使用Poetry上传Python包至Google Artifact Registry遇401认证错误
解决Poetry上传Google Artifact Registry旧仓库401未授权问题
排查方向1:清理Poetry旧仓库的缓存凭证
新仓库能正常上传,说明全局认证链路没问题,问题大概率出在旧仓库的本地缓存凭证上:
- 先确认旧仓库
all-mpm的URL配置是否正确:poetry config repositories.all-mpm - 清除Poetry存储的该仓库旧凭证:
poetry config http-basic.all-mpm --unset - 强制关联GAR认证token到该仓库:
poetry config http-basic.all-mpm oauth2accesstoken "$(gcloud auth print-access-token)"
排查方向2:核对旧仓库的IAM权限
切换环境后使用的账号可能丢失了旧仓库的上传权限:
- 检查当前账号对旧仓库的权限配置:
gcloud artifacts repositories get-iam-policy all-mpm --location=europe-west3 - 若缺少上传权限,添加
roles/artifactregistry.writer角色:gcloud artifacts repositories add-iam-policy-binding all-mpm \ --location=europe-west3 \ --member="user:你的谷歌账号邮箱" \ --role="roles/artifactregistry.writer"
排查方向3:调整Keyring认证后端优先级
你的Keyring后端中,Google认证后端优先级低于ChainerBackend,可能导致旧仓库认证未走Google凭证链:
- 临时强制使用Google认证后端:
export KEYRING_BACKEND=keyrings.gauth.GooglePythonAuth - 重新执行上传命令验证,若生效,可将该环境变量加入WSL的
~/.bashrc或~/.zshrc持久化。
排查方向4:重置旧仓库的Poetry配置
仓库URL的微小错误(如末尾斜杠缺失)可能引发认证失败,重新配置:
- 删除旧仓库的Poetry配置:
poetry config repositories.all-mpm --unset - 重新添加正确格式的仓库URL:
poetry config repositories.all-mpm "https://europe-west3-python.pkg.dev/你的项目ID/all-mpm/" - 再次关联认证token后重试上传。
验证步骤
执行带详细日志的上传命令,确认认证流程是否正常触发:
poetry publish --build --repository all-mpm -vvv
若日志中出现"Checking Cloud SDK credentials"并成功获取token,说明问题已解决。
内容的提问来源于stack exchange,提问作者sonder
相关产品推荐
相关产品推荐

