You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Functions部署报错403:项目读取权限被拒求助

解决GCP Cloud Functions部署时的403 "Read access to project was denied"错误

问题场景

日常使用GCP Console及gcloud functions deploy部署Gen2 Cloud Functions,此前操作正常,今日执行部署命令时触发403错误:

ERROR: (gcloud.functions.deploy) ResponseError: status=[403], code=[Ok], message=[Read access to project 'project-id' was denied]

执行的部署命令如下:

gcloud functions deploy cloud-function-name --gen2 --concurrency=1000 --memory=4G --timeout=3600 --source=. --entry-point=entry_point --region africa-south1 --runtime python312 --min-instances 0 --max-instances 5 --trigger-http --env-vars-file .env.yaml --service-account service-account-name.com --update-labels name=label-name

当前登录SDK Shell的账号及命令指定的服务账号均已配置Cloud Functions Developer角色,但权限问题仍存在。

排查与解决方案

1. 检查gcloud CLI的当前授权项目

  • 执行命令确认CLI绑定的项目是否为目标project-id:
    gcloud config get-value project
    
  • 如果输出不是目标项目,执行切换命令:
    gcloud config set project project-id
    

2. 修正服务账号格式错误

命令中--service-account参数格式不符合GCP要求,正确的服务账号格式应为[账号名]@[项目ID].iam.gserviceaccount.com,而非service-account-name.com。

  • 将命令中的服务账号参数修正为完整的IAM邮箱格式,例如:
    --service-account service-account-name@project-id.iam.gserviceaccount.com
    

3. 补充Gen2函数部署所需的额外权限

Gen2 Cloud Functions依赖Artifact Registry存储函数镜像,Cloud Functions Developer角色默认不包含Artifact Registry的操作权限,会导致部署时权限不足:

  • 为登录账号及服务账号添加Artifact Registry Writer角色(或更细粒度的artifactregistry.repositories.create、artifactregistry.repositories.update权限)。

4. 检查项目组织政策限制

若项目隶属于GCP组织,可能存在组织政策限制Cloud Functions部署:

  • 进入GCP Console的「IAM与管理员」→「组织政策」,检查以下政策:
    • constraints/cloudfunctions.allowedServiceAccounts:确认指定的服务账号在允许列表内
    • constraints/cloudfunctions.disableDeployment:确保该政策未设置为「强制执行」

5. 更新gcloud CLI到最新版本

旧版本gcloud CLI可能对Gen2函数的权限逻辑处理存在bug:

  • 执行命令更新组件:
    gcloud components update
    

内容的提问来源于stack exchange,提问作者imartov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 09:11:10