拥有Artifact Registry Admin权限的GCP服务账号无法推送Docker镜像
问题:Artifact Registry推送Docker镜像提示未授权
问题背景
我使用的GCP服务账号已分配「Artifact Registry Admin」角色,但通过GitHub Action推送Docker镜像到Artifact Registry仓库时失败,提示未授权。
GitHub Action配置文件
name: CI on: push: branches: - main pull_request: workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: dependencies: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - uses: actions/setup-python@v4 with: cache: pip python-version: "3.12" - name: Install dependencies run: | python -m pip install --upgrade pip pip install -r requirements.txt deploy: needs: [dependencies] runs-on: ubuntu-latest if: | github.event_name == 'workflow_dispatch' || (github.event_name == 'push' && github.ref == 'refs/heads/main') env: DOCKER_BUILDKIT: 1 steps: - uses: actions/checkout@v4 - name: Set up Google Cloud SDK uses: google-github-actions/setup-gcloud@v1 with: project_id: my-project-123456 service_account_key: ${{ secrets.GOOGLE_AUTHENTICATION_CREDENTIALS_JSON }} export_default_credentials: true - name: Authorize Docker push run: gcloud auth configure-docker us-west1-docker.pkg.dev # Docker builder image - name: Build Builder with Cache id: build-with-cache continue-on-error: true run: >- docker build --build-arg BUILDKIT_INLINE_CACHE=1 -f Dockerfile --cache-from ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest --target builder . - name: Build Builder with Cache failed -> Build Builder without Cache if: ${{ steps.build-with-cache.outcome == 'failure' }} run: >- docker build -f Dockerfile -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest --target builder . # Docker runtime image - name: Build Runtime with Cache id: build-runtime-with-cache continue-on-error: true run: >- docker build --build-arg COLLECT_STATIC=1 --build-arg BUILDKIT_INLINE_CACHE=1 -f Dockerfile --cache-from ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }} -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest . - name: Build Runtime with Cache failed -> Build Runtime without Cache if: ${{ steps.build-runtime-with-cache.outcome == 'failure' }} run: >- docker build --build-arg COLLECT_STATIC=1 -f Dockerfile -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }} -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest . - name: Push builder image to Artifact Registry run: docker push --all-tags ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder - name: Push runtime image to Artifact Registry run: docker push --all-tags ${{ secrets.RUNTIME_DOCKERIMAGE_URL }} - name: Deploy to Cloud Run uses: google-github-actions/deploy-cloudrun@v1 with: service: ${{ secrets.CLOUD_RUN_NAME }} image: ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }} region: us-west1
错误信息
denied: Unauthenticated request. Unauthenticated requests do not have permission "artifactregistry.repositories.uploadArtifacts" on resource "projects/***-123456/locations/us-west1/repositories/***-repo" (or it may not exist)
已确认的配置
- 服务账号已分配「Artifact Registry Admin」角色
- GitHub密钥
GOOGLE_AUTHENTICATION_CREDENTIALS_JSON的值为服务账号密钥JSON文件内容 - 镜像地址
RUNTIME_DOCKERIMAGE_URL设置为:us-west1-docker.pkg.dev/my-project-123456/my-project-repo/my-project
排查与解决方案
1. 验证服务账号权限绑定范围
- 确认「Artifact Registry Admin」角色是绑定在整个项目或者目标Artifact Registry仓库上,而非仅绑定在服务账号自身或其他无关资源上。
- 检查是否存在组织政策限制,比如项目启用了权限继承拦截规则,导致角色权限被覆盖。
2. 修复Docker认证配置
替换当前的Authorize Docker push步骤,使用显式登录命令确保Docker客户端正确获取GCP凭证:
docker login -u oauth2accesstoken -p "$(gcloud auth print-access-token)" us-west1-docker.pkg.dev
3. 检查服务账号密钥有效性
- 确认服务账号密钥未过期、未被撤销,可重新生成新密钥并更新GitHub Secrets后重试。
4. 验证镜像地址与仓库匹配
- 确认
RUNTIME_DOCKERIMAGE_URL中的仓库名称my-project-repo与GCP实际存在的仓库名称完全一致(区分大小写)。 - 检查仓库区域
us-west1是否与配置一致,Artifact Registry为区域级资源,区域不匹配会导致权限验证失败。
5. 确认GitHub Action环境凭证
在Set up Google Cloud SDK步骤后添加验证命令,确认凭证正确导出:
gcloud auth list gcloud config get-value project
确保输出显示目标服务账号和项目ID。
内容的提问来源于stack exchange,提问作者Laodao
相关产品推荐
相关产品推荐

