Terraform/Gcloud创建google_service_networking_connection遇API权限问题
问题
尝试用Terraform或gcloud工具创建google_service_networking_connection,均因认证问题失败。所有资源都部署在自己的chrism-test项目中,但报错提示需要启用项目681255809395的Service Networking API,无法理解原因。通过UI配置私有连接可正常工作,但执行Terraform配置时触发403错误。
使用版本信息
- Terraform v1.6.1(windows_amd64)
- provider registry.terraform.io/hashicorp/google v4.84.0
- provider registry.terraform.io/hashicorp/google-beta v4.84.0
- provider registry.terraform.io/hashicorp/null v3.2.1
- provider registry.terraform.io/hashicorp/random v3.5.1
Terraform配置(项目为chrism-test)
variables.tf
variable "project_id" { type = string description = "Project id" default = "chrism-test" } variable "region" { type = string description = "Default Google Region" default = "europe-west3" } variable "zone" { type = string description = "Default Zone" default = "europe-west3-a" } variable "subnetwork-cidr" { type = string default = "192.168.0.0/20" } variable "pods-cidr" { type = string default = "10.0.0.0/20" } variable "services-cidr" { type = string default = "10.0.16.0/20" }
main.tf
provider "google" { project = var.project_id // chrism-test region = var.region zone = var.zone } resource "google_compute_network" "vpc_test" { auto_create_subnetworks = false mtu = 1460 name = "vpc-test" routing_mode = "REGIONAL" } resource "google_compute_subnetwork" "private_subnet" { ip_cidr_range = var.subnetwork-cidr name = "private-subnet" network = google_compute_network.vpc_test.name private_ip_google_access = true private_ipv6_google_access = "DISABLE_GOOGLE_ACCESS" purpose = "PRIVATE" secondary_ip_range { ip_cidr_range = var.pods-cidr range_name = "my-pods" } secondary_ip_range { ip_cidr_range = var.services-cidr range_name = "my-services" } stack_type = "IPV4_ONLY" } resource "google_service_networking_connection" "private_vpc_connection" { network = google_compute_network.vpc_test.self_link service = "servicenetworking.googleapis.com" reserved_peering_ranges = [google_compute_global_address.private_ip_range.name] } resource "google_compute_global_address" "private_ip_range" { name = "private-ip-range" purpose = "VPC_PEERING" address_type = "INTERNAL" prefix_length = 16 network = google_compute_network.vpc_test.name }
执行错误信息
╷ │ Error: Error waiting for Create Service Networking Connection: error while retrieving operation: googleapi: Error 403: Service Networking API has not been used in project 681255809395 before or it is disabled. Enable it via Google Cloud Console then retry. If you enabled this API recently, wait a few minutes for the action to propagate to our systems and retry. │ Details: │ [ │ { │ "@type": "type.googleapis.com/google.rpc.Help", │ "links": [ │ { │ "description": "Google developers console API activation", │ "url": "[已移除外链]" │ } │ ] │ }, │ { │ "@type": "type.googleapis.com/google.rpc.ErrorInfo", │ "domain": "googleapis.com", │ "metadata": { │ "consumer": "projects/681255809395", │ "service": "servicenetworking.googleapis.com" │ }, │ "reason": "SERVICE_DISABLED" │ } │ ] │ , accessNotConfigured │ │ with module.network.google_service_networking_connection.private_vpc_connection, │ on modules\network\main.tf line 31, in resource "google_service_networking_connection" "private_vpc_connection": │ 31: resource "google_service_networking_connection" "private_vpc_connection" { │
解决方案
原因解释
项目681255809395是Google管理的Service Networking宿主项目,当你创建与servicenetworking.googleapis.com的VPC对等连接时,Terraform需要调用该宿主项目的API来完成对等配置。UI操作会自动处理这个宿主项目的API启用,但Terraform需要你手动完成这一步。
解决步骤
启用宿主项目的Service Networking API
使用gcloud命令启用该项目的API:gcloud services enable servicenetworking.googleapis.com --project=681255809395注:执行此命令需要你的账号拥有该宿主项目的API启用权限,通常只要你有权限在自己项目中创建私有服务访问,就具备该权限。
确保自身项目的Service Networking API已启用
同时确认自己的chrism-test项目也启用了该API:gcloud services enable servicenetworking.googleapis.com --project=chrism-test重新执行Terraform
完成以上步骤后,等待1-2分钟让API配置生效,再运行:terraform apply
补充说明
如果使用gcloud命令创建连接时也遇到相同问题,执行上述API启用命令后即可解决。本质是Terraform和gcloud工具不会自动触发宿主项目的API启用,而UI流程封装了这一步操作。
内容的提问来源于stack exchange,提问作者Christoph Marketsmüller

