You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Endpoints对接K8s Ingress认证失效问题排查

问题诊断与解决

你的GCP Endpoints认证不生效、无认证请求可直接访问的问题,核心原因及解决方法如下:

1. Security定义缺失关键字段x-google-audiences

你的服务账号认证配置中缺少x-google-audiences字段,这个字段用于指定JWT令牌的受众(Audience),必须设置为你的Endpoints主机名api.endpoints.testproj.cloud.goog。缺失该字段时,Endpoints无法验证令牌是否针对当前API颁发,会直接跳过认证检查。

修改后的securityDefinitions部分:

securityDefinitions:
  google_service_account:
    authorizationUrl: ""
    flow: "implicit"
    type: "oauth2"
    x-google-issuer: "test@testproj.iam.gserviceaccount.com"
    x-google-jwks_uri: "https://www.googleapis.com/robot/v1/metadata/x509/test@testproj.iam.gserviceaccount.com"
    x-google-audiences: "api.endpoints.testproj.cloud.goog"  # 新增该字段

2. 确保Security规则明确绑定到接口

虽然你配置了全局security规则,仍建议在具体接口操作级别显式添加规则,避免Endpoints忽略全局配置:

paths:
  "/":
    get:
      description: "Echo back a given message."
      operationId: "echo"
      security:
        - google_service_account: []  # 显式绑定到当前接口
      responses:
        200:
          description: "Success."
          schema:
            type: string
        400:
          description: "The data structure is invalid or missing."

3. 重新部署Endpoints配置

修改openapi.yaml后,必须重新部署配置到GCP,否则旧的无认证配置仍会生效:

gcloud endpoints services deploy openapi.yaml

4. 改用HTTPS协议

当前配置使用http协议,HTTP环境下可能存在认证逻辑被绕过的情况。生产环境建议强制使用HTTPS:

schemes:
- "https"

额外验证点

  • 确认x-google-issuer中的服务账号邮箱正确,且该账号在GCP IAM中存在;
  • 检查x-google-endpoints中的target字段是否正确指向K8s Ingress的LB IP。

内容的提问来源于stack exchange,提问作者pythonhmmm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 11:43:16