GCP Infrastructure Manager自定义SA需高权限?缺失权限排查
GCP Infrastructure Manager自定义服务账号权限缺失排查
问题背景
尝试使用自定义服务账号(SA)配置GCP Infrastructure Manager(IM),但只有为该SA分配项目ADMIN或OWNER角色时,部署才能正常执行。
已分配的角色
已为该SA分配以下角色:
- roles/cloudbuild.builds.editor
- roles/cloudbuild.connectionAdmin
- roles/config.admin
- roles/iam.serviceAccountAdmin
- roles/secretmanager.admin
- roles/serviceusage.serviceUsageAdmin
- roles/storage.admin
- roles/writer(仅用于测试,无帮助)
- roles/editor(仅用于测试,无帮助)
此外,已为SA自身分配Service Account User角色,以允许在创建触发器时进行身份模拟。
前置操作确认
已通过gcloud builds connections成功创建与GitHub的连接,状态为COMPLETE;也通过gcloud builds repositories为该连接创建了仓库。
执行的部署命令
gcloud infra-manager deployments apply --project=$IM_PROJECT_ID projects/$IM_PROJECT_ID/locations/$IM_REGION/deployments/$DEPLOYMENT_ID \ --service-account projects/$IM_PROJECT_ID/serviceAccounts/$SA_INFRA_MGR \ --git-source-repo="$GIT_REPO" \ --git-source-directory="$GIT_IM_TEST_REPO_DIRECTORY" \ --git-source-ref="master" \ --tf-version-constraint="1.5.7" \ --input-values="im_project_id=$IM_PROJECT_ID,im_region=$IM_REGION,deployment_id=$DEPLOYMENT_ID,git_repo=$GIT_REPO,git_repo_directory=$GIT_IM_TEST_REPO_DIRECTORY,git_sa_secret=$GIT_SA_SECRET,tf_conn_name=$TF_CONN_NAME,sa_infra_mgr_full=$SA_INFRA_MGR_FULL,git_app_id=$GIT_APP_ID,git_ref=$GIT_REF"
错误信息
执行命令后出现如下错误:
ERROR: (gcloud.infra-manager.deployments.apply) Revision failed: The apply build c7cd994e-32f2-44a3-82ee-3643d8c566b6 failed while running: fetch. blueprint fetch failed: error fetching source (for private Git source, ensure proper configuration by consulting the troubleshooting guidance at: https://cloud.google.com/infrastructure-manager/docs/troubleshoot-deployments#validate-cbr): error downloading 'https://github.com/anonymous/appcode.git?ref=master': /usr/bin/git exited with 128: Cloning into '/workspace/apply/content'... fatal: could not read Username for 'https://github.com': No such device or address.
注:为SA分配roles/admin或roles/owner角色后,部署可成功创建,IM能正常工作。
Terraform配置(main.tf)
module "infrastructure-manager-workspace" { source = "terraform-google-modules/bootstrap/google//modules/im_cloudbuild_workspace" version = "~> 11.0" deployment_id = var.deployment_id # GCP project for Infrastructure Manager deployments and Cloud Build triggers. project_id = var.im_project_id # Location for Infrastructure Manager deployment. location = var.im_region # The URI of the repo where the Terraform configs are stored. im_deployment_repo_uri = var.git_repo # Git branch or ref configured to run infra-manager apply. All other refs will run plan by default. im_deployment_ref = var.git_ref # The directory inside the repo where the Terraform root config is located. im_deployment_repo_dir = var.git_repo_directory # Terraform version to use for Infrastructure Manager and the Cloud Builder image. tf_version = "1.5.7" # The secret ID within Secret Manager for an existing personal access token for GitHub. github_pat_secret = var.git_sa_secret # Connection name for linked repository. repo_connection_name = var.tf_conn_name # Custom SA id of form projects/{{project}}/serviceAccounts/{{email}} to be used by Infra Manager. infra_manager_sa = var.sa_infra_mgr_full # Custom SA ID of form projects/{{project}}/serviceAccounts/{{email}} to be used for creating Cloud Build triggers. cloudbuild_sa = var.sa_infra_mgr_full # github id is taken from URL which is accesible by clicking on Google Cloud Build in https://github.com/settings/installations github_app_installation_id = var.git_app_id }
疑问
请问该SA缺失哪些必要权限?
内容的提问来源于stack exchange,提问作者Łukasz Sz.
相关产品推荐
相关产品推荐

