已配置storage.buckets.get权限仍遇GCS 403禁止访问问题排查
问题分析与排查方向
问题概述
创建新服务账号并绑定包含storage.buckets.get权限的自定义角色,但调用Google Cloud Storage的get_bucket接口时返回403禁止访问错误。
错误信息
google.api_core.exceptions.Forbidden: 403 GET https://storage.googleapis.com/storage/v1/b/[bucket-name]?projection=noAcl&prettyPrint=false: [service-account-name]@[project-id].iam.gserviceaccount.com does not have storage.buckets.get access to the Google Cloud Storage bucket. Permission 'storage.buckets.get' denied on resource (or it may not exist).
相关代码
storage_client = storage.Client() bucket_name = os.getenv('BUCKET_NAME') self.bucket = storage_client.get_bucket(bucket_name)
已绑定角色
ROLE projects/[ProjectID]/roles/[CustomRole] roles/storage.objectCreator roles/storage.objectUser roles/storage.objectViewer roles/viewer
自定义角色权限详情
description: [some-description] etag: [some-etag] includedPermissions: - storage.buckets.get name: projects/[ProjectID]/roles/[CustomRole] stage: ALPHA title: [Custom Role Title]
可能的原因及排查步骤
- 自定义角色处于Alpha阶段:你的自定义角色
stage标记为ALPHA,Alpha阶段的功能属于测试性质,可能存在权限未正常生效、需额外启用实验性功能或存在未知限制的情况。建议将角色切换到GA(正式可用)阶段后再测试。 - 客户端未使用目标服务账号凭据:代码中
storage.Client()默认加载环境的默认凭据,当前环境可能未使用你创建的新服务账号。需确认是否通过GOOGLE_APPLICATION_CREDENTIALS环境变量指定了该服务账号的密钥文件路径,或在代码中显式传入凭据:from google.oauth2 import service_account credentials = service_account.Credentials.from_service_account_file( '/path/to/service-account-key.json' ) storage_client = storage.Client(credentials=credentials) - 角色绑定层级与桶归属不匹配:
- 若目标桶不属于绑定角色的项目,仅在当前项目授权无效,需到桶所在项目为该服务账号添加包含
storage.buckets.get的权限。 - 桶的独立IAM设置可能覆盖项目层级权限:检查桶的IAM配置,确认是否直接拒绝了该服务账号访问,或未明确授予
storage.buckets.get权限。
- 若目标桶不属于绑定角色的项目,仅在当前项目授权无效,需到桶所在项目为该服务账号添加包含
- 权限传播延迟:虽然已等待15分钟,但IAM权限的全局传播最长可能需要30分钟,可再等待一段时间后重试。
内容的提问来源于stack exchange,提问作者Prabhjot Singh Rai
相关产品推荐
相关产品推荐

