You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已配置storage.buckets.get权限仍遇GCS 403禁止访问问题排查

问题分析与排查方向

问题概述

创建新服务账号并绑定包含storage.buckets.get权限的自定义角色,但调用Google Cloud Storage的get_bucket接口时返回403禁止访问错误。

错误信息

google.api_core.exceptions.Forbidden: 403 GET https://storage.googleapis.com/storage/v1/b/[bucket-name]?projection=noAcl&prettyPrint=false: [service-account-name]@[project-id].iam.gserviceaccount.com does not have storage.buckets.get access to the Google Cloud Storage bucket. Permission 'storage.buckets.get' denied on resource (or it may not exist).

相关代码

storage_client = storage.Client()
bucket_name = os.getenv('BUCKET_NAME')
self.bucket = storage_client.get_bucket(bucket_name)

已绑定角色

ROLE
projects/[ProjectID]/roles/[CustomRole]
roles/storage.objectCreator
roles/storage.objectUser
roles/storage.objectViewer
roles/viewer

自定义角色权限详情

description: [some-description]
etag: [some-etag]
includedPermissions:
- storage.buckets.get
name: projects/[ProjectID]/roles/[CustomRole]
stage: ALPHA
title: [Custom Role Title]

可能的原因及排查步骤

  • 自定义角色处于Alpha阶段:你的自定义角色stage标记为ALPHA,Alpha阶段的功能属于测试性质,可能存在权限未正常生效、需额外启用实验性功能或存在未知限制的情况。建议将角色切换到GA(正式可用)阶段后再测试。
  • 客户端未使用目标服务账号凭据:代码中storage.Client()默认加载环境的默认凭据,当前环境可能未使用你创建的新服务账号。需确认是否通过GOOGLE_APPLICATION_CREDENTIALS环境变量指定了该服务账号的密钥文件路径,或在代码中显式传入凭据:
    from google.oauth2 import service_account
    
    credentials = service_account.Credentials.from_service_account_file(
        '/path/to/service-account-key.json'
    )
    storage_client = storage.Client(credentials=credentials)
    
  • 角色绑定层级与桶归属不匹配:
    • 若目标桶不属于绑定角色的项目,仅在当前项目授权无效,需到桶所在项目为该服务账号添加包含storage.buckets.get的权限。
    • 桶的独立IAM设置可能覆盖项目层级权限:检查桶的IAM配置,确认是否直接拒绝了该服务账号访问,或未明确授予storage.buckets.get权限。
  • 权限传播延迟:虽然已等待15分钟,但IAM权限的全局传播最长可能需要30分钟,可再等待一段时间后重试。

内容的提问来源于stack exchange,提问作者Prabhjot Singh Rai

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 03:25:59