You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Terraform GCP Cloud Storage远程后端时遭遇403权限拒绝错误的排查求助

Fixing Terraform GCS Backend 403 Permission Denied Error

Let's break down what's causing this permission issue and fix it without resorting to over-broad roles like Owner.

Key Misconfigurations & Fixes

1. You Granted the Wrong Identity the Impersonation Role

A common mistake here: the roles/iam.serviceAccountTokenCreator role shouldn't be assigned to your target service account—it needs to be assigned to your local execution identity (the account you're using to run terraform init via gcloud). This lets your local account generate access tokens to impersonate the service account.

Run this command to fix it (replace your personal email with the one you use to log into gcloud):

gcloud iam service-accounts add-iam-policy-binding my-test-svc@project-sandbox.iam.gserviceaccount.com \
  --member="user:your-personal-email@example.com" \
  --role="roles/iam.serviceAccountTokenCreator"

2. Your Service Account Missing Bucket Metadata Access

The roles/storage.objectAdmin role only grants permissions for bucket objects (create, read, delete, etc.). Terraform's GCS backend also needs permission to read the bucket's metadata (storage.buckets.get) to validate the bucket exists.

You have two options to fix this, following the principle of least privilege:

Option A: Bucket-Level Precise Permissions (Recommended)

Grant permissions directly on your target bucket to avoid broad project-level access:

# Grant object management permissions (matches roles/storage.objectAdmin)
gsutil iam ch serviceAccount:my-test-svc@project-sandbox.iam.gserviceaccount.com:roles/storage.objectAdmin gs://my_example_sandbox_bucket_985gd5d

# Grant permission to read bucket metadata
gsutil iam ch serviceAccount:my-test-svc@project-sandbox.iam.gserviceaccount.com:storage.buckets.get gs://my_example_sandbox_bucket_985gd5d

Option B: Project-Level Permissions (Simpler, Slightly Broader)

If you don't mind project-wide access for this use case, add the roles/storage.viewer role (which includes storage.buckets.get) alongside your existing storage.objectAdmin role:

gcloud projects add-iam-policy-binding project-sandbox \
  --member serviceAccount:my-test-svc@project-sandbox.iam.gserviceaccount.com \
  --role roles/storage.viewer

Final Validation Steps

Before re-running terraform init, double-check these:

  • Confirm your bucket my_example_sandbox_bucket_985gd5d exists (Terraform won't create it automatically)
  • Verify the service account email in main.tf and remote.backend is identical and free of typos
  • Wait 1-2 minutes for GCP IAM policies to propagate (changes can take a moment to take effect)

Once you've completed these steps, re-run your init command:

terraform init -backend-config=remote.backend

内容的提问来源于stack exchange,提问作者Steve Ahlswede

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 19:42:36