You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Run生成Google Cloud Storage签名URL时触发403禁止错误

Cloud Run中调用UrlSigner.Sign抛出403 Forbidden异常问题

在Cloud Run上运行Docker容器时,调用Google.Cloud.Storage.V1.UrlSigner的Sign(bucket, objectName, duration, HttpMethod.Get)方法会立即抛出HttpRequestException,异常根源是403 Forbidden响应。

已为Cloud Run修订版本关联的服务账号配置了包含storage.objects.get权限的角色,该账号能够正常下载存储对象,但生成签名URL时仍报错。本地运行项目时(通过GOOGLE_APPLICATION_CREDENTIALS指向JSON格式的服务账号密钥),可以正常生成可用的签名URL,且本地和Cloud Run环境均能通过该URL下载文件。

经确认,本地与云端使用的是同一服务账号,但GoogleCredential.GetApplicationDefault()返回的凭据类型不同:本地为ServiceAccountCredential,云端为ComputeCredential,不确定这是否是问题根源。

相关代码

var urlSigner = UrlSigner.FromCredential(GoogleCredential.GetApplicationDefault());
var signedUrl = urlSigner.Sign("bucketName", "objectName", TimeSpan.FromMinutes(30), HttpMethod.Get);

相关版本信息

  • Google.Cloud.Storage.V1 4.5.0
  • net6.0
  • ASP.NET Core 6.0

参考资料

切勿在Cloud Run服务上设置GOOGLE_APPLICATION_CREDENTIALS环境变量,请始终配置用户管理的服务账号
生成签名URL时,您指定的用户或服务账号必须拥有执行该签名URL对应请求的足够权限

异常调用栈

System.Net.Http.HttpRequestException: Response status code does not indicate success: 403 (Forbidden).
  at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode()
  at Google.Apis.Auth.OAuth2.Requests.RequestExtensions.PostJsonAsync[TResponse](Object request, HttpClient httpClient, String url, CancellationToken cancellationToken)
  at Google.Apis.Auth.OAuth2.ComputeCredential.SignBlobAsync(Byte[] blob, CancellationToken cancellationToken)
  at Google.Cloud.Storage.V1.UrlSigner.CredentialBlobSigner.CreateSignatureAsync(Byte[] data, BlobSignerParameters _, CancellationToken cancellationToken)
  at Google.Api.Gax.TaskExtensions.WaitWithUnwrappedExceptions(Task task)
  at Google.Api.Gax.TaskExtensions.ResultWithUnwrappedExceptions[T](Task`1 task)
  at Google.Cloud.Storage.V1.UrlSigner.CredentialBlobSigner.CreateSignature(Byte[] data, BlobSignerParameters signerParameters)
  at Google.Cloud.Storage.V1.UrlSigner.V4Signer.Sign(RequestTemplate requestTemplate, Options options, BlobSignerProvider blobSignerProvider, IClock clock)
  at Google.Cloud.Storage.V1.UrlSigner.Sign(RequestTemplate requestTemplate, Options options)
  at Google.Cloud.Storage.V1.UrlSigner.Sign(String bucket, String objectName, TimeSpan duration, HttpMethod httpMethod, Nullable`1 signingVersion)
  at <my code>

内容的提问来源于stack exchange,提问作者Clayton Hughes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 22:44:54