webman生产环境部署需完成五步:一、系统准备(php≥8.0、启用posix/pcntl/event扩展、禁用selinux、确保/dev/shm可用);二、代码部署(上传代码、composer install --no-dev、关闭debug、设置runtime权限);三、nginx反向代理(配置proxy_pass至8787端口、屏蔽敏感路径);四、后台服务管理(以www-data用户启动、配置systemd开机自启);五、安全加固(指定日志路径、禁用display_error、限制open_basedir)。

如果您已完成 Webman 项目的开发并准备将其上线至 Linux 生产环境,则需确保服务稳定、安全、可监控且不暴露调试信息。以下是针对 Webman 在 Linux 系统上完成生产环境部署的完整操作流程:
一、系统与运行时环境准备
Webman 依赖 PHP 运行时及若干扩展,生产环境必须禁用调试模式并启用关键扩展以保障进程稳定性与并发处理能力。
1、确认 PHP 版本为 8.0 或更高版本,执行 php -v 验证。
2、检查必需扩展是否已启用:php -m | grep -E "posix|pcntl|event";若缺失,需在 php.ini 中取消对应扩展前的分号注释,并重启 PHP 服务(如使用 PHP-FPM 则执行 systemctl restart php-fpm)。
3、关闭 SELinux(如启用):执行 setenforce 0 并编辑 /etc/selinux/config 将 SELINUX=enforcing 改为 SELINUX=disabled。
4、确保 /dev/shm 挂载可用且空间充足,Webman 的 event 扩展依赖该内存文件系统。
二、项目代码与依赖部署
生产环境应排除开发依赖,精简体积并提升启动安全性,禁止直接使用开发目录或未清理的缓存。
1、将项目代码(不含 vendor 目录)上传至目标服务器生产路径,例如 /var/www/webman。
2、进入项目根目录,执行 composer install --no-dev --optimize-autoloader 安装仅生产所需依赖并生成优化类映射。
3、修改 config/app.php,将 'debug' => true 显式改为 'debug' => false。
4、设置 runtime/ 目录权限为可写:sudo chown -R www-data:www-data runtime/(Ubuntu/Debian)或 sudo chown -R nginx:nginx runtime/(CentOS/RHEL)。
三、Nginx 反向代理配置
Nginx 作为前置 Web 服务器,负责静态资源响应、HTTPS 终止、请求转发及安全防护,避免 Webman 直接暴露于公网。
1、创建 Nginx 站点配置文件:/etc/nginx/sites-available/webman.conf。
2、写入标准反向代理配置,其中 proxy_pass 必须指向 Webman 启动端口(默认 8787):
server {
listen 80;
server_name example.com;
root /var/www/webman/public;
index index.html index.htm index.php;
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ \.php$ {
fastcgi_pass 127.0.0.1:9000;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
fastcgi_param DOCUMENT_ROOT $realpath_root;
}
location ~ ^/(?:\.|config|app|storage|bootstrap|vendor) {
deny all;
}
location /webman {
proxy_pass http://127.0.0.1:8787;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
}
3、启用配置:sudo ln -sf /etc/nginx/sites-available/webman.conf /etc/nginx/sites-enabled/。
4、测试语法并重载:sudo nginx -t && sudo systemctl reload nginx。
四、Webman 后台服务管理
Webman 基于 Workerman,需以后台守护模式运行,并支持平滑重启与状态监控,避免服务中断。
1、确保 start.php 文件具备执行权限:chmod +x start.php。
2、以非 root 用户(如 www-data)启动服务:sudo -u www-data php start.php start -d。
3、验证进程状态:php start.php status,输出应显示 Workerman[webman] status 及 worker 进程在线数。
4、配置 systemd 服务实现开机自启(创建 /etc/systemd/system/webman.service):
[Unit]
Description=Webman Service
After=network.target
[Service]
Type=simple
User=www-data
WorkingDirectory=/var/www/webman
ExecStart=/usr/bin/php /var/www/webman/start.php start -d
Restart=always
RestartSec=3
[Install]
WantedBy=multi-user.target
5、启用并启动服务:sudo systemctl daemon-reload && sudo systemctl enable --now webman。
五、安全与日志加固
生产环境必须限制敏感路径访问、规范日志输出位置与级别,并防止信息泄露,杜绝攻击面扩大。
1、在 config/server.php 中显式设置日志路径:'log_file' => '/var/log/webman/workerman.log',并确保该目录存在且 www-data 用户可写。
2、禁用错误详情输出:确认 config/app.php 中 'display_error' => false 已生效。
3、在 Nginx 配置中屏蔽敏感路径访问:location ~ ^/(.git|\.env|config/|app/|storage/|bootstrap/|vendor/) { return 403; }。
4、设置 public/ 为唯一 Web 可访问目录,其余代码目录(如 app/、config/)不得置于 Web 根路径下。
5、限制 PHP 脚本执行范围,在 Nginx 的 location ~ \.php$ 块中添加:fastcgi_param PHP_ADMIN_VALUE "open_basedir=/var/www/webman/public:/tmp/";。











