无法禁用certificatemanager.googleapis.com:如何查找关联资源?
解决GCP Certificate Manager API无法禁用的关联资源排查方法
问题描述
尝试禁用项目prj1的certificatemanager.googleapis.com服务时,收到报错:
禁用项目"prj1"的"certificatemanager.googleapis.com"服务失败:等待API禁用时出错:错误代码9,消息:[服务'certificatemanager.googleapis.com'错误:该项目无法停用此服务;请确保没有该服务管理的资源。
已执行以下命令列出指定区域资源,仅返回无法删除的operations资源:
gcloud certificate-manager certificates list --location=us-west1 gcloud certificate-manager dns-authorizations list --location=us-west1 gcloud certificate-manager issuance-configs list --location=us-west1 gcloud certificate-manager maps list --location=us-west1 gcloud certificate-manager operations list --location=us-west1 gcloud certificate-manager trust-configs list --location=us-west1 gcloud certificate-manager maps entries list --location=us-west1
排查关联资源的步骤
检查全局区域资源
多数Certificate Manager资源为全局(global)级而非区域级,执行以下命令查看全局范围的资源:gcloud certificate-manager certificates list --location=global gcloud certificate-manager dns-authorizations list --location=global gcloud certificate-manager issuance-configs list --location=global gcloud certificate-manager maps list --location=global gcloud certificate-manager trust-configs list --location=global gcloud certificate-manager maps entries list --location=global清理残留Operations资源
针对无法删除的操作记录,尝试取消或清理:# 获取所有操作ID gcloud certificate-manager operations list --location=us-west1 --format="value(name)" # 逐个取消操作 gcloud certificate-manager operations cancel [OPERATION_ID] --location=us-west1 # 尝试删除已完成的残留操作记录 gcloud certificate-manager operations delete [OPERATION_ID] --location=us-west1排查跨服务关联资源
其他GCP服务可能引用了Certificate Manager资源,重点检查:- 负载均衡器:查看HTTPS负载均衡器是否关联了Certificate Manager证书:
若输出包含格式类似gcloud compute target-https-proxies list --format="value(name,sslCertificates)"projects/prj1/locations/global/certificates/xxx的资源ID,需先更新负载均衡器移除该引用。 - Cloud CDN:若CDN配置了HTTPS,确认是否使用了Certificate Manager管理的证书。
- 负载均衡器:查看HTTPS负载均衡器是否关联了Certificate Manager证书:
使用资源搜索工具
通过GCP资产搜索命令,查找项目内所有归属Certificate Manager服务的资源:gcloud asset search-all-resources --query="serviceType:certificatemanager.googleapis.com" --project=prj1检查项目级默认配置
查看是否存在项目级别的Certificate Manager默认配置:gcloud certificate-manager settings describe --project=prj1
内容的提问来源于stack exchange,提问作者Gary Ox64
相关产品推荐
相关产品推荐

