You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP实例创建权限异常:iam.serviceAccountUser角色配置无效求助

GCP实例创建权限问题排查(已授予iam.serviceAccountUser角色仍报错)

创建squidproxy和bastion实例时均失败,错误提示用户brahatheeswaran.parimalam@abcdefg.com.au无权限访问对应的服务账号,即使已为该用户添加iam.serviceAccountUser角色,问题依然存在。报错详情如下:

Error: Error waiting for instance to create: The user does not have access to service account 'squidsit-squid-sit@igd-poc-417106.iam.gserviceaccount.com'. Use: 'brahatheeswaran.parimalam@abcdefg.com.au'. Ask a project owner to grant you the iam.serviceAccountUser role on the service account.
with module.zkevm_full.google_compute_instance.squidproxy[0],
on ../modules/zkevm/instance.tf line 157, in resource "google_compute_instance" "squidproxy":
157: resource "google_compute_instance" "squidproxy" {.

Error: Error waiting for instance to create: The user does not have access to service account 'bastion-fork-7-sit@igd-poc-417106.iam.gserviceaccount.com'. Use: 'brahatheeswaran.parimalam@abcdefg.com.au'. Ask a project owner to grant you the iam.serviceAccountUser role on the service account.
with module.zkevm_full.google_compute_instance.bastion,
on ../modules/zkevm/instance.tf line 194, in resource "google_compute_instance" "bastion":
194: resource "google_compute_instance" "bastion" {.

排查步骤

  • 确认角色授予目标正确性:检查是否将iam.serviceAccountUser角色直接授予用户brahatheeswaran.parimalam@abcdefg.com.au,且是针对报错中的具体服务账号(而非项目级泛授权)。操作路径:GCP控制台 → IAM与管理员 → 服务账号 → 找到对应服务账号 → 编辑权限 → 添加成员,输入用户邮箱并选择Service Account User角色。
  • 等待权限生效延迟:GCP IAM权限可能存在5-10分钟的生效延迟,授予角色后等待一段时间再重试实例创建。
  • 验证用户实际权限:用gcloud命令检查用户对目标服务账号的权限:
    # 检查项目级绑定的角色
    gcloud projects get-iam-policy igd-poc-417106 --filter="bindings.members:brahatheeswaran.parimalam@abcdefg.com.au" --format="value(bindings.role)"
    
    # 检查单个服务账号的绑定角色
    gcloud iam service-accounts get-iam-policy squidsit-squid-sit@igd-poc-417106.iam.gserviceaccount.com --filter="bindings.members:brahatheeswaran.parimalam@abcdefg.com.au" --format="value(bindings.role)"
    
    确认输出包含roles/iam.serviceAccountUser。
  • 检查Terraform执行身份:确认执行Terraform的身份是brahatheeswaran.parimalam@abcdefg.com.au,而非其他账号。执行以下命令验证当前gcloud身份:
    gcloud config get-value account
    
  • 排查政策冲突:若项目存在组织级IAM政策或Terraform的google_iam_policy资源,可能覆盖服务账号的单独权限设置,需确认是否存在冲突政策。

内容的提问来源于stack exchange,提问作者Brahatheeswaran Parimalam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 05:27:33