Flask+WSGI部署Apache2 Ubuntu时遇Permission denied: video.mp4错误求助
Hey there! Let's work through that permission error you're getting when trying to download an Azure Blob to your Flask app's directory. Here's a step-by-step breakdown of what to check and fix:
1. Confirm the User Apache Runs As
Apache on Ubuntu typically runs under the www-data user/group. Verify this with:
ps aux | grep apache2
Look for lines starting with www-data—that's the user trying to write to your directory.
2. Fix Directory Permissions
Your Flask app's directory (/var/www/FlaskApp/FlaskApp/) needs write permissions for the www-data user.
First, check the current permissions:
ls -ld /var/www/FlaskApp/FlaskApp/
Option A: Change Directory Ownership (Recommended)
Give www-data ownership of the directory so it can write files there:
sudo chown -R www-data:www-data /var/www/FlaskApp/FlaskApp/
Option B: Adjust Permissions (Quick Test Only)
If you just want to test without changing ownership (not ideal for production), grant broad write access:
sudo chmod -R 777 /var/www/FlaskApp/FlaskApp/
Stick with Option A for production environments to keep things secure.
3. Use a Temporary Directory (Better Practice)
Instead of writing to your app's directory, use a system temporary directory—this avoids permission issues entirely and keeps your app directory clean. Python's tempfile module makes this straightforward:
import tempfile import os from azure.storage.blob import BlockBlobService def watermark(): # Create a temporary .mp4 file (won't auto-delete immediately) with tempfile.NamedTemporaryFile(suffix='.mp4', delete=False) as temp_file: temp_video_path = temp_file.name # Download blob to the temporary path block_blob_service = BlockBlobService(account_name='your_account', account_key='your_key') block_blob_service.get_blob_to_path('your_container', 'video.mp4', temp_video_path) # Run your watermark processing here... # Clean up the temp file when you're done os.unlink(temp_video_path)
4. Check AppArmor Restrictions
Ubuntu uses AppArmor to restrict process access. If Apache is blocked from writing to your directory, update the AppArmor profile:
- Open the Apache profile for editing:
sudo nano /etc/apparmor.d/usr.sbin.apache2
- Add this line inside the
{ ... }block to allow write access to your app directory:
/var/www/FlaskApp/FlaskApp/** rw,
- Save and exit, then reload AppArmor:
sudo systemctl reload apparmor
5. Ensure You're Using Absolute Paths
Relative paths can fail because Apache's working directory isn't what you expect. Use absolute paths to avoid this confusion:
import os # Get the absolute path of your app's directory app_directory = os.path.abspath(os.path.dirname(__file__)) video_path = os.path.join(app_directory, 'video.mp4') # Use the absolute path in your blob download call block_blob_service.get_blob_to_path('your_container', 'video.mp4', video_path)
Start with checking permissions first, then try the temporary directory approach if you want to avoid long-term directory ownership changes. Let me know if you hit any snags!
内容的提问来源于stack exchange,提问作者Dhvani Shah

