You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Artifact Registry重定向回Container Registry时预检查失败求助

问题:禁用Artifact Registry到Container Registry的重定向失败(400预检查错误)

执行命令gcloud artifacts settings disable-upgrade-redirection --project=xx时,返回FAILED_PRECONDITION(预检查失败)的400错误,具体情况:

  • 已配置IAM角色:roles/artifactregistry.admin、roles/artifactregistry.createOnPushRepoAdmin
  • 此前清理过相关镜像及Kubernetes Pod,恢复操作时触发该问题
  • 调试日志显示API请求返回400,错误信息为"Precondition check failed."
  • 当前Artifact Registry的镜像推拉功能正常

解决步骤

1. 排查残留关联资源

预检查失败通常是因为存在依赖重定向的资源未清理,重点检查:

  • Container Registry遗留仓库:执行gcloud container images list确认是否还有未删除的旧仓库
  • Kubernetes残留资源:用kubectl get all --all-namespaces检查是否有Deployment、Pod等仍在引用旧镜像地址
  • 服务账号绑定:确认没有服务账号仍在关联Artifact Registry的重定向配置

2. 查看当前重定向状态

先确认项目的重定向配置详情:

gcloud artifacts settings describe --project=xx

如果输出显示legacyRedirectionState: UPGRADED,说明重定向已启用,需确保没有正在依赖该配置的业务操作。

3. 验证权限是否足够

虽然已有artifactregistry.admin,但临时添加roles/editor权限测试是否是权限问题:

# 添加权限
gcloud projects add-iam-policy-binding xx --member=user:你的邮箱@域名.com --role=roles/editor

# 执行禁用命令
gcloud artifacts settings disable-upgrade-redirection --project=xx

# 移除权限
gcloud projects remove-iam-policy-binding xx --member=user:你的邮箱@域名.com --role=roles/editor

4. 等待后台迁移任务完成

如果项目是自动升级到Artifact Registry的,可能后台有未完成的迁移任务。等待15-20分钟后再重试命令。

5. 直接通过API修改配置

若以上步骤无效,尝试用API强制重置重定向状态(需确认无业务依赖):

curl -X PATCH \
  -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  -H "Content-Type: application/json" \
  https://artifactregistry.googleapis.com/v1/projects/xx/projectSettings?updateMask=legacy_redirection_state \
  -d '{"legacyRedirectionState": "DISABLED"}'

内容的提问来源于stack exchange,提问作者oleksim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 02:42:14