启用Cloud Function API时服务代理账号未创建问题
Cloud Function部署失败:默认服务账号被删除导致404认证错误
问题现象
部署Cloud Function时触发认证失败,报错信息如下:
"error": { "code": 404, "message": "Could not authenticate 'service-xxxx@gcf-admin-robot.iam.gserviceaccount.com': Account deleted: xxxx", "status": "NOT_FOUND" }
已尝试重新启用Cloud Function API,以及执行以下命令,但均无效果:
gcloud services enable run.googleapis.com gcloud services enable eventarc.googleapis.com
解决步骤
恢复/重建默认服务账号
- 获取项目编号:
gcloud projects describe YOUR_PROJECT_ID --format="value(projectNumber)" - 将命令中的
YOUR_PROJECT_NUMBER替换为上述结果,尝试恢复软删除的账号:gcloud iam service-accounts undelete service-YOUR_PROJECT_NUMBER@gcf-admin-robot.iam.gserviceaccount.com - 若恢复失败,直接创建新的服务账号:
gcloud iam service-accounts create service-YOUR_PROJECT_NUMBER --display-name "GCF Admin Robot Service Account"
- 获取项目编号:
授予必要权限
为该服务账号添加Cloud Function运行所需的核心角色:gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \ --member="serviceAccount:service-YOUR_PROJECT_NUMBER@gcf-admin-robot.iam.gserviceaccount.com" \ --role="roles/cloudfunctions.serviceAgent"若使用Eventarc或Cloud Run集成,额外添加
roles/run.admin角色:gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \ --member="serviceAccount:service-YOUR_PROJECT_NUMBER@gcf-admin-robot.iam.gserviceaccount.com" \ --role="roles/run.admin"触发账号初始化流程
禁用再重新启用Cloud Functions API,强制触发服务账号的初始化逻辑:gcloud services disable cloudfunctions.googleapis.com gcloud services enable cloudfunctions.googleapis.com检查组织政策限制
确认项目所属组织没有限制服务账号创建或生命周期的政策,比如constraints/iam.disableServiceAccountCreation、constraints/iam.serviceAccountLifetimeDuration,若有需调整政策允许该账号存在。
内容的提问来源于stack exchange,提问作者An Nguyen
相关产品推荐
相关产品推荐

