Google Cloud Run部署gRpc容器后Postman无法调用问题求助
Cloud Run部署gRPC服务后Postman调用异常的排查与解决
问题概述
已在Google Cloud Run中部署gRPC容器,启用HTTP/2流量并允许未认证访问,容器日志显示gRPC服务已启动并监听端口,但Postman调用时出现以下异常:
- 不带HTTPS的URL返回“Call Cancelled”
- 带HTTPS协议无法调用目标方法
服务配置信息
Cloud Run服务YAML配置如下:
apiVersion: serving.knative.dev/v1 kind: Service metadata: name: my-service namespace: '165746377172' selfLink: /apis/serving.knative.dev/v1/namespaces/165746377172/services/my-service uid: f0188bd4-e5bb-4ab9-ba48-6d33f46251e0 resourceVersion: kjhkjhk generation: 2 creationTimestamp: '2024-05-28T09:03:56.993590Z' labels: run.googleapis.com/satisfiesPzs: 'true' cloud.googleapis.com/location: asia-south1 annotations: serving.knative.dev/creator: sainageswar@gmail.com serving.knative.dev/lastModifier: sainageswar@gmail.com run.googleapis.com/client-name: cloud-console run.googleapis.com/operation-id: 8a00ba77-7c0f-4267-9982-caaf4eb4bf81 run.googleapis.com/ingress: all run.googleapis.com/ingress-status: all spec: template: metadata: labels: client.knative.dev/nonce: 8fe5a91f-6d44-465e-9e6e-6bde389112d5 run.googleapis.com/startupProbeType: Default annotations: autoscaling.knative.dev/maxScale: '3' run.googleapis.com/client-name: cloud-console run.googleapis.com/startup-cpu-boost: 'true' spec: containerConcurrency: 80 timeoutSeconds: 300 serviceAccountName: 165746377172-compute@developer.gserviceaccount.com containers: - name: potter image: docker.io/myImage ports: - name: h2c containerPort: 50051 env: - name: AZURE_TENANT_ID value: xyz - name: AZURE_CLIENT_ID value: abc resources: limits: cpu: 1000m memory: 512Mi startupProbe: timeoutSeconds: 240 periodSeconds: 240 failureThreshold: 1 tcpSocket: port: 50051 traffic: - percent: 100 latestRevision: true status: observedGeneration: 2 conditions: - type: Ready status: 'True' lastTransitionTime: '2024-05-28T09:49:02.523953Z' - type: ConfigurationsReady status: 'True' lastTransitionTime: '2024-05-28T09:03:57.100438Z' - type: RoutesReady status: 'True' lastTransitionTime: '2024-05-28T09:49:02.477867Z' latestReadyRevisionName: hjgjhgj latestCreatedRevisionName: iouoiuoiu traffic: - revisionName: hgjhgjhg percent: 100 latestRevision: true url: https://bnma-el.a.run.app address: url: https://bnma-el.a.run.app
排查与解决步骤
1. 明确Cloud Run的gRPC访问规则
Cloud Run仅支持HTTPS上的gRPC(gRPC over TLS),不允许外部直接访问明文HTTP/2(h2c)服务:
- 不带HTTPS的请求会被Cloud Run入口拦截,无法建立有效连接,因此返回“Call Cancelled”,必须使用HTTPS协议访问。
2. 修正Postman的gRPC配置
带HTTPS无法调用方法通常是Postman配置错误,需检查以下几点:
- 确保选择gRPC请求类型(而非普通HTTP请求)。
- 请求URL填写
https://bnma-el.a.run.app:443:Cloud Run默认使用443端口,无需指定容器内部的50051端口,平台会自动完成外部HTTPS到内部h2c端口的转发。 - 导入正确的
.proto文件,确保方法名、参数结构与gRPC服务定义完全匹配。 - 确认Postman的gRPC设置中TLS已启用(默认开启,无需手动添加证书,Postman会自动验证Cloud Run的官方证书)。
3. 验证容器端口配置的正确性
从YAML配置看,容器端口的name设置为h2c是正确的,该标识告诉Cloud Run容器监听的是明文HTTP/2流量,平台会自动处理TLS终止与流量转发,此配置无需修改。
4. 用grpcurl工具验证服务可用性
如果Postman仍有问题,可使用grpcurl工具测试服务是否正常,命令示例:
grpcurl -d '{"your_param": "value"}' bnma-el.a.run.app:443 your.package.YourService/YourMethod
替换your.package.YourService/YourMethod为实际的服务包名、服务名和方法名,若能正常返回结果,说明服务本身无问题,问题出在Postman配置。
5. 检查容器内gRPC服务的监听地址
确保容器内的gRPC服务监听的是0.0.0.0:50051,而非仅localhost。如果服务仅绑定localhost,Cloud Run无法将外部流量转发到容器内部,需修改服务启动命令的绑定地址。
内容的提问来源于stack exchange,提问作者SaiNageswar S
相关产品推荐
相关产品推荐

