使用Ansible配置RPM仓库时遭遇SELinux错误问题求助
问题:Ansible yum_repository任务因SELinux上下文配置错误执行失败
我在给RHEL8服务器部署Shibboleth RPM包时,执行以下Ansible任务失败:
- name: Add the shibboleth Repository configuration yum_repository: name: security_shibboleth description: Shibboleth (CentOS_7) setype: rpm-md mirrorlist: https://shibboleth.net/cgi-bin/mirrorlist.cgi/CentOS_7 gpgkey: - https://shibboleth.net/downloads/service-provider/RPMS/repomd.xml.key - https://shibboleth.net/downloads/service-provider/RPMS/cantor.repomd.xml.key gpgcheck: true enabled: true tags: - shibboleth
报错信息如下:
fatal: [proxy_server_46]: FAILED! => {"changed": false, "cur_context": ["unconfined_u", "object_r", "system_conf_t", "s0"], "gid": 0, "group": "root", "input_was": [null, null, "rpm-md", null], "mode": "0644", "msg": "invalid selinux context: [Errno 22] Invalid argument", "new_context": ["unconfined_u", "object_r", "rpm-md", "s0"], "owner": "root", "path": "/etc/yum.repos.d/security_shibboleth.repo", "secontext": "unconfined_u:object_r:system_conf_t:s0", "size": 312, "state": "file", "uid": 0}
解决方案
错误根源
问题出在setype: rpm-md这一行:
- "rpm-md"不是合法的SELinux类型,从报错日志能看到,Ansible尝试将repo文件的SELinux上下文设置为
unconfined_u:object_r:rpm-md:s0,但这个类型不存在,导致系统返回"无效参数"错误。 /etc/yum.repos.d/目录下的repo文件默认的SELinux类型是system_conf_t,和日志里显示的当前上下文一致。
修复步骤
你可以通过以下两种方式解决:
删除
setype参数(推荐)
Ansible的yum_repository模块会自动为/etc/yum.repos.d/下的文件设置正确的SELinux上下文,不需要手动指定。修改后的任务如下:- name: Add the shibboleth Repository configuration yum_repository: name: security_shibboleth description: Shibboleth (CentOS_7) mirrorlist: https://shibboleth.net/cgi-bin/mirrorlist.cgi/CentOS_7 gpgkey: - https://shibboleth.net/downloads/service-provider/RPMS/repomd.xml.key - https://shibboleth.net/downloads/service-provider/RPMS/cantor.repomd.xml.key gpgcheck: true enabled: true tags: - shibboleth手动指定正确的SELinux类型
如果确实需要手动设置setype,使用合法的类型system_conf_t:- name: Add the shibboleth Repository configuration yum_repository: name: security_shibboleth description: Shibboleth (CentOS_7) setype: system_conf_t mirrorlist: https://shibboleth.net/cgi-bin/mirrorlist.cgi/CentOS_7 gpgkey: - https://shibboleth.net/downloads/service-provider/RPMS/repomd.xml.key - https://shibboleth.net/downloads/service-provider/RPMS/cantor.repomd.xml.key gpgcheck: true enabled: true tags: - shibboleth
内容的提问来源于stack exchange,提问作者elster
相关产品推荐
相关产品推荐

