Common causes
- PHP-FPM or the application server is stopped or has crashed
- fastcgi_pass or proxy_pass points to the wrong socket path, port or PHP version
- The Nginx user cannot access the PHP-FPM socket because of listen.owner or listen.mode
- PHP workers are killed mid-request by a segfault, OOM killer or request_terminate_timeout
- Large response headers (many cookies) overflow fastcgi_buffer_size or proxy_buffer_size
- A CDN such as Cloudflare cannot reach the origin or gets an invalid reply from it
How to fix it
- Read the Nginx error log. Run sudo tail -n 50 /var/log/nginx/error.log and reload the page. The upstream message (connection refused, no such file, prematurely closed, too big header) points to the exact fix.
- Check the backend is running. Run systemctl status php8.3-fpm (match your version) or check your Node/Gunicorn process. Start or restart it with sudo systemctl restart php8.3-fpm.
- Match the socket or port. Compare listen in /etc/php/8.3/fpm/pool.d/www.conf with fastcgi_pass in the Nginx site config. After a PHP upgrade the socket name usually changes, for example from php8.1-fpm.sock to php8.3-fpm.sock.
- Fix socket permissions. In the pool config set listen.owner = www-data, listen.group = www-data and listen.mode = 0660 (use nginx on RHEL-based systems), then restart PHP-FPM.
- Look for crashed workers. Check the PHP-FPM log and dmesg for segfaults or out-of-memory kills. Lower pm.max_children if the server is running out of RAM.
- Raise header buffers if needed. For "upstream sent too big header" increase fastcgi_buffer_size and fastcgi_buffers (or proxy_buffer_size and proxy_buffers), then run sudo nginx -t && sudo systemctl reload nginx.
Nginx server block
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php8.3-fpm.sock;
fastcgi_buffer_size 32k;
fastcgi_buffers 16 16k;
} How to stop it happening again
- Update fastcgi_pass in the same change whenever you upgrade PHP
- Size pm.max_children to available memory so the OOM killer does not reap workers
- Monitor the backend service and restart it automatically with systemd
- Run nginx -t before every reload