使用mod_wsgi部署Django遇权限错误:无法访问Python虚拟环境
Django + mod_wsgi + pyenv 部署权限问题排查与解决
问题背景
使用mod_wsgi 4.9.4、apache2和pyenv在EC2 Ubuntu 22.04上部署Django应用,通过pyenv创建Python虚拟环境,本地运行正常,collectstatic和migrate命令执行成功,但部署后出现Python初始化权限错误。
Apache虚拟主机配置
<VirtualHost *:80> ServerName dev.<domain>.com WSGIDaemonProcess dev.<domain>.com python-home=<path><to><pyenv-virtualenv> python-path=<projectdir> WSGIProcessGroup dev.<domain>.com WSGIApplicationGroup %{GLOBAL} ErrorLog "${APACHE_LOG_DIR}/timesheet_internal.log" CustomLog "${APACHE_LOG_DIR}/timesheet_internal.log" common LogLevel Warn Alias /static /var/www/<projectpath>/static <Directory /var/www/<projectpath>/static> Require all granted </Directory> Alias /.well-known/acme-challenge/ "/var/www/<projectpath>/.well-known/acme-challenge/" <Directory "/var/www/<projectpath>/"> AllowOverride None Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec Require method GET POST DELETE PATCH OPTIONS </Directory> WSGIScriptAlias / /var/www/<path>/wsgi.py <Directory "/var/www/<path>/wsgi.py"> Require all granted </Directory> </VirtualHost>
错误日志
[Mon Jun 12 14:17:51.520596 2023] [wsgi:warn] [pid 1224676:tid 140062563575680] (13)Permission denied: mod_wsgi (pid=1224676): Unable to stat Python home /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env. Python interpreter may not be able to be initialized correctly. Verify the supplied path and access permissions for whole of the path. Python path configuration: PYTHONHOME = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env' PYTHONPATH = (not set) program name = 'python3' isolated = 0 environment = 1 user site = 1 safe_path = 0 import site = 1 is in build tree = 0 stdlib dir = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11' sys._base_executable = '/usr/bin/python3' sys.base_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env' sys.base_exec_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env' sys.platlibdir = 'lib' sys.executable = '/usr/bin/python3' sys.prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env' sys.exec_prefix = '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env' sys.path = [ '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python311.zip', '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11', '/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/lib/python3.11/lib-dynload', ] Fatal Python error: init_fs_encoding: failed to get the Python codec of the filesystem encoding Python runtime state: core initialized ModuleNotFoundError: No module named 'encodings' Current thread 0x00007f62db592780 (most recent call first): <no Python frame>
已尝试操作
- 确认虚拟环境权限为
ubuntu:ubuntu - 安装
libpython3.11-minimal - 重装虚拟环境、Python版本及相关组件
解决方案
1. 修复目录权限链
Apache运行用户(默认是www-data)需要对pyenv虚拟环境的整个路径链拥有读取和执行权限,而非仅虚拟环境目录本身:
# 允许www-data进入ubuntu用户主目录 chmod o+x /home/ubuntu # 给pyenv版本目录和虚拟环境目录添加读取+执行权限 chmod -R o+rx /home/ubuntu/.pyenv/versions/3.11.3 chmod -R o+rx /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env
更安全的方式是将www-data加入ubuntu用户组:
usermod -aG ubuntu www-data # 刷新目录组权限 chmod g+rx /home/ubuntu chmod -R g+rx /home/ubuntu/.pyenv/versions/3.11.3
2. 明确指定Python解释器路径
在WSGIDaemonProcess中直接指定虚拟环境的Python解释器,避免路径解析问题:
WSGIDaemonProcess dev.<domain>.com python-path=<projectdir> python-home=<path-to-pyenv-virtualenv> python-interpreter=/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env/bin/python3.11
3. 检查SELinux状态(若启用)
Ubuntu默认禁用SELinux,若手动启用需给虚拟环境目录添加正确上下文:
semanage fcontext -a -t httpd_sys_content_t "/home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env(/.*)?" restorecon -Rv /home/ubuntu/.pyenv/versions/3.11.3/envs/timesheet_env
4. 验证Apache运行用户
确认Apache实际运行用户:
ps aux | grep apache2
若为非www-data用户,需调整对应目录权限为该用户可访问。
验证步骤
修改配置和权限后重启Apache:
sudo systemctl restart apache2
查看日志确认错误是否消除:
tail -f ${APACHE_LOG_DIR}/timesheet_internal.log
内容的提问来源于stack exchange,提问作者Balaji Gandham
相关产品推荐
相关产品推荐

