You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub Actions部署至Google Cloud Artifact Registry遇权限问题

问题描述

尝试通过GitHub Actions将镜像推送至Google Cloud Artifact Registry时,遇到以下权限错误:

github actions
google cloud artifact registry
未认证请求无权限"artifactregistry.repositories.uploadArtifacts"

ERROR: (gcloud.auth.docker-helper) 刷新当前认证令牌时出现问题: ('Unable to acquire impersonated credentials', '{
"error": {
"code": 403,
"message": "Permission 'iam.serviceAccounts.getAccessToken' denied on resource (or it may not exist).",
"status": "PERMISSION_DENIED",
"details": [
{
"@type": "type.googleapis.com/google.rpc.ErrorInfo",
"reason": "IAM_PERMISSION_DENIED",
"domain": "iam.googleapis.com",
"metadata": {
"permission": "iam.serviceAccounts.getAccessToken"
}
}
]
}
}
')
请运行:
$ gcloud auth login
以获取新凭据。
如果您已使用其他账号登录,请运行:
$ gcloud config set account ACCOUNT
以选择一个已认证的账号使用。
推送指向仓库[***/front-end]
2bb4a2be8519: Preparing
d26381110329: Preparing
e81429117070: Preparing
7bf3eb1a80e4: Preparing
43adef21ed65: Preparing
f7df5efb2c99: Preparing
5b316f9079a1: Preparing
5e19cd5b03d0: Preparing
678ea5c52c14: Preparing
8d853c8add5d: Preparing
f7df5efb2c99: Waiting
5b316f9079a1: Waiting
5e19cd5b03d0: Waiting
678ea5c52c14: Waiting
8d853c8add5d: Waiting
denied: 未认证请求。未认证请求无权限"artifactregistry.repositories.uploadArtifacts"访问资源

解决方法

1. 配置服务账号权限

确保GitHub Actions使用的GCP服务账号拥有以下两个关键权限:

  • artifactregistry.repositories.uploadArtifacts:直接授予Artifact Registry Writer角色即可
  • iam.serviceAccounts.getAccessToken:授予Service Account Token Creator角色(用于生成访问令牌完成认证)

操作步骤:

  • 打开GCP控制台的IAM页面,找到目标服务账号
  • 点击"添加角色",分别添加上述两个角色

2. 修正GitHub Actions认证流程

使用官方的Google Cloud GitHub Actions完成认证和Docker配置:

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@v4

      - name: Authenticate to Google Cloud
        uses: google-github-actions/auth@v1
        with:
          # 推荐使用工作负载身份(无需管理密钥),或使用服务账号密钥
          workload_identity_provider: 'projects/[你的项目ID]/locations/global/workloadIdentityPools/[你的池ID]/providers/[你的提供者ID]'
          service_account: '[你的服务账号邮箱]'
          # 或者使用密钥(不推荐长期使用)
          # credentials_json: ${{ secrets.GCP_SERVICE_ACCOUNT_KEY }}

      - name: Configure Docker for Artifact Registry
        uses: google-github-actions/docker-auth@v1
        with:
          registries: [你的仓库域名,比如us-central1-docker.pkg.dev]

      - name: Build and push Docker image
        run: |
          docker build -t [你的仓库域名]/[你的项目ID]/[你的仓库名]/front-end:latest .
          docker push [你的仓库域名]/[你的项目ID]/[你的仓库名]/front-end:latest

3. 验证镜像标记格式

确保镜像的标记完全匹配Artifact Registry的路径格式:
[区域]-docker.pkg.dev/[GCP项目ID]/[仓库名称]/[镜像名称]:[标签]

内容的提问来源于stack exchange,提问作者Nguyễn Viết Lam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 22:24:54