You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Compute VM服务账号推送镜像至Artifact Registry权限被拒

Google Compute VM推送镜像至Artifact Registry权限问题解决

问题详情

在Google Compute VM上尝试将容器镜像推送至Artifact Registry(本人为项目所有者/管理员),执行docker push时触发权限错误:

denied: Permission "artifactregistry.repositories.uploadArtifacts" denied on resource "projects/<MY_PROJECT>/locations/<MY_LOCATION>/repositories/<MY_REPOSITORY>" (or it may not exist)

排查信息

  • 执行gcloud auth list,显示当前使用的服务账号为*****-compute@developer.gserviceaccount.com
  • 执行gcloud auth configure-docker,Docker配置如下:
{
  "credHelpers": {
    "<MY_LOCATION>-docker.pkg.dev": "gcloud",
    "gcr.io": "gcloud",
    "us.gcr.io": "gcloud",
    "eu.gcr.io": "gcloud",
    "asia.gcr.io": "gcloud",
    "staging-k8s.gcr.io": "gcloud",
    "marketplace.gcr.io": "gcloud"
  }
}
  • 执行gcloud artifacts docker images list <MY_REPOSITORY>可正常返回镜像列表,说明账号具备读取权限

已尝试的无效操作

  • 在VM页面启用Allow full access to all Cloud APIs并重启VM
  • 在VM上使用项目所有者凭据登录
  • 为服务账号配置读写权限并重启VM

解决步骤

  1. 进入Google Compute的VM实例页面,确认已选中Allow full access to all Cloud APIs
  2. 进入IAM页面为对应服务账号添加Artifact Registry的写入权限(读取权限默认已包含),或通过CLI执行:
    gcloud compute instances set-service-account <YOUR_INSTANCE> --scopes=cloud-platform,storage-rw
    
  3. 在VM内部执行gcloud auth configure-docker <YOUR_LOCATION>,此步骤关键——默认的gcloud auth configure-docker适配GCR,需指定Artifact Registry的地域完成针对性配置

内容的提问来源于stack exchange,提问作者JKJK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 09:42:09