You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 22.04 WSL部署Django至EC2后Apache返回403禁止访问求助

问题描述

在Windows笔记本通过Ubuntu 22.04 WSL部署Django应用,并托管到EC2实例后,用Chrome访问公网IP时出现403禁止错误:

Forbidden, you don't have permission to access this resource. Apache/2.4.52 (Ubuntu) Server at 54.81.101.238 Port 80

已尝试网上(含Stack Overflow)多种方案,包括给Apache授权应用文件夹权限、修改apache2.conf及虚拟主机配置文件,但问题仍未解决。当前虚拟主机配置内容如下:

<VirtualHost *:80>
    #ServerName www.example.com

    ServerAdmin webmaster@localhost
    DocumentRoot /home/rotisary/postly

    #LogLevel info ssl:warn
    ErrorLog  ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined

    #Include conf-available/serve-cgi-bin.conf

    Alias /static /home/rotisary/postly/static
    <Directory /home/rotisary/postly/static>
            Require all granted
    </Directory>

    Alias /media /home/rotisary/postly/media
    <Directory /home/rotisary/postly/media>
            Require all granted
    </Directory>

    <Directory /home/rotisary/postly/postly>
            <Files wsgi.py>
                    Require all granted
            </Files>
    </Directory>

    WSGIScriptAlias / /home/rotisary/postly/postly/wsgi.py
    WSGIDaemonProcess django_app python-path=/home/rotisary/postly:/home>        WSGIProcessGroup django_app
</VirtualHost>
排查与解决建议
  • 修正WSGIDaemonProcess配置语法错误
    你的配置中WSGIDaemonProcess行末尾多了一个多余的>符号,且python-path中的/home路径无意义,修正为:

    WSGIDaemonProcess django_app python-path=/home/rotisary/postly
    

    语法错误会导致WSGI进程无法正确加载Django环境,进而触发权限类报错。

  • 确认Apache用户的目录遍历权限
    执行以下命令检查目录权限,确保Apache运行用户(通常为www-data)能遍历到应用目录:

    ls -ld /home/rotisary
    ls -ld /home/rotisary/postly
    

    目录权限需至少为755,若权限不足,执行:

    chmod 755 /home/rotisary
    chmod -R 755 /home/rotisary/postly
    chown -R www-data:www-data /home/rotisary/postly
    
  • 检查apache2.conf的全局目录限制
    确认apache2.conf中是否存在对/home目录的全局拒绝规则,比如默认配置可能有:

    <Directory /home>
        Require all denied
    </Directory>
    

    若存在,需添加应用目录的例外规则:

    <Directory /home/rotisary/postly>
        Require all granted
    </Directory>
    
  • 验证WSGI脚本文件权限
    确保wsgi.py文件权限正确,执行:

    ls -l /home/rotisary/postly/postly/wsgi.py
    

    文件权限需至少为644,且所属用户/组包含www-data。

  • 重启Apache并查看错误日志
    修改配置后重启Apache服务:

    sudo systemctl restart apache2
    

    实时查看错误日志定位具体问题:

    sudo tail -f /var/log/apache2/error.log
    

    日志中的具体报错信息(如文件读取失败、模块加载错误等)能精准指向问题根源。

内容的提问来源于stack exchange,提问作者Oladotun Kolapo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 10:32:31