通过Anthos Config Management减少Cloud Run服务的API请求次数
问题描述
我正在用Anthos Config Management配置GCP Cloud Run服务,从日志里发现每秒有3次调用google.cloud.run.v2.Services.GetService API的请求,发起方是Config Connector关联的服务账号。因为请求频率太高,已经多次碰到配额限制错误,想知道这些频繁请求的原因,以及有没有办法减少请求次数。
日志摘要
调用记录
2023-04-07T09:29:53.637281Z - google.cloud.run.v2.Services.GetService 2023-04-07T09:29:53.544169Z - google.cloud.run.v2.Services.GetService 2023-04-07T09:29:52.487437Z - google.cloud.run.v2.Services.GetService 2023-04-07T09:29:51.521130Z - google.cloud.run.v2.Services.GetService 2023-04-07T09:29:51.482940Z - google.cloud.run.v2.Services.GetService 2023-04-07T09:29:51.440035Z - google.cloud.run.v2.Services.GetService
审计日志详情
[ { "insertId": "6o7xwnd1apc", "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access", "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "anthos-config-managment-service-account", "principalSubject": "serviceAccount:anthos-config-managment-service-account" }, "authorizationInfo": [ { "granted": true, "permission": "run.services.get", "resource": "projects/projectId/locations/region/services/serviceName", "resourceAttributes": {} } ], "methodName": "google.cloud.run.v2.Services.GetService", "requestMetadata": { "callerIp": "10.156.0.8", "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__", "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)", "destinationAttributes": {}, "requestAttributes": { "auth": {}, "time": "2023-04-07T09:29:53.658779Z" } }, "resourceLocation": { "currentLocations": ["region"] }, "resourceName": "projects/projectId/locations/region/services/serviceName", "serviceName": "run.googleapis.com" }, "receiveTimestamp": "2023-04-07T09:29:54.442225196Z", "resource": { "labels": { "configuration_name": "", "location": "region", "project_id": "projectId", "revision_name": "", "service_name": "serviceName" }, "type": "cloud_run_revision" }, "severity": "INFO", "timestamp": "2023-04-07T09:29:53.637281Z" }, { "insertId": "y4uoutd1cbh", "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access", "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "anthos-config-managment-service-account", "principalSubject": "serviceAccount:anthos-config-managment-service-account" }, "authorizationInfo": [ { "granted": true, "permission": "run.services.get", "resource": "projects/projectId/locations/region/services/serviceName", "resourceAttributes": {} } ], "methodName": "google.cloud.run.v2.Services.GetService", "requestMetadata": { "callerIp": "10.156.0.8", "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__", "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)", "destinationAttributes": {}, "requestAttributes": { "auth": {}, "time": "2023-04-07T09:29:53.561641Z" } }, "resourceLocation": { "currentLocations": ["region"] }, "resourceName": "projects/projectId/locations/region/services/serviceName", "serviceName": "run.googleapis.com" }, "receiveTimestamp": "2023-04-07T09:29:54.124104694Z", "resource": { "labels": { "configuration_name": "", "location": "region", "project_id": "projectId", "revision_name": "", "service_name": "serviceName" }, "type": "cloud_run_revision" }, "severity": "INFO", "timestamp": "2023-04-07T09:29:53.544169Z" }, { "insertId": "170bquhc1db", "logName": "projects/projectId/logs/cloudaudit.googleapis.com%2Fdata_access", "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "anthos-config-managment-service-account", "principalSubject": "serviceAccount:anthos-config-managment-service-account" }, "authorizationInfo": [ { "granted": true, "permission": "run.services.get", "resource": "projects/projectId/locations/region/services/serviceName", "resourceAttributes": {} } ], "methodName": "google.cloud.run.v2.Services.GetService", "requestMetadata": { "callerIp": "10.156.0.8", "callerNetwork": "//compute.googleapis.com/projects/projectId/global/networks/__unknown__", "callerSuppliedUserAgent": "kcc/controller-manager blueprints/kpt-pkg-fn-live DeclarativeClientLib/0.0.1,gzip(gfe),gzip(gfe)", "destinationAttributes": {}, "requestAttributes": { "auth": {}, "time": "2023-04-07T09:29:52.504497Z" } }, "resourceLocation": { "currentLocations": ["region"] }, "resourceName": "projects/projectId/locations/region/services/serviceName", "serviceName": "run.googleapis.com" }, "receiveTimestamp": "2023-04-07T09:29:53.491235721Z", "resource": { "labels": { "configuration_name": "", "location": "region", "project_id": "projectId", "revision_name": "", "service_name": "serviceName" }, "type": "cloud_run_revision" }, "severity": "INFO", "timestamp": "2023-04-07T09:29:52.487437Z" }]
问题解答
频繁请求的原因
- Config Connector的 reconcile 机制:作为声明式控制器,它会定期轮询GCP资源状态,确保集群配置与GCP实际状态一致。默认轮询频率较高(几秒一次),会反复调用
GetService校验Cloud Run服务状态。 - 多副本或重复控制器:如果controller-manager运行多个副本,或者存在重复的Cloud Run服务CRD实例,多个进程会同时发起状态校验,叠加后形成高频请求。
- 状态漂移触发:若Cloud Run服务的实际状态与集群声明配置频繁差异(比如外部手动修改服务),控制器会触发更频繁的reconcile,增加API调用次数。
减少请求次数的方法
- 调整 reconcile 周期:修改Config Connector控制器的
--reconcile-period参数,延长轮询间隔(比如从默认10秒改为30秒),需权衡实时性和请求频率。 - 启用资源缓存:确保Config Connector开启资源缓存(部分版本默认启用),缓存GCP资源状态,避免每次reconcile都直接调用API。
- 控制控制器副本数:将controller-manager副本数设为1,避免多副本重复发起请求。
- 消除状态漂移:排查是否有外部流程(手动修改、其他自动化工具)频繁变更Cloud Run配置,减少不必要的状态波动,降低reconcile触发次数。
- 禁用自动 reconcile:对不需要实时同步的服务,在CRD资源上添加
cnrm.cloud.google.com/disable-auto-reconciliation: "true"注解,仅在配置变更时触发同步。
内容的提问来源于stack exchange,提问作者Eugene
相关产品推荐
相关产品推荐

