GCP Endpoints对接K8s Ingress认证失效问题排查
问题诊断与解决
你的GCP Endpoints认证不生效、无认证请求可直接访问的问题,核心原因及解决方法如下:
1. Security定义缺失关键字段x-google-audiences
你的服务账号认证配置中缺少x-google-audiences字段,这个字段用于指定JWT令牌的受众(Audience),必须设置为你的Endpoints主机名api.endpoints.testproj.cloud.goog。缺失该字段时,Endpoints无法验证令牌是否针对当前API颁发,会直接跳过认证检查。
修改后的securityDefinitions部分:
securityDefinitions: google_service_account: authorizationUrl: "" flow: "implicit" type: "oauth2" x-google-issuer: "test@testproj.iam.gserviceaccount.com" x-google-jwks_uri: "https://www.googleapis.com/robot/v1/metadata/x509/test@testproj.iam.gserviceaccount.com" x-google-audiences: "api.endpoints.testproj.cloud.goog" # 新增该字段
2. 确保Security规则明确绑定到接口
虽然你配置了全局security规则,仍建议在具体接口操作级别显式添加规则,避免Endpoints忽略全局配置:
paths: "/": get: description: "Echo back a given message." operationId: "echo" security: - google_service_account: [] # 显式绑定到当前接口 responses: 200: description: "Success." schema: type: string 400: description: "The data structure is invalid or missing."
3. 重新部署Endpoints配置
修改openapi.yaml后,必须重新部署配置到GCP,否则旧的无认证配置仍会生效:
gcloud endpoints services deploy openapi.yaml
4. 改用HTTPS协议
当前配置使用http协议,HTTP环境下可能存在认证逻辑被绕过的情况。生产环境建议强制使用HTTPS:
schemes: - "https"
额外验证点
- 确认
x-google-issuer中的服务账号邮箱正确,且该账号在GCP IAM中存在; - 检查
x-google-endpoints中的target字段是否正确指向K8s Ingress的LB IP。
内容的提问来源于stack exchange,提问作者pythonhmmm
相关产品推荐
相关产品推荐

