logrotate permission denied

1

Por que estou recebendo permissão para renomear meu arquivo de registro ao executar logrotate ? O proprietário do meu arquivo de log mostrado abaixo é rajohns , que é o mesmo usuário que efetuou login executando o comando logrotate mostrado abaixo.

$ cat /etc/logrotate.d/judgecard-api-0.0.1

/var/log/judgecard-api-0.0.1.log {
    su rajohns rajohns
    weekly
    rotate 4
    create 0777 rajohns rajohns
    missingok
    notifempty
    postrotate
        systemctl restart judgecard-api-0.0.1.service > /dev/null
    endscript
}

$ ls -l /var/log/judgecard-api-0.0.1.log

-rwxrwxrwx 1 rajohns rajohns 10578 Feb 12 23:01 /var/log/judgecard-api-0.0.1.log
$ sudo logrotate -vf -s ~ / logrotate_test_status_file judgecard-api-0.0.1

reading config file judgecard-api-0.0.1

Handling 1 logs

rotating pattern: /var/log/judgecard-api-0.0.1.log  forced from command line (4 rotations)
empty log files are not rotated, old logs are removed
switching euid to 1000 and egid to 1000
considering log /var/log/judgecard-api-0.0.1.log
  log needs rotating
rotating log /var/log/judgecard-api-0.0.1.log, log->rotateCount is 4
dateext suffix '-20180212'
glob pattern '-[0-9][0-9][0-9][0-9][0-9][0-9][0-9][0-9]'
renaming /var/log/judgecard-api-0.0.1.log.4 to /var/log/judgecard-api-0.0.1.log.5 (rotatecount 4, logstart 1, i 4), 
old log /var/log/judgecard-api-0.0.1.log.4 does not exist
renaming /var/log/judgecard-api-0.0.1.log.3 to /var/log/judgecard-api-0.0.1.log.4 (rotatecount 4, logstart 1, i 3), 
old log /var/log/judgecard-api-0.0.1.log.3 does not exist
renaming /var/log/judgecard-api-0.0.1.log.2 to /var/log/judgecard-api-0.0.1.log.3 (rotatecount 4, logstart 1, i 2), 
old log /var/log/judgecard-api-0.0.1.log.2 does not exist
renaming /var/log/judgecard-api-0.0.1.log.1 to /var/log/judgecard-api-0.0.1.log.2 (rotatecount 4, logstart 1, i 1), 
old log /var/log/judgecard-api-0.0.1.log.1 does not exist
renaming /var/log/judgecard-api-0.0.1.log.0 to /var/log/judgecard-api-0.0.1.log.1 (rotatecount 4, logstart 1, i 0), 
old log /var/log/judgecard-api-0.0.1.log.0 does not exist
log /var/log/judgecard-api-0.0.1.log.5 doesn't exist -- won't try to dispose of it
renaming /var/log/judgecard-api-0.0.1.log to /var/log/judgecard-api-0.0.1.log.1
error: failed to rename /var/log/judgecard-api-0.0.1.log to /var/log/judgecard-api-0.0.1.log.1: Permission denied
switching euid to 0 and egid to 0
    
por Adam Johns 13.02.2018 / 07:01

1 resposta

3

Obviamente, a rotação / var / log falha, pois o diretório normalmente pertence à raiz: adm.

Você pode dar uma olhada no Apache e em outros para ver como eles fazem isso.

A maneira usual de fazer isso é criar um subdiretório em / var / log e tornar outro usuário o proprietário dele:

 sudo mkdir /var/log/judgecards
 chown rajohns /var/log/judgecards

Em seguida, mova os registros antigos e crie novos registros do seu aplicativo aqui.

    
por 13.02.2018 / 08:11