You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions部署Cloud Functions遇权限错误求助

问题

我希望通过GitHub Actions自动部署Cloud Functions,以下是我的deploy-cloud-functions.yml配置文件:

name: Deploy Cloud Functions

on:
  push:
    branches:
      - feat/queue

jobs:
  deploy:
    runs-on: ubuntu-latest

    permissions:
      contents: 'read'
      id-token: 'write'

    steps:
    - name: Checkout code
      uses: actions/checkout@v3

    - name: Authenticate
      uses: 'google-github-actions/auth@v1'
      with:
        workload_identity_provider: 'projects/<number>/locations/global/workloadIdentityPools/<name>/providers/<name>'
        service_account: 'test@test.iam.gserviceaccount.com'

    - name: Deploy Cloud Functions
      uses: google-github-actions/deploy-cloud-functions@v1
      with:
        name: myName
        runtime: nodejs16
        entry_point: myName
        source_dir: ./functions

但在Deploy Cloud Functions步骤中出现错误:

Error: google-github-actions/deploy-cloud-functions failed with: failed to upload zip file: Permission 'iam.serviceAccounts.getAccessToken' denied on resource (or it may not exist).

我已为服务账号添加以下权限:

Cloud Functions Service Agent
Service Account OpenID Connect Identity Token Creator
Service Account Token Creator
Service Account User
Workload Identity User

请帮我排查问题出在哪里?

排查方案
  • 确认权限绑定目标
    你添加的Service Account Token Creator权限,必须是绑定在目标服务账号(test@test.iam.gserviceaccount.com)自身上的。因为iam.serviceAccounts.getAccessToken权限要求当前身份能获取自身的AccessToken,所以需要给该服务账号授予对自己的Service Account Token Creator角色,而不是绑定到其他账号或项目层面。

  • 检查Workload Identity匹配规则
    核对Workload Identity Provider的GitHub匹配规则,确认是否允许当前仓库、分支触发身份验证。如果规则限制过严,会导致获取的身份权限不足,触发该错误。

  • 等待权限生效并手动验证
    IAM权限有时需要5-10分钟才能完成传播,等一段时间后重新运行Action测试。也可以用gcloud命令手动验证服务账号权限:

    gcloud auth activate-service-account test@test.iam.gserviceaccount.com --key-file=key.json
    gcloud iam service-accounts get-iam-policy test@test.iam.gserviceaccount.com
    

    查看输出里是否包含roles/iam.serviceAccountTokenCreator绑定到该服务账号本身。

  • 补充部署必要权限
    部署Cloud Functions除了现有权限,还需要cloudfunctions.functions.create/cloudfunctions.functions.update权限,以及默认存储桶(gs://[PROJECT_ID].appspot.com)的读写权限。可以直接给服务账号添加Cloud Functions Developer角色,这个角色包含部署所需的基础权限集合。

  • 升级Action版本
    当前使用的deploy-cloud-functions@v1可能存在版本兼容问题,尝试升级到最新稳定版(比如v2),部分旧版本的权限处理逻辑可能存在缺陷。

内容的提问来源于stack exchange,提问作者Roman Mahotskyi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 17:52:16