RHEL 7.7上Ansible Tower无法获取许可证列表问题求助
Based on your situation—where curl can reach subscription.rhsm.redhat.com but Ansible Tower can’t—the problem almost certainly stems from Ansible Tower’s isolated runtime environment not inheriting your system’s network, proxy, or DNS configurations. Let’s walk through targeted checks and fixes:
1. Configure Proxy Settings for Tower’s Python Virtual Environment
Ansible Tower runs in its own Python virtual environment (/var/lib/awx/venv/awx/), which doesn’t automatically pick up system-wide proxy rules from /etc/rhsm/rhsm.conf. You need to explicitly set proxy for Tower:
Option 1: Add proxy to Tower’s core settings
Edit/etc/tower/settings.pyand insert these lines (replace with your actual proxy details):PROXIES = { 'http': 'http://your-proxy:port/', 'https': 'https://your-proxy:port/', } # Link to your CA certificate to avoid SSL trust issues REQUESTS_CA_BUNDLE = '/usr/share/rhn/RHNS-CA-CERT'Option 2: Set proxy via service environment variables
Edit/etc/sysconfig/awxand add:HTTP_PROXY=http://your-proxy:port/ HTTPS_PROXY=https://your-proxy:port/ NO_PROXY=localhost,127.0.0.1,.your-internal-domain.comRestart Tower to apply changes:
systemctl restart awx
2. Fix CA Certificate Access for Tower’s Virtual Environment
Tower’s Python venv uses its own CA store (managed by the certifi package), which might not include your RHNS certificate. Update it with:
cat /usr/share/rhn/RHNS-CA-CERT >> /var/lib/awx/venv/awx/lib/python3.6/site-packages/certifi/cacert.pem
3. Test Connectivity as the Tower Runtime User
Ansible Tower runs under the awx user, which might have different environment variables than your login user. Switch to awx and validate connectivity directly:
su - awx -s /bin/bash # Test DNS resolution first nslookup subscription.rhsm.redhat.com # Test HTTPS connection with your CA cert curl -v --cacert /usr/share/rhn/RHNS-CA-CERT https://subscription.rhsm.redhat.com/subscription/users/altangerel_g/owners
If this fails, add proxy variables to /var/lib/awx/.bash_profile so the awx user inherits them on startup.
4. Check SELinux Restrictions
RHEL 7’s SELinux could be blocking Tower’s outbound network calls. Temporarily set SELinux to permissive mode to test:
setenforce 0
If the license retrieval works after this, make the permissive rule permanent for Tower’s service:
semanage permissive -a httpd_t
Or review audit logs to identify specific denied actions and create a custom SELinux policy:
grep httpd_t /var/log/audit/audit.log | grep denied
内容的提问来源于stack exchange,提问作者gtaagii

