Ansible部署PostgreSQL 10备库启动集群时归档命令因rsync权限拒绝失败
Let's break down your problem and walk through the likely fixes. You're hitting a Permission denied error for rsync when starting your PostgreSQL standby via Ansible, but the exact same command works fine when you manually switch to the postgres user. This usually boils down to differences in the execution context between Ansible and your interactive shell, or subtle permission/configuration issues.
1. Verify rsync Executable Permissions
First, make sure the rsync binary itself is accessible to all users, including postgres:
ls -l /bin/rsync
You should see permissions like -rwxr-xr-x (read/write/execute for owner, read/execute for group and others). If not, fix the permissions with:
sudo chmod 755 /bin/rsync
2. Fix Ansible Execution Context (Environment Variables)
When you manually run sudo su - postgres, you're loading the full postgres user environment (including ~/.bash_profile, ~/.bashrc). But Ansible's become_user by default uses a minimal shell environment that might skip these setup files. Try switching to the shell module instead of command, and explicitly load the user's profile:
- name: Start PostgreSQL standby cluster shell: '. ~postgres/.bash_profile && pg_ctl -D {{ data_dir }} start' when: inventory_hostname == (groups['pgdb']|sort())[1] become: yes become_user: postgres
This ensures the same environment as your manual login is used when starting the cluster.
3. Check SELinux Restrictions
If your system has SELinux enabled (check with getenforce), it might be blocking the postgres user from executing rsync. Try temporarily disabling SELinux to test:
sudo setenforce 0
If the error goes away, create a permanent SELinux policy to allow this action:
# Capture denial logs and generate a policy module sudo audit2allow -a -M postgres_rsync # Install the policy sudo semodule -i postgres_rsync.pp
4. Confirm PostgreSQL Standby Archive Configuration
Wait a second—your recovery.conf defines a restore_command (for fetching archives from the primary), but the error mentions an archive_command (used to ship archives off the current node). If this is a basic standby (not a cascading standby), you likely don't need archiving enabled here:
- Open the standby's
postgresql.confand setarchive_mode = off - If you do need archiving on the standby, double-check the
archive_commandis correct, and ensure thepostgresuser has SSH key-based auth set up for the remote host (if rsyncing to another machine)
5. Check PostgreSQL User's Shell
Ensure the postgres user has a valid login shell (not /sbin/nologin), which might be preventing Ansible from properly executing commands in a full environment:
cat /etc/passwd | grep postgres
If the shell is /sbin/nologin, update it to bash:
sudo usermod -s /bin/bash postgres
6. Switch Ansible Become Method to Sudo
By default, Ansible uses su for privilege escalation. Try switching to sudo instead, which often handles user environments more consistently:
Either add this to your ansible.cfg:
become_method = sudo
Or specify it directly in your task:
- name: Start PostgreSQL standby cluster command: pg_ctl -D {{ data_dir }} start when: inventory_hostname == (groups['pgdb']|sort())[1] become: yes become_user: postgres become_method: sudo
内容的提问来源于stack exchange,提问作者JPNagarajan

