Rails 7.0.4部署时ActiveSupport::MessageEncryptor::InvalidMessage错误排查
部署Rails项目时assets:precompile报ActiveSupport::MessageEncryptor::InvalidMessage错误的解决过程
我基于Ruby 3.1.2 + Rails 7.0.4创建了新项目,正在从Ubuntu 22.04部署至Debian 11,技术栈包含capistrano、nginx、passenger、rbenv。部署时执行assets:precompile任务出现如下错误:
00:04 deploy:assets:precompile 01 $HOME/.rbenv/bin/rbenv exec bundle exec rake assets:precompile 01 rake aborted! 01 ActiveSupport::MessageEncryptor::InvalidMessage: ActiveSupport::MessageEncryptor::InvalidMessage 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/message_encryptor.rb:209:in `rescue in _decrypt' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/message_encryptor.rb:186:in `_decrypt' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/message_encryptor.rb:160:in `decrypt_and_verify' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/messages/rotator.rb:22:in `decrypt_and_verify' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/encrypted_file.rb:104:in `decrypt' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/encrypted_file.rb:66:in `read' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/encrypted_configuration.rb:21:in `read' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/encrypted_configuration.rb:33:in `config' 01 /var/www/profile/shared/bundle/ruby/3.1.0/gems/activesupport-7.0.4/lib/active_support/encrypted_configuration.rb:48:in `options'
尝试过的无效修复方案
- 使用
bin/rails credentials:edit创建凭证并提交部署; - 创建production密钥并复制到生产环境,配置capistrano进行链接;
- 配置生产环境使用master.key替代production.key,复制master.key到共享目录并添加到linked_files,部署失败;
- 将密钥生成哈希算法从SHA256改为SHA1,配置
config.active_support.key_generator_hash_digest_class = OpenSSL::Digest::SHA1,无效; - 重新创建credentials.yml.enc和master.key,复制master.key到生产环境后重新部署,仍失败。
更新1:重新尝试配置production.key
再次创建production密钥后部署仍报错,开发机操作步骤:
$ rails secret $ EDITOR=mg rails credentials:edit $ rails credentials:edit --environment production $ RAILS_ENV=production rails c $ scp config/credentials/production.key 10.1.1.6:/var/www/profile/shared/config/credentials/ $ git add . $ git ca -m 'Add production encrypted file'
在deploy.rb中添加:
append :linked_files, 'config/credentials/production.key'
执行cap production deploy后,验证服务器上production.key已正确链接,但仍报错。
更新2:在生产服务器直接生成production.yml.enc
登录生产服务器执行以下操作:
$ cd /var/www/profile/releases/20221221021047 $ rm config/credentials/production.* $ EDITOR=mg rails credentials:edit -e production
测试RAILS_ENV=production rails c可正常运行。回到开发机,复制生产服务器的production.yml.enc提交部署:
$ scp 10.1.1.6:/var/www/profile/releases/20221221021047/config/credentials/production.yml.enc ~/code/profile/config/credentials $ git commit -am 'Updated production encrypted yaml with server generated one' $ cap production deploy
部署时不再报错,但Nginx仍报错,重启Nginx无效,此方法不符合规范。
更新3:问题解决——移除.rbenv-vars文件
发现之前参考文档创建的生产环境.rbenv-vars文件导致部署问题,移除该文件后,重新创建production文件并复制production.key到生产环境,部署及Nginx均恢复正常,操作步骤:
- 开发机:创建production.yml.enc并提交
$ rm config/credentials/production.yml.enc $ scp config/credentials/production.key 10.1.1.6:/var/www/profile/shared/config/credentials/ $ rake secret $ rails credentials:edit --environment production # 输入 secret_key_base: <rake secret生成的密钥> $ git ca -m 'updated production encrypted file with secret again' $ cap production deploy
内容的提问来源于stack exchange,提问作者map7
相关产品推荐
相关产品推荐

