GCP现有存储桶添加IAM权限报错:指定角色不支持该资源
解决GCP存储桶IAM权限添加错误问题
你遇到的错误根源是角色名称拼写错误——GCP存储桶对应的IAM角色是复数形式buckets,而非单数bucket,另外第二条命令里的用户邮箱误写为emailo,需要修正为有效邮箱地址。
针对你要实现的需求(让指定用户能列出、查看存储桶及其IAM策略),正确的命令如下:
- 授予查看存储桶元数据的权限:
gcloud storage buckets add-iam-policy-binding gs://bucket-name --member=user:your-valid-email --role=roles/storage.buckets.get
- 授予查看存储桶IAM策略的权限:
gcloud storage buckets add-iam-policy-binding gs://bucket-name --member=user:your-valid-email --role=roles/storage.buckets.getIamPolicy
- 如果需要用户能列出存储桶内的对象,需额外执行这条命令:
gcloud storage buckets add-iam-policy-binding gs://bucket-name --member=user:your-valid-email --role=roles/storage.objects.list
如果想简化操作,也可以直接使用预定义组合角色roles/storage.objectViewer(包含查看存储桶、列出/查看对象的权限),再搭配IAM策略查看角色:
gcloud storage buckets add-iam-policy-binding gs://bucket-name --member=user:your-valid-email --role=roles/storage.objectViewer gcloud storage buckets add-iam-policy-binding gs://bucket-name --member=user:your-valid-email --role=roles/storage.buckets.getIamPolicy
内容的提问来源于stack exchange,提问作者Shahjahan Ravjee
相关产品推荐
相关产品推荐

