You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Cloud Function导出资产清单时出现503连接失败问题

GCP Cloud Function调用Asset Inventory服务出现503连接错误的排查方案

问题背景

以下Python代码在本地运行正常,但部署为GCP Cloud Function时触发503 failed to connect to all addresses错误:

import base64
from google.cloud import asset_v1

def export_assets(event, context):
    # 创建客户端
    client = asset_v1.AssetServiceClient()
    print("""此函数由消息ID {}于 {} 发布到 {} 触发
    """.format(context.event_id, context.timestamp, context.resource["name"]))
    
    # BQ分区配置
    # PARTITION_KEY_UNSPECIFIED = 0
    # READ_TIME = 1
    # REQUEST_TIME = 2
    partition_spec = asset_v1.PartitionSpec()
    partition_spec.partition_key = 1
    
    # 初始化请求
    output_config = asset_v1.OutputConfig()
    output_config.bigquery_destination.dataset = "projects/ss-org-logging-project/datasets/cloud_assets_inventory"
    output_config.bigquery_destination.table = "gcp_assets"
    output_config.bigquery_destination.force = True
    output_config.bigquery_destination.partition_spec = partition_spec
    
    request = asset_v1.ExportAssetsRequest(
        parent="projects/ss-org-logging-project",
        content_type = "RESOURCE",
        asset_types = [
            ".*",
        ],
        output_config = output_config,
    )
    
    # 发送请求
    operation = client.export_assets(request=request)
    
    msg_body = base64.b64decode(event['data']).decode('utf-8')
    print('正在导出: {}'.format(msg_body))
    response = operation.result()
    
    # 处理响应
    print(response)

错误堆栈

Traceback (most recent call last):
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/flask/app.py", line 2073, in wsgi_app
    response = self.full_dispatch_request()
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/flask/app.py", line 1518, in full_dispatch_request
    rv = self.handle_user_exception(e)
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/flask/app.py", line 1516, in full_dispatch_request
    rv = self.dispatch_request()
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/flask/app.py", line 1502, in dispatch_request
    return self.ensure_sync(self.view_functions[rule.endpoint])(**req.view_args)
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/functions_framework/__init__.py", line 171, in view_func
    function(data, context)
  File "/workspace/main.py", line 35, in export_assets
    operation = client.export_assets(request=request)
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/google/cloud/asset_v1/services/asset_service/client.py", line 552, in export_assets
    response = rpc(request, retry=retry, timeout=timeout, metadata=metadata,)
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/google/api_core/gapic_v1/method.py", line 113, in __call__
    return wrapped_func(*args, **kwargs)
  File "/layers/google.python.pip/pip/lib/python3.9/site-packages/google/api_core/grpc_helpers.py", line 74, in error_remapped_callable
    raise exceptions.from_grpc_error(exc) from exc
google.api_core.exceptions.ServiceUnavailable: 503 failed to connect to all addresses; last error: UNKNOWN: ipv4:199.36.153.5:443: Failed to connect to remote host: FD Shutdown

可能原因及解决方案

1. 网络配置限制

  • 场景:Cloud Function部署在私有VPC中,未配置公网访问权限,或VPC出站规则阻止了HTTPS流量。
  • 解决:
    • 若需访问公网Asset Inventory服务,为VPC配置云NAT网关,确保Cloud Function可通过NAT访问公网。
    • 或启用Private Service Connect,直接通过VPC内部访问Asset Inventory服务,规避公网依赖。
    • 检查VPC出站防火墙规则,确保允许目标IP(如199.36.153.5)的443端口流量,或放宽规则允许所有HTTPS出站。

2. Cloud Asset Inventory API未启用

  • 场景:项目未启用Cloud Asset Inventory API,导致服务无法访问。
  • 解决:
    • 登录GCP控制台,进入项目API库,搜索「Cloud Asset Inventory API」,确认已启用;若未启用,点击启用按钮等待生效。

3. 依赖库版本不一致

  • 场景:本地测试使用的google-cloud-asset版本与Cloud Function云端安装版本不一致,引发gRPC连接兼容性问题。
  • 解决:
    • 在项目根目录创建requirements.txt文件,指定与本地一致的库版本,例如:
      google-cloud-asset==2.15.0
      
    • 重新部署Cloud Function,确保云端安装指定版本的依赖。

4. 客户端连接参数优化

  • 场景:默认gRPC连接超时或重试策略无法应对云端网络波动。
  • 解决:
    • 修改客户端初始化代码,增加超时时间或自定义重试策略,示例:
      from google.api_core.retry import Retry
      from google.cloud import asset_v1
      import google.api_core.exceptions
      
      def export_assets(event, context):
          # 配置针对503错误的重试策略
          retry_policy = Retry(
              initial=1.0,
              total=30.0,
              predicate=lambda exc: isinstance(exc, google.api_core.exceptions.ServiceUnavailable)
          )
          # 创建客户端
          client = asset_v1.AssetServiceClient()
          # 调用时传入重试与超时参数
          operation = client.export_assets(request=request, retry=retry_policy, timeout=60)
      

内容的提问来源于stack exchange,提问作者Gaurang Shah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 08:49:55