You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Anthos Config Management减少Cloud Run服务的API请求次数

问题描述

我正在用Anthos Config Management配置GCP Cloud Run服务,从日志里发现每秒有3次调用google.cloud.run.v2.Services.GetService API的请求,发起方是Config Connector关联的服务账号。因为请求频率太高,已经多次碰到配额限制错误,想知道这些频繁请求的原因,以及有没有办法减少请求次数。

日志摘要

调用记录

2023-04-07T09:29:53.637281Z - google.cloud.run.v2.Services.GetService
2023-04-07T09:29:53.544169Z - google.cloud.run.v2.Services.GetService
2023-04-07T09:29:52.487437Z - google.cloud.run.v2.Services.GetService
2023-04-07T09:29:51.521130Z - google.cloud.run.v2.Services.GetService
2023-04-07T09:29:51.482940Z - google.cloud.run.v2.Services.GetService
2023-04-07T09:29:51.440035Z - google.cloud.run.v2.Services.GetService

审计日志详情

[
  {
    "insertId": "6o7xwnd1apc",
    "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access",
    "protoPayload": {
      "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
      "authenticationInfo": {
        "principalEmail": "anthos-config-managment-service-account",
        "principalSubject": "serviceAccount:anthos-config-managment-service-account"
      },
      "authorizationInfo": [
        {
          "granted": true,
          "permission": "run.services.get",
          "resource": "projects/projectId/locations/region/services/serviceName",
          "resourceAttributes": {}
        }
      ],
      "methodName": "google.cloud.run.v2.Services.GetService",
      "requestMetadata": {
        "callerIp": "10.156.0.8",
        "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__",
        "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)",
        "destinationAttributes": {},
        "requestAttributes": {
          "auth": {},
          "time": "2023-04-07T09:29:53.658779Z"
        }
      },
      "resourceLocation": {
        "currentLocations": ["region"]
      },
      "resourceName": "projects/projectId/locations/region/services/serviceName",
      "serviceName": "run.googleapis.com"
    },
    "receiveTimestamp": "2023-04-07T09:29:54.442225196Z",
    "resource": {
      "labels": {
        "configuration_name": "",
        "location": "region",
        "project_id": "projectId",
        "revision_name": "",
        "service_name": "serviceName"
      },
      "type": "cloud_run_revision"
    },
    "severity": "INFO",
    "timestamp": "2023-04-07T09:29:53.637281Z"
  },
  {
    "insertId": "y4uoutd1cbh",
    "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access",
    "protoPayload": {
      "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
      "authenticationInfo": {
        "principalEmail": "anthos-config-managment-service-account",
        "principalSubject": "serviceAccount:anthos-config-managment-service-account"
      },
      "authorizationInfo": [
        {
          "granted": true,
          "permission": "run.services.get",
          "resource": "projects/projectId/locations/region/services/serviceName",
          "resourceAttributes": {}
        }
      ],
      "methodName": "google.cloud.run.v2.Services.GetService",
      "requestMetadata": {
        "callerIp": "10.156.0.8",
        "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__",
        "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)",
        "destinationAttributes": {},
        "requestAttributes": {
          "auth": {},
          "time": "2023-04-07T09:29:53.561641Z"
        }
      },
      "resourceLocation": {
        "currentLocations": ["region"]
      },
      "resourceName": "projects/projectId/locations/region/services/serviceName",
      "serviceName": "run.googleapis.com"
    },
    "receiveTimestamp": "2023-04-07T09:29:54.124104694Z",
    "resource": {
      "labels": {
        "configuration_name": "",
        "location": "region",
        "project_id": "projectId",
        "revision_name": "",
        "service_name": "serviceName"
      },
      "type": "cloud_run_revision"
    },
    "severity": "INFO",
    "timestamp": "2023-04-07T09:29:53.544169Z"
  },
  {
    "insertId": "170bquhc1db",
    "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access",
    "protoPayload": {
      "@type": "type.googleapis.com/google.cloud.audit.AuditLog",
      "authenticationInfo": {
        "principalEmail": "anthos-config-managment-service-account",
        "principalSubject": "serviceAccount:anthos-config-managment-service-account"
      },
      "authorizationInfo": [
        {
          "granted": true,
          "permission": "run.services.get",
          "resource": "projects/projectId/locations/region/services/serviceName",
          "resourceAttributes": {}
        }
      ],
      "methodName": "google.cloud.run.v2.Services.GetService",
      "requestMetadata": {
        "callerIp": "10.156.0.8",
        "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__",
        "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)",
        "destinationAttributes": {},
        "requestAttributes": {
          "auth": {},
          "time": "2023-04-07T09:29:52.504497Z"
        }
      },
      "resourceLocation": {
        "currentLocations": ["region"]
      },
      "resourceName": "projects/projectId/locations/region/services/serviceName",
      "serviceName": "run.googleapis.com"
    },
    "receiveTimestamp": "2023-04-07T09:29:53.491235721Z",
    "resource": {
      "labels": {
        "configuration_name": "",
        "location": "region",
        "project_id": "projectId",
        "revision_name": "",
        "service_name": "serviceName"
      },
      "type": "cloud_run_revision"
    },
    "severity": "INFO",
    "timestamp": "2023-04-07T09:29:52.487437Z"
  }]
问题解答

频繁请求的原因

  • Config Connector的 reconcile 机制:作为声明式控制器,它会定期轮询GCP资源状态,确保集群配置与GCP实际状态一致。默认轮询频率较高(几秒一次),会反复调用GetService校验Cloud Run服务状态。
  • 多副本或重复控制器:如果controller-manager运行多个副本,或者存在重复的Cloud Run服务CRD实例,多个进程会同时发起状态校验,叠加后形成高频请求。
  • 状态漂移触发:若Cloud Run服务的实际状态与集群声明配置频繁差异(比如外部手动修改服务),控制器会触发更频繁的reconcile,增加API调用次数。

减少请求次数的方法

  • 调整 reconcile 周期:修改Config Connector控制器的--reconcile-period参数,延长轮询间隔(比如从默认10秒改为30秒),需权衡实时性和请求频率。
  • 启用资源缓存:确保Config Connector开启资源缓存(部分版本默认启用),缓存GCP资源状态,避免每次reconcile都直接调用API。
  • 控制控制器副本数:将controller-manager副本数设为1,避免多副本重复发起请求。
  • 消除状态漂移:排查是否有外部流程(手动修改、其他自动化工具)频繁变更Cloud Run配置,减少不必要的状态波动,降低reconcile触发次数。
  • 禁用自动 reconcile:对不需要实时同步的服务,在CRD资源上添加cnrm.cloud.google.com/disable-auto-reconciliation: "true"注解,仅在配置变更时触发同步。

内容的提问来源于stack exchange,提问作者Eugene

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 14:13:09