You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置KEDA GCP Storage触发器时遇403权限错误求助

排查KEDA GCP Storage触发器Workload Identity权限问题

问题背景

使用Workload Identity配置KEDA的GCP Storage触发器,已确认Kubernetes服务账号绑定的GCP服务账号拥有Storage Admin和Storage Object Admin角色,但触发时出现403权限错误,提示缺失storage.objects.list权限。

TriggerAuthentication配置

apiVersion: keda.sh/v1alpha1
kind: TriggerAuthentication
metadata:
  name: keda-trigger-auth-gcp-credentials
spec:
  podIdentity:
    provider: gcp

ScaledJob配置

apiVersion: keda.sh/v1alpha1
kind: ScaledJob
metadata:
  name: sample-scaled-job
  namespace: default
  labels:
      {{- include "app.labels" . | nindent 4 }}
spec:
  jobTargetRef:
    template:
      metadata:
        labels:
          app.kubernetes.io/name: sample-scaled-job
          app.kubernetes.io/instance: sample-scaled-job
      spec:
        imagePullSecrets: {{ .Values.deployment.imagePullSecrets | toYaml | nindent 8 }}
        serviceAccountName: {{ .Values.serviceaccount.name }}
        containers:
          - name: sample-job-container
            image: nginx
            imagePullPolicy: Always
            command: ["echo","Mukesh"]
  pollingInterval:  5                    # Optional. Default: 5 seconds
  minReplicaCount:  0                   # Optional. Default: 0
  maxReplicaCount:  2                    # Optional. Default: 100
  successfulJobsHistoryLimit: 2
  failedJobsHistoryLimit: 2
  rollout:
    strategy: gradual
    propagationPolicy: foreground
  triggers:
  - type: gcp-storage
    authenticationRef:
      name: keda-trigger-auth-gcp-credentials
    metadata:
      bucketName: "ccon-ap-core-pilot-us-east4-gcs"
      targetObjectCount: "5"
      blobPrefix: "inputs/"

错误日志

Type     Reason              Age                    From           Message                                                                                         
----     ------              ----                   ----           -------                                                                                         
Normal   KEDAScalersStarted  38m                    scale-handler  Started scalers watch                                                                            
Warning  KEDAScalerFailed    38m                    scale-handler  context canceled                                                                                
Warning  KEDAScalerFailed    38m                    scale-handler  scaler with id 0 not found, len = 0, cache has been probably already invalidated                
Normal   ScaledJobReady      36m (x3 over 38m)      keda-operator  ScaledJob is ready for scaling                                                                  
Warning  KEDAScalerFailed    3m44s (x420 over 38m)  scale-handler  googleapi: Error 403: Caller does not have storage.objects.list access to the Google Cloud Storage bucket. Permission 'storage.objects.list' denied on resource (or it may not exist)., forbidden          

排查步骤

  • 明确权限主体:KEDA Operator而非业务Job
    KEDA的GCP Storage触发器由KEDA Operator主动查询GCS桶对象数量,因此需给KEDA Operator所在的Kubernetes服务账号绑定GCP权限,而非ScaledJob中jobTargetRef指定的业务服务账号。

  • 验证Workload Identity绑定关系
    确保KEDA Operator的K8s服务账号已正确绑定到拥有GCS权限的GCP服务账号,执行绑定命令:

    gcloud iam service-accounts add-iam-policy-binding GCP_SA_NAME@PROJECT_ID.iam.gserviceaccount.com \
      --role roles/iam.workloadIdentityUser \
      --member "serviceAccount:PROJECT_ID.svc.id.goog[KEDA_NAMESPACE/KEDA_SA_NAME]"
    

    替换命令中的GCP_SA_NAME、PROJECT_ID、KEDA_NAMESPACE、KEDA_SA_NAME为实际值。

  • 确认GCP服务账号权限有效性
    检查GCP服务账号是否确实拥有storage.objects.list权限:

    gcloud projects get-iam-policy PROJECT_ID \
      --filter="bindings.members:GCP_SA_NAME@PROJECT_ID.iam.gserviceaccount.com" \
      --format="value(bindings.role)"
    

    也可直接测试权限:激活该服务账号后尝试列出桶内对象:

    gcloud auth activate-service-account GCP_SA_NAME@PROJECT_ID.iam.gserviceaccount.com --key-file=key.json
    gsutil ls gs://ccon-ap-core-pilot-us-east4-gcs/inputs/
    
  • 检查TriggerAuthentication的命名空间匹配
    如果KEDA Operator部署在非default命名空间,需确保TriggerAuthentication与KEDA Operator在同一命名空间,或在authenticationRef中指定命名空间:

    authenticationRef:
      name: keda-trigger-auth-gcp-credentials
      namespace: KEDA_NAMESPACE
    
  • 验证GCS桶的存在与名称正确性
    确认桶名ccon-ap-core-pilot-us-east4-gcs拼写正确,且在对应的GCP项目中存在,可通过gsutil ls gs://ccon-ap-core-pilot-us-east4-gcs验证。

内容的提问来源于stack exchange,提问作者panch mukesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 02:29:53