perf(deploy): 边缘 nginx 承压调优与连接池/PG 参数(P0-2/P0-3)

- 主配置 nginx.conf 进镜像(worker_connections 16384 + rlimit 65536 + gzip
  + 带上游耗时的访问日志):官方默认 1024×4=4096 连接硬顶是 1w 并发第一道墙
- admin.conf:upstream keepalive 64(proxy_http 1.1 + Connection "")、
  /public/ /v2-api/ 限流 50r/s burst 200(429)、代理超时 5s/30s、
  /uploads/ /assets/ 30d 缓存头;admin.v2.conf 的 /v2/h5/ 哈希产物长缓存
- compose:PG 显式参数(statement_timeout=10s/max_connections=200/
  shared_buffers=512MB)、DATABASE_URL connection_limit=50&pool_timeout=3
  (单位秒,勿写毫秒;勿加 statement_cache_size=0)、admin ulimits nofile 65536
- 部署注意:主配置走镜像须 rebuild;PG 参数重启前按全局约束 pg_dump+快照存档
This commit is contained in:
yeuimu
2026-09-03 03:40:28 +08:00
parent ab79325ab0
commit 9f856858e2
5 changed files with 114 additions and 7 deletions
+23 -1
View File
@@ -9,6 +9,20 @@ services:
v2-postgres:
image: postgres:16-alpine
restart: unless-stopped
# 性能整改 P0-3plans/refactor/public-capacity-10k-refactor.md):
# - statement_timeout=10s:慢查询不无限期占住连接(池排队由此可控);
# - max_connections=200:为未来 api 副本/同步 worker 预留(单 api 池 50);
# - shared_buffers/effective_cache_size14GB 内存机的工作集调优(数据 ~几十 MB,512MB 充裕)。
# 部署注意(全局约束 §1):改参数需重启容器(秒级中断)——先 pg_dump -Fc + 配置快照
# 落 deploy/backups/<时间戳>/ 再低峰 force-recreate。
command:
[
"postgres",
"-c", "statement_timeout=10000",
"-c", "max_connections=200",
"-c", "shared_buffers=512MB",
"-c", "effective_cache_size=1536MB",
]
environment:
POSTGRES_USER: inkreach
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD}
@@ -32,7 +46,10 @@ services:
environment:
NODE_ENV: production
PORT: 3001
DATABASE_URL: postgresql://inkreach:${POSTGRES_PASSWORD}@v2-postgres:5432/inkreach
# 性能整改 P0-3:池上限 50 < PG max_connections 200(同步/运维连接留余量);
# pool_timeout 单位是秒(Prisma 默认 10)——池耗尽 3s 快速失败而非挂 10s。
# 不要加 statement_cache_size=0pgbouncer 专用,直连禁 prepared statement 反而拖慢)。
DATABASE_URL: postgresql://inkreach:${POSTGRES_PASSWORD}@v2-postgres:5432/inkreach?connection_limit=50&pool_timeout=3
JWT_SECRET: ${JWT_SECRET}
CORS_ORIGINS: "*"
# 激活 product-family 聚合公开读路径
@@ -65,6 +82,11 @@ services:
ports:
- "80:80"
- "443:443"
# 性能整改 P0-24 worker × 16384 连接 + 上游 keepalive 需要容器 fd 预算匹配
ulimits:
nofile:
soft: 65536
hard: 65536
volumes:
- ./nginx/admin.conf:/etc/nginx/conf.d/default.conf:ro
- ./certbot/www:/var/www/certbot:ro