GCP实例创建权限异常:iam.serviceAccountUser角色配置无效求助
创建squidproxy和bastion实例时均失败,错误提示用户brahatheeswaran.parimalam@abcdefg.com.au无权限访问对应的服务账号,即使已为该用户添加iam.serviceAccountUser角色,问题依然存在。报错详情如下:
Error: Error waiting for instance to create: The user does not have access to service account 'squidsit-squid-sit@igd-poc-417106.iam.gserviceaccount.com'. Use: 'brahatheeswaran.parimalam@abcdefg.com.au'. Ask a project owner to grant you the iam.serviceAccountUser role on the service account.
with module.zkevm_full.google_compute_instance.squidproxy[0],
on ../modules/zkevm/instance.tf line 157, in resource "google_compute_instance" "squidproxy":
157: resource "google_compute_instance" "squidproxy" {.Error: Error waiting for instance to create: The user does not have access to service account 'bastion-fork-7-sit@igd-poc-417106.iam.gserviceaccount.com'. Use: 'brahatheeswaran.parimalam@abcdefg.com.au'. Ask a project owner to grant you the iam.serviceAccountUser role on the service account.
with module.zkevm_full.google_compute_instance.bastion,
on ../modules/zkevm/instance.tf line 194, in resource "google_compute_instance" "bastion":
194: resource "google_compute_instance" "bastion" {.
排查步骤
- 确认角色授予目标正确性:检查是否将
iam.serviceAccountUser角色直接授予用户brahatheeswaran.parimalam@abcdefg.com.au,且是针对报错中的具体服务账号(而非项目级泛授权)。操作路径:GCP控制台 → IAM与管理员 → 服务账号 → 找到对应服务账号 → 编辑权限 → 添加成员,输入用户邮箱并选择Service Account User角色。 - 等待权限生效延迟:GCP IAM权限可能存在5-10分钟的生效延迟,授予角色后等待一段时间再重试实例创建。
- 验证用户实际权限:用gcloud命令检查用户对目标服务账号的权限:
确认输出包含# 检查项目级绑定的角色 gcloud projects get-iam-policy igd-poc-417106 --filter="bindings.members:brahatheeswaran.parimalam@abcdefg.com.au" --format="value(bindings.role)" # 检查单个服务账号的绑定角色 gcloud iam service-accounts get-iam-policy squidsit-squid-sit@igd-poc-417106.iam.gserviceaccount.com --filter="bindings.members:brahatheeswaran.parimalam@abcdefg.com.au" --format="value(bindings.role)"roles/iam.serviceAccountUser。 - 检查Terraform执行身份:确认执行Terraform的身份是
brahatheeswaran.parimalam@abcdefg.com.au,而非其他账号。执行以下命令验证当前gcloud身份:gcloud config get-value account - 排查政策冲突:若项目存在组织级IAM政策或Terraform的
google_iam_policy资源,可能覆盖服务账号的单独权限设置,需确认是否存在冲突政策。
内容的提问来源于stack exchange,提问作者Brahatheeswaran Parimalam

