GCP部署容器遇IAM_PERMISSION_DENIED错误,本地正常求解决
GCP容器部署后Logging API权限拒绝问题解决思路
在GCP上部署容器后查看日志,遇到错误:
error details: name = ErrorInfo reason = IAM_PERMISSION_DENIED domain = iam.googleapis.com metadata = map[permission:logging.logEntries.create]
本地Docker运行正常,同一主机上未调用Google API的其他服务可正常运行。出错服务包含.env文件、服务账号密钥JSON文件,相关配置与代码如下:
相关配置与代码
.env文件内容
GOOGLE_APPLICATION_CREDENTIALS=json/name-of-json-file.json
Dockerfile内容
# Specifies a parent image FROM golang:1.19.2-bullseye # Creates an app directory to hold your app’s source code WORKDIR /app # Copies everything from your root directory into /app COPY . . # Installs Go dependencies RUN go mod download # Builds your app with optional configuration RUN go build -o /logging-go # Tells Docker which network port your container listens on EXPOSE 8040 # Specifies the executable command that runs when the container starts CMD [ "/logging-go" ]
Logging API调用代码片段
c, cErr := Load(".env") if cErr != nil { log.Fatalf("could not load config: %s", cErr) return } // initializes logger which writes to stdout ctx := context.Background() opt := option.WithCredentialsFile(c.GoogleApplicationCredentials); loggerClient, clientErr := logging.NewClient(ctx, "poc-projects-01", opt) if clientErr != nil { log.Fatal(clientErr) } if clientErr := loggerClient.Ping(ctx); clientErr != nil { log.Fatal(clientErr) } logger := loggerClient.Logger("frontend_logs")
解决思路
- 检查服务账号权限:确认
.env中指定的服务账号是否拥有logging.logEntries.create权限。在GCP IAM控制台找到该服务账号,添加Logs Writer角色(包含所需日志写入权限),或直接添加logging.logEntries.create具体权限。 - 验证密钥文件部署状态:确认容器部署时,服务账号密钥JSON文件是否被正确复制到容器内的
json/name-of-json-file.json路径。可进入运行中的容器,检查该路径下文件是否存在、内容是否与本地一致。 - 排查路径解析问题:容器工作目录为
/app,.env中指定的是相对路径,需确认代码加载时是否正确解析为/app/json/name-of-json-file.json。可在代码中打印实际加载路径,验证路径正确性。 - 确认项目与API状态:代码中初始化Logging Client使用的项目ID
poc-projects-01,需与服务账号所属项目一致,且该项目已启用Cloud Logging API。 - 检查GCP环境凭据干扰:GCP环境中容器可能自动使用实例服务账号凭据,虽代码明确指定了密钥文件,但仍需确认实例服务账号是否无相关权限导致冲突。可尝试在代码中使用绝对路径指定密钥文件,避免环境变量路径解析问题。
内容的提问来源于stack exchange,提问作者neil_ruaro
相关产品推荐
相关产品推荐

