温馨提示×

debian ulimit用户级怎么配

小樊
49
2026-09-25 06:01:43
栏目: 智能运维

在 Debian(以及大多数 Linux 发行版)中,用户级 ulimit 通常通过 PAM + limits.conf 或 systemd 用户/服务配置 来设置。下面按常见场景说明。


一、通过 /etc/security/limits.conf(最常用)

1️⃣ 修改配置文件

编辑:

sudo nano /etc/security/limits.conf

2️⃣ 配置语法

<domain> <type> <item> <value>

示例(用户 www):

www soft nofile 65535
www hard nofile 65535

常用项:

  • soft:软限制(用户可自己改)
  • hard:硬限制(不能超过)
  • nofile:打开文件数
  • nproc:进程数
  • stack:栈大小
  • memlock:锁内存

示例(所有用户):

* soft nofile 10240
* hard nofile 65535

3️⃣ 确保 PAM 生效

Debian 需要 PAM 模块支持:

检查以下文件是否包含:

grep pam_limits /etc/pam.d/login
grep pam_limits /etc/pam.d/sshd

通常应有:

session required pam_limits.so

如果没有,手动添加。


4️⃣ 重新登录生效

logout

或

su - 用户名

验证:

ulimit -a
ulimit -n

二、只对某个 systemd 服务限制(推荐服务用)

如果是服务(如 nginx、mysql):

1️⃣ 编辑 service

systemctl edit nginx

2️⃣ 添加

[Service]
LimitNOFILE=65535
LimitNPROC=4096

3️⃣ 重载

systemctl daemon-reload
systemctl restart nginx

三、只对当前 shell 临时设置

ulimit -n 65535

⚠️ 重启或退出 shell 后失效。


四、用户级 systemd(user 模式)

如果是 systemctl --user:

systemctl --user edit xxx
[Service]
LimitNOFILE=65535

五、常见问题

❌ 修改后不生效?

  • 是否重新登录?
  • 是否使用 systemd 登录(图形/SSH)?
  • 是否被 service 覆盖?

❌ root 不生效?

limits.conf 对 root 默认不限制,需要显式写:

root soft nofile 65535
root hard nofile 65535

六、推荐生产配置示例

* soft nofile 65535
* hard nofile 65535
* soft nproc 4096
* hard nproc 4096

如果你能告诉我:

  • 是 普通用户 / 服务 / Docker / systemd
  • 想限制 nofile / nproc / 内存

我可以给你更精确的配置。

0 踩