl restart nginx
查看:
cat /proc/$(pgrep nginx | head -1)/limits
查看:
cat /proc/sys/fs/file-max
临时:
sysctl -w fs.file-max=1000000
永久:
sudo vim /etc/sysctl.conf
fs.file-max = 1000000
sysctl -p
limits.conf 默认对 root 不生效,需要:
root soft nofile 65536
root hard nofile 65536
或 systemd 中显式设置。
❌ ulimit -n 1000000 报错
→ 超过 hard limit 或内核限制
❌ 修改后不生效
→ 没重新登录 / systemd 服务没配
❌ Docker 容器里不生效
→ 需在宿主机或 docker run 加:
docker run --ulimit nofile=65536:65536
如果你能说下 具体场景(比如:Nginx?MySQL?Docker?普通用户?),我可以给你一份精确配置。