在 CentOS 上优化 Apache(通常是 httpd),可以从系统层面、Apache 配置、模块、缓存、安全、监控几个方面来做。下面给你一套比较实用、可落地的优化方案(以 CentOS 7/8 + Apache 2.4 为主)。
getenforce
Enforcing 且不影响业务,可保持setenforce 0
ulimit -n
建议至少:
* soft nofile 65535
* hard nofile 65535
写入 /etc/security/limits.conf
net.ipv4.tcp_tw_reuse = 1
net.ipv4.tcp_fin_timeout = 30
net.core.somaxconn = 65535
net.ipv4.tcp_max_syn_backlog = 8192
生效:
sysctl -p
httpd -V | grep -i mpm
使用 prefork
<IfModule mpm_prefork_module>
StartServers 5
MinSpareServers 5
MaxSpareServers 10
MaxRequestWorkers 150
MaxConnectionsPerChild 3000
</IfModule>
使用 event(推荐)
<IfModule mpm_event_module>
StartServers 4
MinSpareThreads 64
MaxSpareThreads 192
ThreadsPerChild 64
MaxRequestWorkers 512
MaxConnectionsPerChild 5000
</IfModule>
修改后:
systemctl restart httpd
查看已加载模块:
httpd -M
常见可关闭:
注释掉对应 LoadModule
KeepAlive On
KeepAliveTimeout 5
MaxKeepAliveRequests 100
Timeout 30
HostnameLookups Off
<IfModule mod_deflate.c>
AddOutputFilterByType DEFLATE text/html text/css application/javascript
</IfModule>
<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType image/jpg "access plus 30 days"
ExpiresByType text/css "access plus 7 days"
ExpiresByType application/javascript "access plus 7 days"
</IfModule>
yum install php-fpm
Apache 配置:
<FilesMatch \.php$>
SetHandler "proxy:fcgi://127.0.0.1:9000"
</FilesMatch>
CustomLog logs/access_log common
或关闭无关日志
确保:
logrotate -d /etc/logrotate.d/httpd
ServerTokens Prod
ServerSignature Off
LimitRequestBody 10485760
<Location /server-status>
SetHandler server-status
Require local
</Location>
ab -n 10000 -c 100 http://localhost/
ServerTokens Prod
KeepAlive On
KeepAliveTimeout 5
Timeout 30
HostnameLookups Off
<IfModule mpm_event_module>
StartServers 4
ThreadsPerChild 64
MaxRequestWorkers 512
</IfModule>
如果你愿意,可以告诉我:
我可以给你一套 针对性配置。