Google Compute VM服务账号推送镜像至Artifact Registry权限被拒
Google Compute VM推送镜像至Artifact Registry权限问题解决
问题详情
在Google Compute VM上尝试将容器镜像推送至Artifact Registry(本人为项目所有者/管理员),执行docker push时触发权限错误:
denied: Permission "artifactregistry.repositories.uploadArtifacts" denied on resource "projects/<MY_PROJECT>/locations/<MY_LOCATION>/repositories/<MY_REPOSITORY>" (or it may not exist)
排查信息
- 执行
gcloud auth list,显示当前使用的服务账号为*****-compute@developer.gserviceaccount.com - 执行
gcloud auth configure-docker,Docker配置如下:
{ "credHelpers": { "<MY_LOCATION>-docker.pkg.dev": "gcloud", "gcr.io": "gcloud", "us.gcr.io": "gcloud", "eu.gcr.io": "gcloud", "asia.gcr.io": "gcloud", "staging-k8s.gcr.io": "gcloud", "marketplace.gcr.io": "gcloud" } }
- 执行
gcloud artifacts docker images list <MY_REPOSITORY>可正常返回镜像列表,说明账号具备读取权限
已尝试的无效操作
- 在VM页面启用
Allow full access to all Cloud APIs并重启VM - 在VM上使用项目所有者凭据登录
- 为服务账号配置读写权限并重启VM
解决步骤
- 进入Google Compute的VM实例页面,确认已选中
Allow full access to all Cloud APIs - 进入IAM页面为对应服务账号添加Artifact Registry的写入权限(读取权限默认已包含),或通过CLI执行:
gcloud compute instances set-service-account <YOUR_INSTANCE> --scopes=cloud-platform,storage-rw - 在VM内部执行
gcloud auth configure-docker <YOUR_LOCATION>,此步骤关键——默认的gcloud auth configure-docker适配GCR,需指定Artifact Registry的地域完成针对性配置
内容的提问来源于stack exchange,提问作者JKJK
相关产品推荐
相关产品推荐

