You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

解决Google Artifact Registry中ServiceAccount的operations.get权限拒绝问题

解决Google Artifact Registry删除后操作权限拒绝问题

我正尝试为ServiceAccount创建最小化自定义角色,用于从Google Artifact Registry删除制品。gcloud命令已成功删除制品,但后续对project.locations.operations的请求始终返回PERMISSION_DENIED。当前自定义角色包含以下权限:

artifactregistry.versions.delete,
artifactregistry.tags.get,
artifactregistry.tags.list,
artifactregistry.tags.delete,
artifactregistry.repositories.get,

执行删除命令后,最终出现如下错误:

ERROR: (gcloud.artifacts.docker.images.delete) PERMISSION_DENIED: Permission denied on operation projects/MYPROJ/locations/MYLOC/operations/12345-12345-12345-12345 (or it may not exist)

解决步骤

1. 添加对应权限到自定义角色

为ServiceAccount的自定义角色添加**artifactregistry.operations.get**权限(注意:Artifact Registry的操作权限属于自身服务权限组,而非通用的projects.locations.operations.get)。

2. 更新自定义角色的命令

使用gcloud命令更新现有自定义角色:

gcloud iam roles update [YOUR_CUSTOM_ROLE_NAME] \
  --project=[YOUR_PROJECT_ID] \
  --add-permissions=artifactregistry.operations.get

3. 验证权限生效

更新角色后,重新执行删除镜像的gcloud命令,即可正常获取操作状态,不再返回403权限拒绝错误。

补充说明

Google Cloud中各服务的操作资源权限归属对应服务的权限前缀,Artifact Registry的操作权限统一使用artifactregistry.operations.*前缀。若需查看所有Artifact Registry相关权限,可执行:

gcloud iam list-testable-permissions //artifactregistry.googleapis.com/

内容的提问来源于stack exchange,提问作者mathe_matician

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 02:55:18