You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Run绑定服务账户无法生成Cloud Storage签名URL

问题原因

Cloud Run绑定的服务账户提供的是临时凭据(属于google.auth.compute_engine.credentials.Credentials类型),这类凭据仅包含访问令牌,没有私钥。而你当前调用的generate_signed_url默认依赖私钥完成签名操作,所以即使服务账户有Storage权限,也会触发这个错误。

解决方案(无需服务账户密钥)

方法1:使用IAM Credentials API生成签名URL

这是Google推荐的无密钥签名方式,通过调用IAM Credentials API完成签名,依赖服务账户的权限而非本地私钥:

  1. 添加必要权限:给你的main-app@tapnfc-ef8ce.iam.gserviceaccount.com服务账户添加Service Account Token Creator角色(该角色允许服务账户调用IAM Credentials API生成签名)。
  2. 修改代码:在生成签名URL时启用IAM签名,无需指定service_account_email参数(默认使用当前服务账户):
@classmethod
def view_documents(cls, email, filename) -> str | None:
    bucket = cls.client.bucket(cls.bucket_name)
    blob = bucket.blob(f"{email}/{filename}")
    if blob.exists():
        url = blob.generate_signed_url(
            version="v4",
            response_disposition="inline",
            expiration=timedelta(minutes=15),
            method="GET",
            iam_signing=True  # 启用IAM签名
        )
        return url
    return None

注意:确保你的google-cloud-storage库版本足够新(建议>=2.0.0),旧版本可能不支持iam_signing参数。

方法2:使用Cloud Storage签名政策文档(可选)

如果只是需要控制用户对对象的临时访问,也可以使用签名政策文档,通过定义访问规则生成签名,同样不需要私钥,但配置相对复杂,适合批量或更精细的访问控制场景。


内容的提问来源于stack exchange,提问作者Phillip Ng

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 14:52:05