You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

公有Cloud Run V2服务与私有服务间网络连通性故障求助

问题排查:Cloud Run V2服务间调用404无日志问题

我通过Cloud Run V2部署了两个服务:Server App(公网可访问)和Embedding Generator App(仅允许内部访问),已配置子网与VPC连接器实现两者连通。当前遇到以下问题:

  • Server App调用Embedding Generator时返回404错误,且私有服务的Cloud Run日志无任何记录
  • 将虚拟机接入Horcrux子网后,可成功调用Embedding Generator

推测两个Cloud Run服务间连通性存在问题,附上部署服务和VPC连接器的Terraform配置文件:


embedding_generator_app.tf

resource "google_service_account" "embedding_generator_app" {
  account_id = "embedding-generator-app"
}

resource "google_cloud_run_v2_service" "embedding_generator_app" {
  name     = "embedding-generator-app"
  location = "us-central1"
  ingress  = "INGRESS_TRAFFIC_INTERNAL_ONLY"

  template {
    service_account = google_service_account.embedding_generator_app.email

    scaling {
      max_instance_count = 10
    }

    vpc_access {
      connector = google_vpc_access_connector.horcrux.id
      egress    = "PRIVATE_RANGES_ONLY"
    }

    containers {
      image = "project-registry/embedding-generator-app"

      ports {
        container_port = 1010
      }

      resources {
        startup_cpu_boost = true
        limits = {
          cpu    = "4000m"
          memory = "2Gi"
        }
      }
    }
  }
}

resource "google_cloud_run_v2_service_iam_binding" "embedding_generator_app_run_invoker" {
  name     = google_cloud_run_v2_service.embedding_generator_app.name
  project  = google_cloud_run_v2_service.embedding_generator_app.project
  location = google_cloud_run_v2_service.embedding_generator_app.location
  role     = "roles/run.invoker"
  members = [
    "allUsers",
  ]
}

server_app.tf

resource "google_service_account" "server_app" {
  account_id   = "server-app"
}

resource "google_service_account_key" "server_app" {
  service_account_id = google_service_account.server_app.name
}

resource "google_cloud_run_v2_service" "server_app" {
  name     = "server-app"
  location = "us-central1"
  ingress  = "INGRESS_TRAFFIC_ALL"

  template {
    service_account = google_service_account.server_app.email

    scaling {
      max_instance_count = 10
    }

    vpc_access {
      connector = google_vpc_access_connector.horcrux.id
      egress    = "PRIVATE_RANGES_ONLY"
    }

    containers {
      image = "project-registry/serverapp"

      ports {
        container_port = 9090
      }

      resources {
        startup_cpu_boost = true
        cpu_idle          = true
        limits = {
          cpu    = "2000m"
          memory = "1Gi"
        }
      }

      env {
        name  = "EMBEDDING_GENERATOR_APP_URL"
        value = google_cloud_run_v2_service.embedding_generator_app.uri
      }
    }
  }
}

resource "google_cloud_run_v2_service_iam_binding" "server_app_run_invoker" {
  name     = google_cloud_run_v2_service.server_app.name
  project  = google_cloud_run_v2_service.server_app.project
  location = google_cloud_run_v2_service.server_app.location
  role     = "roles/run.invoker"
  members = [
    "allUsers",
  ]
}

vpc.tf

resource "google_project_service" "vpc_access_api" {
  project    = "project-id"
  service = "vpcaccess.googleapis.com"
}

resource "google_compute_subnetwork" "horcrux" {
  name          = "horcrux"
  ip_cidr_range = "10.2.0.0/28"
  region        = "us-central1"
  network       = "default"
  private_ip_google_access = true
  depends_on = [google_project_service.vpc_access_api]
}

resource "google_vpc_access_connector" "horcrux" {
  name          = "horcrux"
  machine_type  = "e2-micro"
  min_instances = 2
  max_instances = 3
  subnet {
    name = google_compute_subnetwork.horcrux.name
  }
}

排查关键点

1. 调用URL的正确性

google_cloud_run_v2_service.embedding_generator_app.uri 返回的是Cloud Run公网域名,但Embedding Generator设置了INGRESS_TRAFFIC_INTERNAL_ONLY,公网域名无法被VPC内的Cloud Run服务直接访问。需改用内部服务域名,格式为:
http://embedding-generator-app.default.svc.cluster.local(同一项目同一区域场景),或直接使用服务的私有IP访问。

2. VPC连接器配置验证

  • 确认VPC连接器horcrux关联的子网private_ip_google_access已生效(当前配置已开启,可通过GCP控制台子网详情页验证)
  • Server App的egress = "PRIVATE_RANGES_ONLY"会限制流量仅到私有IP范围,需确保Embedding Generator的内部地址属于该范围

3. 访问权限与Ingress规则

  • INGRESS_TRAFFIC_INTERNAL_ONLY允许的内部流量包括VPC内资源、同项目Cloud Run服务(通过内部域名)、VPC连接器转发的流量。需确认Server App通过VPC连接器发起的请求被识别为内部流量。
  • 当前IAM绑定allUsers已满足权限要求,但需验证Server App的服务账号是否能通过VPC连接器正常访问目标服务。

4. 日志排查方向

  • 检查Server App的日志,确认调用URL是否正确,是否存在DNS解析失败、连接超时等细节
  • 在Cloud Logging中搜索vpcaccess.googleapis.com,查看VPC连接器的流量转发日志
  • 确认Embedding Generator容器是否正常启动,端口1010是否正确监听

内容的提问来源于stack exchange,提问作者mdornfe1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 14:30:04