You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 24.04下monit监控Rails应用遇ProtectSystem=strict权限问题求助

解决Ubuntu 24.04下Monit与Rails Bundler缓存权限冲突的方案

方案1:使用Systemd Drop-In配置扩展Monit权限(推荐,不影响apt升级)

Systemd允许通过drop-in配置文件覆盖包自带的单元设置,完全不会被apt升级覆盖,是官方推荐的自定义方式:

  • 创建Monit的drop-in配置目录:
    sudo mkdir -p /etc/systemd/system/monit.service.d
    
  • 创建自定义配置文件(比如命名为bundler-path.conf):
    [Service]
    ReadWritePaths=/home/ubuntu/.bundles/pw_bundle
    
  • 重新加载systemd配置并重启Monit:
    sudo systemctl daemon-reload
    sudo systemctl restart monit
    

这个方法既解决了权限问题,又完全遵循systemd最佳实践,不用担心后续Monit升级重置配置。

方案2:给Rails应用单独配置Systemd单元,让Monit监控服务而非直接进程

把Rails应用的启动逻辑移到独立的systemd单元中,Monit只负责监控这个systemd服务,这样Rails进程不会继承Monit的文件系统限制:

  1. 创建Rails应用的systemd单元文件(比如/etc/systemd/system/rails-pw.service):
    [Unit]
    Description=My Rails PW App
    After=network.target
    
    [Service]
    User=ubuntu
    WorkingDirectory=/path/to/your/rails/app
    ExecStart=/bin/bash -lc "bundle exec rails server -e production"
    Restart=always
    Environment="RAILS_ENV=production"
    # 可按需添加其他配置,不受Monit权限限制
    
    [Install]
    WantedBy=multi-user.target
    
  2. 启用并启动该服务:
    sudo systemctl enable --now rails-pw.service
    
  3. 修改Monit配置,替换原有的直接启动进程的规则:
    check process rails-pw with pidfile /path/to/your/rails/app/tmp/pids/server.pid
      start program = "/bin/systemctl start rails-pw.service"
      stop program = "/bin/systemctl stop rails-pw.service"
      if failed port 3000 protocol http then restart
    

这个方案更适合生产环境,将应用进程与监控进程的权限隔离,架构更清晰,也方便后续对Rails应用单独配置资源限制、环境变量等。

方案3:将Bundler缓存迁移到Monit已允许的合法目录

Monit已经开放了/var/lib/monit/作为可写路径(该目录专门用于存储监控相关应用数据),可以把Bundler缓存移到这里,比放到/var/log/更合理:

  • 针对ubuntu用户全局设置Bundler缓存路径:
    bundle config set --global path /var/lib/monit/bundles/pw_bundle
    
  • 或者仅对当前Rails项目单独设置:
    cd /path/to/your/rails/app
    bundle config set path /var/lib/monit/bundles/pw_bundle
    
  • 确保目录权限正确:
    sudo mkdir -p /var/lib/monit/bundles/pw_bundle
    sudo chown ubuntu:ubuntu /var/lib/monit/bundles/pw_bundle
    

这个方案无需修改任何systemd配置,仅调整Bundler的存储路径,轻量化解决问题。

推荐选择

  • 若只是快速解决权限问题,方案1最快捷且不破坏原有架构;
  • 若为长期生产环境部署,方案2更规范,权限隔离更清晰,便于后续维护;
  • 若不想触碰systemd配置,方案3是最轻量化的选择。

内容的提问来源于stack exchange,提问作者brahmana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 01:20:14