部署至App Engine Flexible遇CloudGaia账户禁用错误求助
问题概述
部署服务至App Engine Flexible环境时触发CloudGaia相关错误,已确认App Engine Flexible API启用,且配置了Usage Viewer权限,问题仍未解决。以下是错误详情及对应背景说明、排查方案:
Cloud Build错误日志
WARNING: Unable to verify that the Appengine Flexible API is enabled for project [****************]. You may not have permission to list enabled services on this project. If it is not enabled, this may cause problems in running your deployment. Please ask the project owner to ensure that the Appengine Flexible API has been enabled and that this account has permission to list enabled APIs.
ERROR: (gcloud.app.deploy) NOT_FOUND: APPLICATION_ERROR;google.iam.credentials.v1/CloudGaia.GenerateAccessToken;Account disabled: xxxxxxxx
权限配置截图
API权限

IAM权限

CloudGaia相关背景说明
CloudGaia是Google云后台负责IAM凭证生成的内部服务,CloudGaia.GenerateAccessToken接口用于为服务账号生成访问令牌。错误中的Account disabled: xxxxxxxx指向两种核心原因:
- 执行部署的服务账号(或其关联身份)已被手动禁用
- 该账号的令牌生成权限被IAM政策或组织级政策限制
排查步骤
- 检查服务账号状态:进入Google Cloud控制台IAM页面,搜索错误中的账号ID(
xxxxxxx),确认账号处于启用状态,未被手动禁用。 - 验证令牌生成权限:确保服务账号拥有
iam.serviceAccounts.generateAccessToken权限,可通过为账号添加Service Account Token Creator预定义角色快速配置。 - 排查政策限制:检查项目是否存在组织级或项目级的IAM政策,限制了服务账号的凭证生成操作(例如
constraints/iam.disableServiceAccountTokenCreation约束)。 - 确认Cloud Build账号关联:若使用自定义服务账号执行部署,确认该账号已正确绑定到Cloud Build服务,且账号密钥未过期或被吊销。
内容的提问来源于stack exchange,提问作者Essa A. Haddad

