升级至1.3.0后Azure edgeAgent无法启动问题求助
Azure IoT Edge 1.3.0升级后edgeAgent启动失败(权限拒绝问题)
旧环境
- 硬件/系统:Amd64架构的Ubuntu 18.04服务器
- IoT Edge运行时版本:1.2.7
- 模块版本:
- azureiotedge-hub:1.2.8
- azureiotedge-agent:1.2.8
- 状态:此前所有模块运行正常
新环境
- IoT Edge运行时版本:1.3.0
- 模块版本:
- azureiotedge-agent:1.3.0
- azureiotedge-hub:1.2.8(edgeAgent升级到1.3.0前已崩溃)
问题现象
升级IoT Edge运行时到1.3.0后一切正常,但部署新版本的iotedge-agent后,azureiotedge-agent:1.3.0容器启动时因无法访问主机绑定的存储目录/iotedge/storage/edgeAgent崩溃。
检查更新后的agentStart.sh脚本执行情况:
- 主机已创建UID为13622的用户
edgeagentuser - 存储目录和管理套接字的所有权已修改为UID 13622
- Edge Agent Service DLL启动后崩溃
日志信息
执行iotedge check仅显示DNS服务器警告,其余检测项均正常。
IoT Edge Agent容器日志如下:
2022-07-19 08:23:29 Starting Edge Agent 2022-07-19 08:23:29 Changing ownership of storage folder: /iotedge/storage//edgeAgent to 13622 2022-07-19 08:23:29 Changing ownership of management socket: /var/run/iotedge/mgmt.sock 2022-07-19 08:23:29 Completed necessary setup. Starting Edge Agent. 2022-07-19 08:23:29.368 +00:00 Edge Agent Main() <6> 2022-07-19 08:23:29.935 +00:00 [INF] - Initializing Edge Agent. <6> 2022-07-19 08:23:30.473 +00:00 [INF] - Version - 1.3.0.57041647 (b022069058d21deb30c7760c4e384b637694f464) <6> 2022-07-19 08:23:30.475 +00:00 [INF] - [excluded the ASCII art] <0> 2022-07-19 08:23:30.527 +00:00 [FTL] - Fatal error reading the Agent's configuration. System.UnauthorizedAccessException: Access to the path '/iotedge/storage/edgeAgent' is denied. ---> System.IO.IOException: Permission denied --- End of inner exception stack trace --- at System.IO.FileSystem.CreateDirectory(String fullPath) at System.IO.Directory.CreateDirectory(String path) at Microsoft.Azure.Devices.Edge.Agent.Service.Program.GetOrCreateDirectoryPath(String baseDirectoryPath, String directoryName) in /mnt/vss/_work/1/s/edge-agent/src/Microsoft.Azure.Devices.Edge.Agent.Service/Program.cs:line 361 at Microsoft.Azure.Devices.Edge.Agent.Service.Program.MainAsync(IConfiguration configuration)
解决方案建议
递归同步存储目录权限
脚本仅修改了目录本身的所有权,可能未同步子文件/子目录权限,执行以下命令修复:sudo chown -R 13622:13622 /iotedge/storage/edgeAgent sudo chmod -R 700 /iotedge/storage/edgeAgent排查AppArmor限制
Ubuntu 18.04默认启用AppArmor,可能阻止容器访问主机目录。临时关闭AppArmor测试:sudo aa-teardown若问题解决,需为iotedge-agent配置正确的AppArmor规则,或更新IoT Edge自带的AppArmor配置。
检查存储挂载属性
如果/iotedge/storage是外部挂载存储(如NFS、独立分区),需确认挂载参数(如NFS的no_root_squash)是否允许UID 13622正常访问。清理旧代理数据后重新升级
回退到旧版本后,清理edgeAgent存储目录再重新升级:sudo systemctl stop iotedge sudo rm -rf /iotedge/storage/edgeAgent sudo systemctl start iotedge之后重新部署1.3.0版本的edgeAgent模块。
验证用户映射配置
检查/etc/iotedge/config.yaml中的用户映射规则,确保edgeAgent容器使用的UID 13622与主机用户无冲突。
内容的提问来源于stack exchange,提问作者MarcoL83
相关产品推荐
相关产品推荐

