使用Python编写Sensu检查时遇TTY错误的技术问询
Hey there! I’ve run into this exact TTY issue with Sensu checks before—let’s break down how to fix it. The root problem is that Sensu runs checks as a background service without a TTY (terminal) attached, but many default sudo configurations require a TTY for execution. Since you’ve already started with sudo rules, here are the next steps:
1. Update Your Sudoers Configuration to Skip TTY Requirement
First, we need to tell sudo that the Sensu user doesn’t need a TTY to run your target command. Always edit sudoers with visudo—it validates syntax to avoid locking yourself out of the system.
Run this command to open the sudoers file safely:
sudo visudo
Add one of these entries depending on your needs:
- To disable TTY requirement for all commands run by the Sensu user:
Defaults:sensu !requiretty - To restrict this to only your specific check command (more secure):
Cmnd_Alias SENSU_CHECK_CMD = /path/to/your/shell/command Defaults!/SENSU_CHECK_CMD !requiretty sensu ALL=(ALL) NOPASSWD: SENSU_CHECK_CMD
Save and exit the editor (usually Ctrl+O then Ctrl+X if you’re using nano).
2. Modify Your Python Script to Avoid TTY Dependencies
When calling shell commands from Python, ensure you’re using flags that skip interactive TTY prompts. For sudo, add the -n (non-interactive) flag—it tells sudo not to request a TTY or password prompt (which aligns with your NOPASSWD sudo rule).
Here’s a revised snippet of your Python check script:
import subprocess import sys def execute_sensu_check(): try: # Use sudo -n to bypass TTY requirement cmd_result = subprocess.run( ["sudo", "-n", "/path/to/your/shell/command"], capture_output=True, text=True, check=True ) print(f"Check passed: {cmd_result.stdout.strip()}") sys.exit(0) # Sensu OK exit code except subprocess.CalledProcessError as e: print(f"Check failed: {e.stderr.strip()}") sys.exit(2) # Sensu CRITICAL exit code except Exception as e: print(f"Unexpected error: {str(e)}") sys.exit(1) # Sensu WARNING exit code if __name__ == "__main__": execute_sensu_check()
3. Verify Your Command Doesn’t Require Interactive Input
Double-check that the shell command you’re calling doesn’t inherently need a TTY for interaction. For example, if you’re using apt, add -y to auto-confirm prompts; if you’re running a custom script, ensure it has no read commands that wait for user input. If it does, modify the command to run in non-interactive mode.
Quick Test
After making these changes, test the script as the Sensu user to confirm it works without a TTY:
sudo -u sensu python3 /path/to/your/check/script.py
This should run without throwing TTY-related errors now.
内容的提问来源于stack exchange,提问作者Royce

