You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ansible部署PostgreSQL 10备库启动集群时归档命令因rsync权限拒绝失败

PostgreSQL 10 Standby Startup: rsync Permission Denied When Using Ansible

Let's break down your problem and walk through the likely fixes. You're hitting a Permission denied error for rsync when starting your PostgreSQL standby via Ansible, but the exact same command works fine when you manually switch to the postgres user. This usually boils down to differences in the execution context between Ansible and your interactive shell, or subtle permission/configuration issues.

1. Verify rsync Executable Permissions

First, make sure the rsync binary itself is accessible to all users, including postgres:

ls -l /bin/rsync

You should see permissions like -rwxr-xr-x (read/write/execute for owner, read/execute for group and others). If not, fix the permissions with:

sudo chmod 755 /bin/rsync

2. Fix Ansible Execution Context (Environment Variables)

When you manually run sudo su - postgres, you're loading the full postgres user environment (including ~/.bash_profile, ~/.bashrc). But Ansible's become_user by default uses a minimal shell environment that might skip these setup files. Try switching to the shell module instead of command, and explicitly load the user's profile:

- name: Start PostgreSQL standby cluster
  shell: '. ~postgres/.bash_profile && pg_ctl -D {{ data_dir }} start'
  when: inventory_hostname == (groups['pgdb']|sort())[1]
  become: yes
  become_user: postgres

This ensures the same environment as your manual login is used when starting the cluster.

3. Check SELinux Restrictions

If your system has SELinux enabled (check with getenforce), it might be blocking the postgres user from executing rsync. Try temporarily disabling SELinux to test:

sudo setenforce 0

If the error goes away, create a permanent SELinux policy to allow this action:

# Capture denial logs and generate a policy module
sudo audit2allow -a -M postgres_rsync
# Install the policy
sudo semodule -i postgres_rsync.pp

4. Confirm PostgreSQL Standby Archive Configuration

Wait a second—your recovery.conf defines a restore_command (for fetching archives from the primary), but the error mentions an archive_command (used to ship archives off the current node). If this is a basic standby (not a cascading standby), you likely don't need archiving enabled here:

  • Open the standby's postgresql.conf and set archive_mode = off
  • If you do need archiving on the standby, double-check the archive_command is correct, and ensure the postgres user has SSH key-based auth set up for the remote host (if rsyncing to another machine)

5. Check PostgreSQL User's Shell

Ensure the postgres user has a valid login shell (not /sbin/nologin), which might be preventing Ansible from properly executing commands in a full environment:

cat /etc/passwd | grep postgres

If the shell is /sbin/nologin, update it to bash:

sudo usermod -s /bin/bash postgres

6. Switch Ansible Become Method to Sudo

By default, Ansible uses su for privilege escalation. Try switching to sudo instead, which often handles user environments more consistently:
Either add this to your ansible.cfg:

become_method = sudo

Or specify it directly in your task:

- name: Start PostgreSQL standby cluster
  command: pg_ctl -D {{ data_dir }} start
  when: inventory_hostname == (groups['pgdb']|sort())[1]
  become: yes
  become_user: postgres
  become_method: sudo

内容的提问来源于stack exchange,提问作者JPNagarajan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 19:19:07