You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Infrastructure Manager自定义SA需高权限?缺失权限排查

GCP Infrastructure Manager自定义服务账号权限缺失排查

问题背景

尝试使用自定义服务账号(SA)配置GCP Infrastructure Manager(IM),但只有为该SA分配项目ADMIN或OWNER角色时,部署才能正常执行。

已分配的角色

已为该SA分配以下角色:

  • roles/cloudbuild.builds.editor
  • roles/cloudbuild.connectionAdmin
  • roles/config.admin
  • roles/iam.serviceAccountAdmin
  • roles/secretmanager.admin
  • roles/serviceusage.serviceUsageAdmin
  • roles/storage.admin
  • roles/writer(仅用于测试,无帮助)
  • roles/editor(仅用于测试,无帮助)

此外,已为SA自身分配Service Account User角色,以允许在创建触发器时进行身份模拟。

前置操作确认

已通过gcloud builds connections成功创建与GitHub的连接,状态为COMPLETE;也通过gcloud builds repositories为该连接创建了仓库。

执行的部署命令

gcloud infra-manager deployments apply --project=$IM_PROJECT_ID projects/$IM_PROJECT_ID/locations/$IM_REGION/deployments/$DEPLOYMENT_ID \
        --service-account projects/$IM_PROJECT_ID/serviceAccounts/$SA_INFRA_MGR \
        --git-source-repo="$GIT_REPO" \
        --git-source-directory="$GIT_IM_TEST_REPO_DIRECTORY" \
        --git-source-ref="master" \
        --tf-version-constraint="1.5.7" \
        --input-values="im_project_id=$IM_PROJECT_ID,im_region=$IM_REGION,deployment_id=$DEPLOYMENT_ID,git_repo=$GIT_REPO,git_repo_directory=$GIT_IM_TEST_REPO_DIRECTORY,git_sa_secret=$GIT_SA_SECRET,tf_conn_name=$TF_CONN_NAME,sa_infra_mgr_full=$SA_INFRA_MGR_FULL,git_app_id=$GIT_APP_ID,git_ref=$GIT_REF"

错误信息

执行命令后出现如下错误:

ERROR: (gcloud.infra-manager.deployments.apply) Revision failed: The apply build c7cd994e-32f2-44a3-82ee-3643d8c566b6 failed while running: fetch.
blueprint fetch failed: error fetching source (for private Git source, ensure proper configuration by consulting the troubleshooting guidance at: https://cloud.google.com/infrastructure-manager/docs/troubleshoot-deployments#validate-cbr): error downloading 'https://github.com/anonymous/appcode.git?ref=master': /usr/bin/git exited with 128: Cloning into '/workspace/apply/content'...
fatal: could not read Username for 'https://github.com': No such device or address.

注:为SA分配roles/admin或roles/owner角色后,部署可成功创建,IM能正常工作。

Terraform配置(main.tf)

module "infrastructure-manager-workspace" {
    source = "terraform-google-modules/bootstrap/google//modules/im_cloudbuild_workspace"
    version = "~> 11.0"
    deployment_id = var.deployment_id

    # GCP project for Infrastructure Manager deployments and Cloud Build triggers.
    project_id = var.im_project_id

    # Location for Infrastructure Manager deployment.
    location = var.im_region

    # The URI of the repo where the Terraform configs are stored.
    im_deployment_repo_uri = var.git_repo

    # Git branch or ref configured to run infra-manager apply. All other refs will run plan by default. 
    im_deployment_ref = var.git_ref

    # The directory inside the repo where the Terraform root config is located.
    im_deployment_repo_dir = var.git_repo_directory

    # Terraform version to use for Infrastructure Manager and the Cloud Builder image.
    tf_version = "1.5.7"

    # The secret ID within Secret Manager for an existing personal access token for GitHub.
    github_pat_secret = var.git_sa_secret

    # Connection name for linked repository.
    repo_connection_name = var.tf_conn_name

    # Custom SA id of form projects/{{project}}/serviceAccounts/{{email}} to be used by Infra Manager.
    infra_manager_sa = var.sa_infra_mgr_full

    # Custom SA ID of form projects/{{project}}/serviceAccounts/{{email}} to be used for creating Cloud Build triggers. 
    cloudbuild_sa = var.sa_infra_mgr_full

    # github id is taken from URL which is accesible by clicking on Google Cloud Build in https://github.com/settings/installations
    github_app_installation_id = var.git_app_id
}

疑问

请问该SA缺失哪些必要权限?


内容的提问来源于stack exchange,提问作者Łukasz Sz.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 06:31:06