Debian下NGINX+Gunicorn+Flask部署:Socket文件权限拒绝问题
问题:Nginx + Gunicorn部署Flask API时Unix Socket权限拒绝
补充说明:使用Debian系统
更新:已找到解决方案(见下方)
花了约5小时尝试部署,始终无法成功。尝试通过NGINX + Gunicorn运行Flask API,但持续遇到Socket文件权限拒绝问题,试过各类帖子中的方案均无效。
相关配置文件
/etc/systemd/system/app.service
[Unit] Description=Gunicorn instance to serve licenses-server Flask app After=network.target [Service] User=<root> Group=www-data WorkingDirectory=/home/<root>/services/licenses-server Environment="PATH=/home/<root>/<app>/<app>/bin:/user/bind:/bin" ExecStart=/home/<root>/services/licenses-server/licenses/bin/gunicorn --workers 3 --bind unix:/var/sockets/licenses.sock -m 007 wsgi:app PrivateTmp=No [Install] WantedBy=multi-user.target
/etc/nginx/sites-available/app.conf
server { listen 80; server_name mydomain.com www.mydomain.com; location / { try_files $uri $uri/ @flask; } location @flask { proxy_pass http://unix:/var/sockets/licenses.sock; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X_Forwared-For $proxy_add_x_forwarded_for; } }
/var/log/nginx/error.log
2024/09/19 23:46:05 [crit] 17111#17111: *1 connect() to unix:/var/sockets/<my_sock>.sock failed (13: Permission denied) while connecting to upstream, client: 172.17.0.2, server: mydomain.com, request: "GET <my_url> HTTP/1.1", upstream: "http://unix:/var/sockets/licenses.sock:<my_url>", host: "mydomain.com"
权限信息
$ ls -l / ... drwxrwxr-x 13 root www-data 4096 Sep 19 23:12 var $ ls -l /var ... drwxrwxrwx 2 root www-data 4096 Sep 19 23:43 sockets $ ls -l /var/sockets ... srwxrwx--- 1 <root> www-data 0 Sep 19 23:45 licenses.sock
/etc/nginx/nginx.conf
user nginx; worker_processes auto; error_log /var/log/nginx/error.log notice; pid /var/run/nginx.pid; events { worker_connections 1024; } http { include /etc/nginx/mime.types; default_type application/octet-stream; log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"'; access_log /var/log/nginx/access.log main; sendfile on; #tcp_nopush on; keepalive_timeout 65; #gzip on; include /etc/nginx/conf.d/*.conf; include /etc/nginx/sites-available/licenses-server.conf; }
/etc/nginx/conf.d/default.conf
server { listen 80; server_name localhost; access_log /var/log/nginx/host.access.log main; #location / { #root /usr/share/nginx/html; #index index.html index.htm; #} #error_page 404 /404.html; # redirect server error pages to the static page /50x.html # #error_page 500 502 503 504 /50x.html; #location = /50x.html { #root /usr/share/nginx/html; #} # proxy the PHP scripts to Apache listening on 127.0.0.1:80 # #location ~ \.php$ { # proxy_pass http://127.0.0.1; #} # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 # #location ~ \.php$ { # root html; # fastcgi_pass 127.0.0.1:9000; # fastcgi_index index.php; # fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; # include fastcgi_params; #} # deny access to .htaccess files, if Apache's document root # concurs with nginx's one # #location ~ /\.ht { # deny all; #} }
解决方案
问题核心:Nginx以nginx用户运行,但socket文件所属组是www-data,且socket权限为srwxrwx---,仅所属用户和组内用户可访问,nginx用户不在www-data组中,因此被拒绝。
执行以下步骤解决:
将nginx用户加入www-data组
sudo usermod -aG www-data nginx重启Nginx服务使变更生效
sudo systemctl restart nginx(可选)验证用户组配置
检查nginx用户是否已加入www-data组:groups nginx输出中应包含
www-data。
若问题仍存在,可重启Gunicorn服务确保socket权限正确加载:
sudo systemctl restart app.service
内容的提问来源于stack exchange,提问作者Gabriel Assis
相关产品推荐
相关产品推荐

