部署Firebase Cloud Functions时构建服务账号权限缺失,如何授权?
我使用firebase deploy --only functions命令将Node.js(第二代)Cloud Functions部署到Firebase项目,代码如下:
import {onDocumentWritten} from "firebase-functions/v2/firestore"; import pkgNM from "nodemailer"; const {nodemailer} = pkgNM; // Firebase Cloud Function to send email on new document creation export const sendEmailOnNewDocument = onDocumentWritten( "subscriptions/{documentId}", async (event) => { const newData = event.data; const recipientEmail = "skysuiteservices@gmail.com"; const subject = "New Subscription Created"; const text1 = `A new Subscription was created: ${newData["shopName"]}`; const text2 = ` Subscription: ${newData["subscriptionType"]}`; // Check if the document was created or updated if (newData.after.exists()) { try { // Create a nodemailer transporter const transporter = nodemailer.createTransport({ // Configure your email service host: "smtp.gmail.com", port: 465, auth: { user: "skysuiteservices@gmail.com", pass: "vtmi uzgz eiyw eooy", }, }); // Send email await transporter.sendMail({ from: "skysuiteservices@gmail.com", to: recipientEmail, subject: subject, text: text1 + text2, }); console.log("Email sent successfully"); } catch (error) { console.error("Error sending email:", error); } } else { // Document was deleted console.log("Document deleted:", newData.before.data()); } }, );
部署时出现如下错误:
PS C:\Users\Sameera\skypos-cloud-functions-repo> firebase deploy --only functions
(node:21484) [DEP0040] 弃用警告:punycode模块已被弃用,请改用第三方替代方案。(使用node --trace-deprecation ...查看警告产生位置)=== 正在部署到'skypos360-bedb0'...
i 正在部署functions 运行命令:npm --prefix "$RESOURCE_DIR" run lint
lint
eslint .
- functions: 预部署脚本执行完成。
i functions: 准备默认代码库用于部署
i functions: 确保所需API cloudfunctions.googleapis.com已启用...
i functions: 确保所需API cloudbuild.googleapis.com已启用...
i artifactregistry: 确保所需API artifactregistry.googleapis.com已启用...- functions: 所需API cloudfunctions.googleapis.com已启用
- artifactregistry: 所需API artifactregistry.googleapis.com已启用
- functions: 所需API cloudbuild.googleapis.com已启用
i functions: 加载并分析默认代码库的源代码以确定部署内容,服务端口8869i extensions: 确保所需API firebaseextensions.googleapis.com已启用...
- extensions: 所需API firebaseextensions.googleapis.com已启用
i functions: 准备functions目录用于上传...
i functions: 已打包C:\Users\Sameera\skypos-cloud-functions-repo\functions(69.22 KB)用于上传
i functions: 确保所需API run.googleapis.com已启用...
i functions: 确保所需API eventarc.googleapis.com已启用...
i functions: 确保所需API pubsub.googleapis.com已启用...
i functions: 确保所需API storage.googleapis.com已启用...- functions: 所需API pubsub.googleapis.com已启用
- functions: 所需API run.googleapis.com已启用
- functions: 所需API eventarc.googleapis.com已启用
- functions: 所需API storage.googleapis.com已启用
i functions: 为pubsub.googleapis.com生成服务标识...
i functions: 为eventarc.googleapis.com生成服务标识...- functions: functions文件夹上传成功
i functions: 创建Node.js 18(2nd Gen)函数sendEmailOnNewDocument(us-central1)...
构建失败,状态:FAILURE。由于构建服务账号缺少权限,无法构建函数。如果您未显式撤销该权限,可能是组织策略变更导致的。以下函数部署出错:
sendEmailOnNewDocument(us-central1)
i functions: 清理构建文件...
! functions: 清理构建镜像时出现未处理错误。若不修正可能会产生小额月度账单。您可以尝试重新部署来删除这些镜像,或手动删除:错误:部署functions时出错
请问需要在哪里以及如何授予该权限?
1. 定位构建服务账号
构建服务账号的格式为:[你的Firebase项目编号]@cloudbuild.gserviceaccount.com
你可以通过Google Cloud控制台的IAM与管理员页面找到该账号,或从Firebase项目设置中获取关联的Google Cloud项目编号来拼接账号名。
2. 授予必要权限
进入Google Cloud控制台的IAM与管理员 > IAM页面:
- 找到上述构建服务账号,点击账号右侧的编辑图标
- 在「添加角色」下拉菜单中,添加以下角色:
Cloud Functions Developer:允许创建和管理Cloud Functions资源Cloud Build Editor:赋予构建服务账号编辑Cloud Build资源的权限Artifact Registry Writer:用于管理构建生成的镜像存储
- 保存权限更改
3. 重新部署
权限生效后,再次运行firebase deploy --only functions即可完成部署。
注意:如果你的项目隶属于某个组织,可能需要联系组织管理员确认是否有组织策略限制了这些权限的授予。
内容的提问来源于stack exchange,提问作者Sameera Tennakoon

