You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

新建GKE集群无法拉取Artifact Registry私有镜像问题排查

GKE集群无法拉取Artifact Registry私有镜像问题解决

问题场景

通过Terraform使用自定义服务账号创建GKE集群后,执行Helm部署应用时出现镜像拉取失败,Pod状态为ImagePullBackOff。

集群创建的Terraform代码

locals {
  service         = "example"
  resource_prefix = format("%s-%s", local.service, var.env)
  location        = format("%s-b", var.gcp_region)
}

resource "google_service_account" "main" {
  account_id   = format("%s-sa", local.resource_prefix)
  display_name = format("%s-sa", local.resource_prefix)
  project      = var.gcp_project
}

resource "google_container_cluster" "main" {
  name                     = local.resource_prefix
  description              = format("Cluster primarily servicing the service %s", local.service)
  location                 = local.location
  remove_default_node_pool = true
  initial_node_count       = 1
}

resource "google_container_node_pool" "main" {
  name       = format("%s-node-pool", local.resource_prefix)
  location   = local.location
  cluster    = google_container_cluster.main.name
  node_count = var.gke_cluster_node_count

  node_config {
    preemptible  = true
    machine_type = var.gke_node_machine_type
    # Google recommends custom service accounts that have cloud-platform scope and permissions granted via IAM Roles.
    service_account = google_service_account.main.email
    oauth_scopes = [
      "https://www.googleapis.com/auth/logging.write",
      "https://www.googleapis.com/auth/monitoring",
      "https://www.googleapis.com/auth/cloud-platform",
      "https://www.googleapis.com/auth/devstorage.read_only",
      "https://www.googleapis.com/auth/servicecontrol",
      "https://www.googleapis.com/auth/service.management.readonly",
      "https://www.googleapis.com/auth/trace.append"
    ]
  }

  autoscaling {
    min_node_count = var.gke_cluster_autoscaling_min_node_count
    max_node_count = var.gke_cluster_autoscaling_max_node_count
  }
}

错误信息

Pod状态:

default       php-5996c7fbfd-d6xf5                                             0/1     ImagePullBackOff             0          37m

详细报错:

Normal   Pulling    36m (x4 over 37m)      kubelet            Pulling image "europe-docker.pkg.dev/example-999999/eu.gcr.io/example-php-fpm:latest"
  Warning  Failed     36m (x4 over 37m)      kubelet            Failed to pull image "europe-docker.pkg.dev/example-999999/eu.gcr.io/example-php-fpm:latest": rpc error: code = Unknown desc = failed to pull and unpack image "europe-docker.pkg.dev/example-999999/eu.gcr.io/example-php-fpm:latest": failed to resolve reference "europe-docker.pkg.dev/example-999999/eu.gcr.io/example-php-fpm:latest": failed to authorize: failed to fetch oauth token: unexpected status: 403 Forbidden
  Warning  Failed     36m (x4 over 37m)      kubelet            Error: ErrImagePull
  Warning  Failed     35m (x6 over 37m)      kubelet            Error: ImagePullBackOff

经排查,问题与服务账号权限相关,即使通过Cloud SSH生成OAuth token,使用crictl仍无法拉取镜像。

解决方法

为自定义服务账号添加Artifact Registry读取权限,在Terraform中新增以下资源配置:

resource "google_project_iam_member" "artifact_role" {
  role = "roles/artifactregistry.reader"
  member  = "serviceAccount:${google_service_account.main.email}"
  project = var.gcp_project
}

添加后重新部署Terraform,集群节点即可正常拉取Artifact Registry中的私有镜像。


内容的提问来源于stack exchange,提问作者David

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 20:11:47