You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java版AWS Lambda通过Google工作负载身份联盟调用Admin Directory API遇权限问题

问题:GCP身份联盟集成AWS Lambda调用Admin Directory API遇403权限问题

背景与已完成操作

  • 创建了GCP工作负载池、服务账号,并将主体关联到AWS Lambda执行角色;
  • 在Lambda中使用AwsCredentials类成功生成访问令牌,确认GCP已正确识别该AWS资源;
  • 调用Directory API时返回403错误,错误信息如下:
{"code": 403,
 "errors": [{"domain": "global",
             "message": "Not Authorized to access this resource/api",
             "reason": "forbidden"}],
 "message": "Not Authorized to access this resource/api"}
  • 确认调用API的范围正确(https://www.googleapis.com/auth/admin.directory.user.readonly),因为使用带密钥文件的服务账号时相同代码可正常运行。

用户问题

  1. 怀疑服务账号权限配置不正确,如何为服务账号启用https://www.googleapis.com/auth/admin.directory.user.readonly范围?已测试设置Owner角色但无效;
  2. Directory API需要超级管理员模拟,但AwsCredentials或IdentityPoolCredential类没有createDelegated方法,如何实现此类需要模拟的API调用?

解决方案

问题1:配置服务账号的Admin Directory API范围与权限

  1. 添加API访问范围
    • 登录GCP控制台,进入「IAM与管理」→「服务账号」,找到目标服务账号;
    • 点击「编辑」→「显示高级设置」→「API权限」,点击「添加范围」;
    • 搜索Admin Directory API,选中https://www.googleapis.com/auth/admin.directory.user.readonly后保存。
  2. 授予Google Workspace域权限
    • 仅给服务账号加Owner角色没用,需要在Google Workspace管理后台(admin.google.com)操作:
      • 进入「安全」→「API控制」→「域名宽权限」;
      • 点击「添加新的客户端」,输入服务账号的邮箱地址;
      • 勾选Admin Directory API下的「读取用户数据」权限,保存设置。

问题2:实现超级管理员模拟

AwsCredentials本身不支持createDelegated,可以通过ImpersonatedCredentials包装实现模拟:

  1. 代码示例
    // 初始化AwsCredentials
    AwsCredentials awsCredentials = AwsCredentials.newBuilder()
        .setRegion("your-aws-region")
        .build();
    
    // 创建模拟超级管理员的凭证
    ImpersonatedCredentials impersonatedCredentials = ImpersonatedCredentials.newBuilder()
        .setSourceCredentials(awsCredentials)
        .setTargetPrincipal("super-admin@your-domain.com") // 替换为你的超级管理员邮箱
        .setScopes(Arrays.asList("https://www.googleapis.com/auth/admin.directory.user.readonly"))
        .setLifetime(3600) // 令牌有效期,单位秒
        .build();
    
    // 使用模拟凭证调用Directory API
    Directory directory = new Directory.Builder(
        GoogleNetHttpTransport.newTrustedTransport(),
        JacksonFactory.getDefaultInstance(),
        new HttpCredentialsAdapter(impersonatedCredentials))
        .setApplicationName("your-app-name")
        .build();
    
  2. 前置条件
    • 在GCP控制台的IAM中,给目标服务账号添加「Service Account Token Creator」角色;
    • 在Google Workspace管理后台的「安全」→「API控制」→「域委派」中,添加该服务账号邮箱并授予对应的Directory API范围。

内容的提问来源于stack exchange,提问作者Sanghyun Kim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 22:31:10