Failed to register authentication agent: ...
Failed to start xxx.service: Interactive authentication required.
또는
==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-units ====
Authentication is required to start 'xxx.service'.
polkit-agent-helper-1: ... was not provided by any .service files
systemctl 이 서비스를 제어하려면 권한 확인이 필요한데, root 가 아닌 사용자로 실행했을 때 그 확인을 대신 해 줄 polkit 인증 에이전트가 없거나 D-Bus 를 통해 polkit 데몬에 닿지 못한 상태다.
가장 흔한 원인이다. 서비스 제어는 특권 동작이다.
sudo systemctl restart myapp
sudo 로 실행했는데도 같은 메시지가 나온다면 아래로 넘어간다.
rpm -q polkit # RHEL 계열
dpkg -l | grep policykit # Debian 계열
systemctl status polkit
sudo systemctl restart polkit
최소 설치 이미지나 컨테이너 베이스 이미지에는 polkit 이 빠져 있는 경우가 있다.
sudo dnf install -y polkit
sudo apt install -y policykit-1
polkit 은 D-Bus 위에서 동작한다.
systemctl status dbus
sudo systemctl restart dbus
동작 중인 시스템에서 dbus 를 재시작하면 그것에 매달린 서비스들이 함께 흔들린다. 가능하면 점검 창에서 하고, 그렇지 않다면 재부팅이 오히려 안전하다.
su - 로 전환했거나 cron·CI 처럼 로그인 세션이 없는 문맥에서 실행하면 세션 정보가 없어 polkit 이 대화형 확인을 시도하다 실패한다.
loginctl
echo "$XDG_SESSION_ID $DBUS_SESSION_BUS_ADDRESS"
세션이 없다면 sudo 로 root 권한을 명시적으로 얻어 실행하거나, machinectl shell 로 정상 세션을 만들어 들어간다.
sudo machinectl shell root@
컨테이너에는 대개 systemd 자체가 없다. systemctl 을 실행하면 다음이 나온다.
System has not been booted with systemd as init system (PID 1). Can't operate.
이것은 polkit 문제가 아니다. 컨테이너에서는 프로세스를 직접 띄우거나 이미지의 entrypoint 를 쓴다.
운영 계정에 재시작 권한만 주고 싶다면 두 가지 길이 있다.
sudoers 로 명령 단위로 허용한다.
sudo visudo -f /etc/sudoers.d/myapp
appops ALL=(root) NOPASSWD: /usr/bin/systemctl restart myapp.service, /usr/bin/systemctl status myapp.service
또는 polkit 규칙을 둔다.
sudo vi /etc/polkit-1/rules.d/50-myapp.rules
polkit.addRule(function(action, subject) {
if (action.id == "org.freedesktop.systemd1.manage-units" &&
action.lookup("unit") == "myapp.service" &&
subject.isInGroup("appops")) {
return polkit.Result.YES;
}
});
polkit 규칙 파일은 JavaScript 문법이며 polkit 0.106 이상에서 동작한다. RHEL 7 의 폭넓게 쓰이던 .pkla 형식과는 다르다.