CentOS7下Nginx+Puma(Rails)多部分表单提交权限配置问题
Let's walk through the exact configurations you need to ensure all processes run as the rails user and resolve those upload permission errors. I'll cover the key areas that usually cause this issue:
1. Configure Nginx to use the rails user for worker processes
Nginx runs a root-owned master process (to bind to ports like 80/443), but we need its worker processes (which handle file uploads) to run as rails:
- Open your main Nginx config file (usually
/etc/nginx/nginx.conf) - Find the
userdirective at the top (it might default tonginxorapache) and change it to:user rails; - Restart Nginx to apply the change:
sudo systemctl restart nginx - Verify the worker processes are running as
railswith:
You should see lines forps aux | grep nginxnginx: worker processowned by therailsuser.
2. Fix permissions for upload-related directories
File uploads rely on two key directories: Nginx's temporary upload storage and your Rails app's upload directory.
Nginx's temporary client body directory
Nginx stores uploaded files temporarily before passing them to Puma. By default this is /var/lib/nginx/tmp/client_body. Give rails ownership here:
sudo chown -R rails:rails /var/lib/nginx/tmp sudo chmod -R 755 /var/lib/nginx/tmp
If you've customized client_body_temp_path in your Nginx server block, apply the same permissions to that custom path.
Rails app's upload directory
Whether you're storing uploads in public/uploads, tmp/uploads, or a custom path, ensure rails owns it:
sudo chown -R rails:rails /path/to/your/rails/app/public/uploads sudo chmod -R 755 /path/to/your/rails/app/public/uploads
Adjust the path to match where your Rails app saves uploads.
3. Confirm Puma is running as the rails user
Double-check Puma isn't running as root or another user:
- In your Puma config (
config/puma.rb), add or verify these lines to enforce therailsuser/group:user 'rails', 'rails' - Restart Puma using the
railsuser (avoid running it as root):su - rails -c 'cd /path/to/your/rails/app && bundle exec puma -C config/puma.rb -d' - Verify with:
All Puma processes should showps aux | grep pumarailsas the owner.
4. Fix SELinux permissions (CentOS 7-specific critical step)
CentOS 7 enables SELinux by default, which will block Nginx/Puma from accessing upload directories even if file permissions look correct.
Set SELinux context for your Rails upload directory
Run this to allow web processes to read/write to your uploads folder:
sudo chcon -R -t httpd_sys_rw_content_t /path/to/your/rails/app/public/uploads
Set SELinux context for Nginx's temporary directory
If you modified /var/lib/nginx/tmp earlier, apply the correct context:
sudo chcon -R -t httpd_sys_rw_content_t /var/lib/nginx/tmp
(Optional) Persist SELinux changes
To make these context changes survive a system reboot, use semanage:
sudo semanage fcontext -a -t httpd_sys_rw_content_t "/path/to/your/rails/app/public/uploads(/.*)?" sudo restorecon -R /path/to/your/rails/app/public/uploads
Do the same for Nginx's temporary directory if needed.
5. Test and troubleshoot
After making these changes, try uploading a file again. If you still get errors, check Nginx's error log (usually /var/log/nginx/error.log) for specific messages:
- If you see
permission deniedfor a file in/var/lib/nginx/tmp, double-check the directory ownership and SELinux context. - If the error points to your Rails app's upload directory, confirm the
railsuser has write access there.
内容的提问来源于stack exchange,提问作者Dave

