公有Cloud Run V2服务与私有服务间网络连通性故障求助
问题排查:Cloud Run V2服务间调用404无日志问题
我通过Cloud Run V2部署了两个服务:Server App(公网可访问)和Embedding Generator App(仅允许内部访问),已配置子网与VPC连接器实现两者连通。当前遇到以下问题:
- Server App调用Embedding Generator时返回404错误,且私有服务的Cloud Run日志无任何记录
- 将虚拟机接入Horcrux子网后,可成功调用Embedding Generator
推测两个Cloud Run服务间连通性存在问题,附上部署服务和VPC连接器的Terraform配置文件:
embedding_generator_app.tf
resource "google_service_account" "embedding_generator_app" { account_id = "embedding-generator-app" } resource "google_cloud_run_v2_service" "embedding_generator_app" { name = "embedding-generator-app" location = "us-central1" ingress = "INGRESS_TRAFFIC_INTERNAL_ONLY" template { service_account = google_service_account.embedding_generator_app.email scaling { max_instance_count = 10 } vpc_access { connector = google_vpc_access_connector.horcrux.id egress = "PRIVATE_RANGES_ONLY" } containers { image = "project-registry/embedding-generator-app" ports { container_port = 1010 } resources { startup_cpu_boost = true limits = { cpu = "4000m" memory = "2Gi" } } } } } resource "google_cloud_run_v2_service_iam_binding" "embedding_generator_app_run_invoker" { name = google_cloud_run_v2_service.embedding_generator_app.name project = google_cloud_run_v2_service.embedding_generator_app.project location = google_cloud_run_v2_service.embedding_generator_app.location role = "roles/run.invoker" members = [ "allUsers", ] }
server_app.tf
resource "google_service_account" "server_app" { account_id = "server-app" } resource "google_service_account_key" "server_app" { service_account_id = google_service_account.server_app.name } resource "google_cloud_run_v2_service" "server_app" { name = "server-app" location = "us-central1" ingress = "INGRESS_TRAFFIC_ALL" template { service_account = google_service_account.server_app.email scaling { max_instance_count = 10 } vpc_access { connector = google_vpc_access_connector.horcrux.id egress = "PRIVATE_RANGES_ONLY" } containers { image = "project-registry/serverapp" ports { container_port = 9090 } resources { startup_cpu_boost = true cpu_idle = true limits = { cpu = "2000m" memory = "1Gi" } } env { name = "EMBEDDING_GENERATOR_APP_URL" value = google_cloud_run_v2_service.embedding_generator_app.uri } } } } resource "google_cloud_run_v2_service_iam_binding" "server_app_run_invoker" { name = google_cloud_run_v2_service.server_app.name project = google_cloud_run_v2_service.server_app.project location = google_cloud_run_v2_service.server_app.location role = "roles/run.invoker" members = [ "allUsers", ] }
vpc.tf
resource "google_project_service" "vpc_access_api" { project = "project-id" service = "vpcaccess.googleapis.com" } resource "google_compute_subnetwork" "horcrux" { name = "horcrux" ip_cidr_range = "10.2.0.0/28" region = "us-central1" network = "default" private_ip_google_access = true depends_on = [google_project_service.vpc_access_api] } resource "google_vpc_access_connector" "horcrux" { name = "horcrux" machine_type = "e2-micro" min_instances = 2 max_instances = 3 subnet { name = google_compute_subnetwork.horcrux.name } }
排查关键点
1. 调用URL的正确性
google_cloud_run_v2_service.embedding_generator_app.uri 返回的是Cloud Run公网域名,但Embedding Generator设置了INGRESS_TRAFFIC_INTERNAL_ONLY,公网域名无法被VPC内的Cloud Run服务直接访问。需改用内部服务域名,格式为:http://embedding-generator-app.default.svc.cluster.local(同一项目同一区域场景),或直接使用服务的私有IP访问。
2. VPC连接器配置验证
- 确认VPC连接器
horcrux关联的子网private_ip_google_access已生效(当前配置已开启,可通过GCP控制台子网详情页验证) - Server App的
egress = "PRIVATE_RANGES_ONLY"会限制流量仅到私有IP范围,需确保Embedding Generator的内部地址属于该范围
3. 访问权限与Ingress规则
INGRESS_TRAFFIC_INTERNAL_ONLY允许的内部流量包括VPC内资源、同项目Cloud Run服务(通过内部域名)、VPC连接器转发的流量。需确认Server App通过VPC连接器发起的请求被识别为内部流量。- 当前IAM绑定
allUsers已满足权限要求,但需验证Server App的服务账号是否能通过VPC连接器正常访问目标服务。
4. 日志排查方向
- 检查Server App的日志,确认调用URL是否正确,是否存在DNS解析失败、连接超时等细节
- 在Cloud Logging中搜索
vpcaccess.googleapis.com,查看VPC连接器的流量转发日志 - 确认Embedding Generator容器是否正常启动,端口1010是否正确监听
内容的提问来源于stack exchange,提问作者mdornfe1
相关产品推荐
相关产品推荐

