无法重新配置gitlab-ee,出现gitlab_shell_t未定义相关报错
libsepol.context_from_record: type gitlab_shell_t is not defined (No such file or directory).
libsepol.context_from_record: could not create context structure (Invalid argument).
libsemanage.validate_handler: invalid context system_u:object_r:gitlab_shell_t:s0 specified for /var/opt/gitlab/.ssh(/.*)? [all files] (Invalid argument).
libsemanage.dbase_llist_iterate: could not iterate over records (Invalid argument).
semodule: Failed!
以上报错为SELinux安全模块加载GitLab自定义策略失败导致,gitlab_shell_t 是GitLab专属的SELinux上下文类型,系统找不到该类型定义,导致配置流程中断,可按以下步骤排查解决:
排查解决步骤
1. 验证是否为SELinux限制导致
- 执行命令
sestatus查看当前SELinux运行模式 - 若当前为Enforcing强制模式,执行
setenforce 0临时切换为宽容模式 - 重新执行GitLab配置命令
gitlab-ctl reconfigure,若配置能正常完成,则确认是SELinux策略问题
2. 修复GitLab SELinux策略
- 执行
semodule -l | grep gitlab查看系统中已安装的GitLab相关SELinux模块名称 - 卸载损坏的GitLab SELinux模块:
semodule -r [查询到的GitLab模块名] - 重新加载GitLab内置的SELinux策略文件:
semodule -i /opt/gitlab/embedded/selinux/gitlab.pp - 恢复GitLab SSH目录的默认上下文:
restorecon -Rv /var/opt/gitlab/.ssh - 再次执行
gitlab-ctl reconfigure验证配置是否正常
3. 可选永久方案(不需要开启SELinux时使用)
如果业务场景不需要启用SELinux,可永久关闭避免后续同类问题:
- 编辑SELinux配置文件:
vi /etc/selinux/config - 将配置项
SELINUX=enforcing修改为SELINUX=disabled - 重启服务器后配置生效
内容的提问来源于stack exchange,提问作者pavan
相关产品推荐
相关产品推荐

