You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行Cloud Run Job时推送镜像至GCP Artifact Registry遇权限错误求助

推送镜像至Artifact Registry时遇权限错误排查

我按照GCP官方指南执行Cloud Run Job,在通过Google Cloud SDK推送容器镜像到Artifact Registry时遇到权限问题。

执行的命令

export SERVICE_NAME=parallel-job
gcloud builds submit \
    --pack image=us-central1-docker.pkg.dev/casentric-classifier/my-repo/${SERVICE_NAME}

报错信息

Successfully built image 'us-central1-docker.pkg.dev/casentric-classifier/my-repo/parallel-job'
PUSH
Pushing us-central1-docker.pkg.dev/casentric-classifier/my-repo/parallel-job
The push refers to repository [us-central1-docker.pkg.dev/casentric-classifier/my-repo/parallel-job]
744c9ff06f7e: Preparing
0bb83f7438cd: Preparing
792a42128dc1: Preparing
3e933186f9b6: Preparing
36f9de0748c4: Preparing
8e9f20ffb142: Preparing
79971806f283: Preparing
9025ac911ca6: Preparing
dc2bd61bfaf6: Preparing
6213d5ec7fee: Preparing
629ca62fb7c7: Preparing
8e9f20ffb142: Waiting
79971806f283: Waiting
9025ac911ca6: Waiting
dc2bd61bfaf6: Waiting
6213d5ec7fee: Waiting
629ca62fb7c7: Waiting
denied: Permission "artifactregistry.repositories.uploadArtifacts" denied on resource "projects/casentric-classifier/locations/us-central1/repositories/my-repo" (or it may not exist)
Pushing us-central1-docker.pkg.dev/casentric-classifier/my-repo/parallel-job
The push refers to repository [us-central1-docker.pkg.dev/casentric-classifier/my-repo/parallel-job]

已完成的操作

  • 执行gcloud auth login完成账号登录
  • 执行gcloud auth configure-docker us-central1-docker.pkg.dev配置Docker认证

排查解决方案

  1. 确认目标仓库存在
    先验证Artifact Registry中指定的仓库是否存在:

    gcloud artifacts repositories list --location=us-central1 --project=casentric-classifier
    

    如果未找到my-repo,需先创建仓库:

    gcloud artifacts repositories create my-repo --repository-format=docker --location=us-central1 --project=casentric-classifier
    
  2. 检查本地登录账号权限
    确认当前登录账号是否拥有镜像上传权限:

    gcloud projects get-iam-policy casentric-classifier --filter="bindings.members:$(gcloud config get-value account)" --format="value(bindings.role)"
    

    若输出中没有roles/artifactregistry.writer、roles/editor或roles/owner这类包含上传权限的角色,需前往GCP控制台IAM页面,给账号添加Artifact Registry Writer角色(按需选择合适权限等级)。

  3. 授权Cloud Build服务账号
    由于使用gcloud builds submit时,实际执行推送的是Cloud Build的服务账号,而非本地登录账号,需给该服务账号赋予权限:

    # 获取Cloud Build服务账号邮箱
    CLOUD_BUILD_ACCOUNT=$(gcloud projects describe casentric-classifier --format='value(projectNumber)')@cloudbuild.gserviceaccount.com
    # 赋予镜像上传权限
    gcloud projects add-iam-policy-binding casentric-classifier \
        --member="serviceAccount:${CLOUD_BUILD_ACCOUNT}" \
        --role="roles/artifactregistry.writer"
    
  4. 重新执行推送命令
    完成上述配置后,再次运行最初的镜像推送命令即可。

内容的提问来源于stack exchange,提问作者Ryan Tracy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 16:27:27