You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Run部署gRpc容器后Postman无法调用问题求助

Cloud Run部署gRPC服务后Postman调用异常的排查与解决

问题概述

已在Google Cloud Run中部署gRPC容器,启用HTTP/2流量并允许未认证访问,容器日志显示gRPC服务已启动并监听端口,但Postman调用时出现以下异常:

  • 不带HTTPS的URL返回“Call Cancelled”
  • 带HTTPS协议无法调用目标方法

服务配置信息

Cloud Run服务YAML配置如下:

apiVersion: serving.knative.dev/v1
kind: Service
metadata:
  name: my-service
  namespace: '165746377172'
  selfLink: /apis/serving.knative.dev/v1/namespaces/165746377172/services/my-service
  uid: f0188bd4-e5bb-4ab9-ba48-6d33f46251e0
  resourceVersion: kjhkjhk
  generation: 2
  creationTimestamp: '2024-05-28T09:03:56.993590Z'
  labels:
    run.googleapis.com/satisfiesPzs: 'true'
    cloud.googleapis.com/location: asia-south1
  annotations:
    serving.knative.dev/creator: sainageswar@gmail.com
    serving.knative.dev/lastModifier: sainageswar@gmail.com
    run.googleapis.com/client-name: cloud-console
    run.googleapis.com/operation-id: 8a00ba77-7c0f-4267-9982-caaf4eb4bf81
    run.googleapis.com/ingress: all
    run.googleapis.com/ingress-status: all
spec:
  template:
    metadata:
      labels:
        client.knative.dev/nonce: 8fe5a91f-6d44-465e-9e6e-6bde389112d5
        run.googleapis.com/startupProbeType: Default
      annotations:
        autoscaling.knative.dev/maxScale: '3'
        run.googleapis.com/client-name: cloud-console
        run.googleapis.com/startup-cpu-boost: 'true'
    spec:
      containerConcurrency: 80
      timeoutSeconds: 300
      serviceAccountName: 165746377172-compute@developer.gserviceaccount.com
      containers:
      - name: potter
        image: docker.io/myImage
        ports:
        - name: h2c
          containerPort: 50051
        env:
        - name: AZURE_TENANT_ID
          value: xyz
        - name: AZURE_CLIENT_ID
          value: abc
        resources:
          limits:
            cpu: 1000m
            memory: 512Mi
        startupProbe:
          timeoutSeconds: 240
          periodSeconds: 240
          failureThreshold: 1
          tcpSocket:
            port: 50051
  traffic:
  - percent: 100
    latestRevision: true
status:
  observedGeneration: 2
  conditions:
  - type: Ready
    status: 'True'
    lastTransitionTime: '2024-05-28T09:49:02.523953Z'
  - type: ConfigurationsReady
    status: 'True'
    lastTransitionTime: '2024-05-28T09:03:57.100438Z'
  - type: RoutesReady
    status: 'True'
    lastTransitionTime: '2024-05-28T09:49:02.477867Z'
  latestReadyRevisionName: hjgjhgj
  latestCreatedRevisionName: iouoiuoiu
  traffic:
  - revisionName: hgjhgjhg
    percent: 100
    latestRevision: true
  url: https://bnma-el.a.run.app
  address:
    url: https://bnma-el.a.run.app

排查与解决步骤

1. 明确Cloud Run的gRPC访问规则

Cloud Run仅支持HTTPS上的gRPC(gRPC over TLS),不允许外部直接访问明文HTTP/2(h2c)服务:

  • 不带HTTPS的请求会被Cloud Run入口拦截,无法建立有效连接,因此返回“Call Cancelled”,必须使用HTTPS协议访问。

2. 修正Postman的gRPC配置

带HTTPS无法调用方法通常是Postman配置错误,需检查以下几点:

  • 确保选择gRPC请求类型(而非普通HTTP请求)。
  • 请求URL填写https://bnma-el.a.run.app:443:Cloud Run默认使用443端口,无需指定容器内部的50051端口,平台会自动完成外部HTTPS到内部h2c端口的转发。
  • 导入正确的.proto文件,确保方法名、参数结构与gRPC服务定义完全匹配。
  • 确认Postman的gRPC设置中TLS已启用(默认开启,无需手动添加证书,Postman会自动验证Cloud Run的官方证书)。

3. 验证容器端口配置的正确性

从YAML配置看,容器端口的name设置为h2c是正确的,该标识告诉Cloud Run容器监听的是明文HTTP/2流量,平台会自动处理TLS终止与流量转发,此配置无需修改。

4. 用grpcurl工具验证服务可用性

如果Postman仍有问题,可使用grpcurl工具测试服务是否正常,命令示例:

grpcurl -d '{"your_param": "value"}' bnma-el.a.run.app:443 your.package.YourService/YourMethod

替换your.package.YourService/YourMethod为实际的服务包名、服务名和方法名,若能正常返回结果,说明服务本身无问题,问题出在Postman配置。

5. 检查容器内gRPC服务的监听地址

确保容器内的gRPC服务监听的是0.0.0.0:50051,而非仅localhost。如果服务仅绑定localhost,Cloud Run无法将外部流量转发到容器内部,需修改服务启动命令的绑定地址。

内容的提问来源于stack exchange,提问作者SaiNageswar S

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 08:45:00