You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

拥有Artifact Registry Admin权限的GCP服务账号无法推送Docker镜像

问题:Artifact Registry推送Docker镜像提示未授权

问题背景

我使用的GCP服务账号已分配「Artifact Registry Admin」角色,但通过GitHub Action推送Docker镜像到Artifact Registry仓库时失败,提示未授权。

GitHub Action配置文件

name: CI
on:
  push:
    branches:
      - main
  pull_request:
  workflow_dispatch:

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  dependencies:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: actions/setup-python@v4
        with:
          cache: pip
          python-version: "3.12"
      - name: Install dependencies
        run: |
          python -m pip install --upgrade pip
          pip install -r requirements.txt

  deploy:
    needs: [dependencies]
    runs-on: ubuntu-latest
    if: |
      github.event_name == 'workflow_dispatch' || (github.event_name == 'push' && github.ref == 'refs/heads/main')
    env:
      DOCKER_BUILDKIT: 1
    steps:
      - uses: actions/checkout@v4

      - name: Set up Google Cloud SDK
        uses: google-github-actions/setup-gcloud@v1
        with:
          project_id: my-project-123456
          service_account_key: ${{ secrets.GOOGLE_AUTHENTICATION_CREDENTIALS_JSON }}
          export_default_credentials: true  

      - name: Authorize Docker push
        run: gcloud auth configure-docker us-west1-docker.pkg.dev
        
      # Docker builder image
      - name: Build Builder with Cache
        id: build-with-cache
        continue-on-error: true
        run: >-
          docker build
          --build-arg BUILDKIT_INLINE_CACHE=1
          -f Dockerfile
          --cache-from ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest
          --target builder
          .

      - name: Build Builder with Cache failed -> Build Builder without Cache
        if: ${{ steps.build-with-cache.outcome == 'failure' }}
        run: >-
          docker build
          -f Dockerfile
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder:latest
          --target builder
          .

      # Docker runtime image
      - name: Build Runtime with Cache
        id: build-runtime-with-cache
        continue-on-error: true
        run: >-
          docker build
          --build-arg COLLECT_STATIC=1
          --build-arg BUILDKIT_INLINE_CACHE=1
          -f Dockerfile
          --cache-from ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }}
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest
          .

      - name: Build Runtime with Cache failed -> Build Runtime without Cache
        if: ${{ steps.build-runtime-with-cache.outcome == 'failure' }}
        run: >-
          docker build
          --build-arg COLLECT_STATIC=1
          -f Dockerfile
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }}
          -t ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:latest
          .

      - name: Push builder image to Artifact Registry
        run: docker push --all-tags ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}-builder

      - name: Push runtime image to Artifact Registry
        run: docker push --all-tags ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}

      - name: Deploy to Cloud Run
        uses: google-github-actions/deploy-cloudrun@v1
        with:
          service: ${{ secrets.CLOUD_RUN_NAME }}
          image: ${{ secrets.RUNTIME_DOCKERIMAGE_URL }}:${{ github.sha }}
          region: us-west1

错误信息

denied: Unauthenticated request. Unauthenticated requests do not have permission "artifactregistry.repositories.uploadArtifacts" on resource "projects/***-123456/locations/us-west1/repositories/***-repo" (or it may not exist)

已确认的配置

  • 服务账号已分配「Artifact Registry Admin」角色
  • GitHub密钥GOOGLE_AUTHENTICATION_CREDENTIALS_JSON的值为服务账号密钥JSON文件内容
  • 镜像地址RUNTIME_DOCKERIMAGE_URL设置为:us-west1-docker.pkg.dev/my-project-123456/my-project-repo/my-project

排查与解决方案

1. 验证服务账号权限绑定范围

  • 确认「Artifact Registry Admin」角色是绑定在整个项目或者目标Artifact Registry仓库上,而非仅绑定在服务账号自身或其他无关资源上。
  • 检查是否存在组织政策限制,比如项目启用了权限继承拦截规则,导致角色权限被覆盖。

2. 修复Docker认证配置

替换当前的Authorize Docker push步骤,使用显式登录命令确保Docker客户端正确获取GCP凭证:

docker login -u oauth2accesstoken -p "$(gcloud auth print-access-token)" us-west1-docker.pkg.dev

3. 检查服务账号密钥有效性

  • 确认服务账号密钥未过期、未被撤销,可重新生成新密钥并更新GitHub Secrets后重试。

4. 验证镜像地址与仓库匹配

  • 确认RUNTIME_DOCKERIMAGE_URL中的仓库名称my-project-repo与GCP实际存在的仓库名称完全一致(区分大小写)。
  • 检查仓库区域us-west1是否与配置一致,Artifact Registry为区域级资源,区域不匹配会导致权限验证失败。

5. 确认GitHub Action环境凭证

在Set up Google Cloud SDK步骤后添加验证命令,确认凭证正确导出:

gcloud auth list
gcloud config get-value project

确保输出显示目标服务账号和项目ID。

内容的提问来源于stack exchange,提问作者Laodao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 10:33:19