You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RHEL 7.7上Ansible Tower无法获取许可证列表问题求助

Troubleshooting Ansible Tower License Connection Issue on RHEL 7.7

Based on your situation—where curl can reach subscription.rhsm.redhat.com but Ansible Tower can’t—the problem almost certainly stems from Ansible Tower’s isolated runtime environment not inheriting your system’s network, proxy, or DNS configurations. Let’s walk through targeted checks and fixes:

1. Configure Proxy Settings for Tower’s Python Virtual Environment

Ansible Tower runs in its own Python virtual environment (/var/lib/awx/venv/awx/), which doesn’t automatically pick up system-wide proxy rules from /etc/rhsm/rhsm.conf. You need to explicitly set proxy for Tower:

  • Option 1: Add proxy to Tower’s core settings
    Edit /etc/tower/settings.py and insert these lines (replace with your actual proxy details):

    PROXIES = {
        'http': 'http://your-proxy:port/',
        'https': 'https://your-proxy:port/',
    }
    # Link to your CA certificate to avoid SSL trust issues
    REQUESTS_CA_BUNDLE = '/usr/share/rhn/RHNS-CA-CERT'
    
  • Option 2: Set proxy via service environment variables
    Edit /etc/sysconfig/awx and add:

    HTTP_PROXY=http://your-proxy:port/
    HTTPS_PROXY=https://your-proxy:port/
    NO_PROXY=localhost,127.0.0.1,.your-internal-domain.com
    

    Restart Tower to apply changes:

    systemctl restart awx
    

2. Fix CA Certificate Access for Tower’s Virtual Environment

Tower’s Python venv uses its own CA store (managed by the certifi package), which might not include your RHNS certificate. Update it with:

cat /usr/share/rhn/RHNS-CA-CERT >> /var/lib/awx/venv/awx/lib/python3.6/site-packages/certifi/cacert.pem

3. Test Connectivity as the Tower Runtime User

Ansible Tower runs under the awx user, which might have different environment variables than your login user. Switch to awx and validate connectivity directly:

su - awx -s /bin/bash
# Test DNS resolution first
nslookup subscription.rhsm.redhat.com
# Test HTTPS connection with your CA cert
curl -v --cacert /usr/share/rhn/RHNS-CA-CERT https://subscription.rhsm.redhat.com/subscription/users/altangerel_g/owners

If this fails, add proxy variables to /var/lib/awx/.bash_profile so the awx user inherits them on startup.

4. Check SELinux Restrictions

RHEL 7’s SELinux could be blocking Tower’s outbound network calls. Temporarily set SELinux to permissive mode to test:

setenforce 0

If the license retrieval works after this, make the permissive rule permanent for Tower’s service:

semanage permissive -a httpd_t

Or review audit logs to identify specific denied actions and create a custom SELinux policy:

grep httpd_t /var/log/audit/audit.log | grep denied

内容的提问来源于stack exchange,提问作者gtaagii

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 22:34:06