You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用mod_wsgi部署Django遇权限错误:无法访问Python虚拟环境

Django + mod_wsgi + pyenv 部署权限问题排查与解决

问题背景

使用mod_wsgi 4.9.4、apache2和pyenv在EC2 Ubuntu 22.04上部署Django应用,通过pyenv创建Python虚拟环境,本地运行正常,collectstatic和migrate命令执行成功,但部署后出现Python初始化权限错误。

Apache虚拟主机配置

<VirtualHost *:80>
        ServerName dev.<domain>.com
        WSGIDaemonProcess dev.<domain>.com python-home=<path><to><pyenv-virtualenv> python-path=<projectdir>
        WSGIProcessGroup dev.<domain>.com
        WSGIApplicationGroup %{GLOBAL}

        ErrorLog "${APACHE_LOG_DIR}/timesheet_internal.log"
        CustomLog "${APACHE_LOG_DIR}/timesheet_internal.log" common
        LogLevel Warn

        Alias /static /var/www/<projectpath>/static
        <Directory /var/www/<projectpath>/static>
            Require all granted
        </Directory>
    
    Alias /.well-known/acme-challenge/ "/var/www/<projectpath>/.well-known/acme-challenge/"
    <Directory "/var/www/<projectpath>/">
        AllowOverride None
        Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec
        Require method GET POST DELETE PATCH OPTIONS
    </Directory>

    WSGIScriptAlias / /var/www/<path>/wsgi.py
    <Directory "/var/www/<path>/wsgi.py">
      Require all granted
    </Directory>
</VirtualHost>

错误日志

[Mon Jun 12 14:17:51.520596 2023] [wsgi:warn] [pid 1224676:tid 140062563575680] (13)Permission denied: mod_wsgi (pid=1224676): Unable to stat Python home /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env. Python interpreter may not be able to be initialized correctly. Verify the supplied path and access permissions for whole of the path.
Python path configuration:
  PYTHONHOME = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env'
  PYTHONPATH = (not set)
  program name = 'python3'
  isolated = 0
  environment = 1
  user site = 1
  safe_path = 0
  import site = 1
  is in build tree = 0
  stdlib dir = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11'
  sys._base_executable = '/usr/bin/python3'
  sys.base_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env'
  sys.base_exec_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env'
  sys.platlibdir = 'lib'
  sys.executable = '/usr/bin/python3'
  sys.prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env'
  sys.exec_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env'
  sys.path = [
    '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python311.zip',
    '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11',
    '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11/lib-dynload',
  ]
Fatal Python error: init_fs_encoding: failed to get the Python codec of the filesystem encoding
Python runtime state: core initialized
ModuleNotFoundError: No module named 'encodings'

Current thread 0x00007f62db592780 (most recent call first):
  <no Python frame>

已尝试操作

  • 确认虚拟环境权限为ubuntu:ubuntu
  • 安装libpython3.11-minimal
  • 重装虚拟环境、Python版本及相关组件

解决方案

1. 修复目录权限链

Apache运行用户(默认是www-data)需要对pyenv虚拟环境的整个路径链拥有读取和执行权限,而非仅虚拟环境目录本身:

# 允许www-data进入ubuntu用户主目录
chmod o+x /home/ubuntu
# 给pyenv版本目录和虚拟环境目录添加读取+执行权限
chmod -R o+rx /home/ubuntu/.pyenv/versions/3.11.3
chmod -R o+rx /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env

更安全的方式是将www-data加入ubuntu用户组:

usermod -aG ubuntu www-data
# 刷新目录组权限
chmod g+rx /home/ubuntu
chmod -R g+rx /home/ubuntu/.pyenv/versions/3.11.3

2. 明确指定Python解释器路径

在WSGIDaemonProcess中直接指定虚拟环境的Python解释器,避免路径解析问题:

WSGIDaemonProcess dev.<domain>.com python-path=<projectdir> python-home=<path-to-pyenv-virtualenv> python-interpreter=/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/bin/python3.11

3. 检查SELinux状态(若启用)

Ubuntu默认禁用SELinux,若手动启用需给虚拟环境目录添加正确上下文:

semanage fcontext -a -t httpd_sys_content_t "/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env(/.*)?"
restorecon -Rv /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env

4. 验证Apache运行用户

确认Apache实际运行用户:

ps aux | grep apache2

若为非www-data用户,需调整对应目录权限为该用户可访问。

验证步骤

修改配置和权限后重启Apache:

sudo systemctl restart apache2

查看日志确认错误是否消除:

tail -f ${APACHE_LOG_DIR}/timesheet_internal.log

内容的提问来源于stack exchange,提问作者Balaji Gandham

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 12:43:20