You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP服务账号生成Cloud Storage Blobs签名URL的权限及Terraform示例

Got it, let's break this down clearly. You want to strip down your default App Engine service account to only the permissions needed to generate GET and PUT signed URLs for objects in GCS bucket B1—no extra bloat. Here's the exact setup and Terraform code to make that happen:

Minimal Permissions for GCS Signed URLs (GET/PUT)

First, forget the broad default permissions. The service account only needs two core sets of permissions:

1. GCS Object Operations

To generate signed URLs for reading (GET) or writing/overwriting (PUT) objects in B1:

  • storage.objects.get: Required for GET signed URLs (lets the service account authorize read access via the signature)
  • storage.objects.create: Required for PUT signed URLs (lets the service account authorize write/overwrite access)

2. Signing Capability

Generating a signed URL requires the service account to cryptographically sign the request. For this, you need:

  • iam.serviceAccounts.signBlob: Grants the ability to generate signatures using the service account's identity. We'll scope this to the service account itself to keep it secure.

Role Strategy

Instead of assigning individual permissions directly, use a custom IAM role for the GCS object permissions (cleaner to manage) and pair it with a minimal token creator role for signing.


Terraform Script to Lock Down Permissions

Here's a complete, production-ready Terraform configuration that implements this setup:

# Configure the GCP provider
provider "google" {
  project = "your-gcp-project-id" # Replace with your actual project ID
  region  = "us-central1"         # Replace with your preferred region
}

# Define your service account and bucket details
locals {
  app_engine_sa = "${var.project_id}@appspot.gserviceaccount.com"
  gcs_bucket    = "B1"
}

# Custom role for GCS GET/PUT signed URL permissions
resource "google_project_iam_custom_role" "gcs_signed_url_role" {
  project     = var.project_id
  role_id     = "gcs_signed_url_generator"
  title       = "GCS Signed URL Generator (GET/PUT)"
  description = "Minimal role to generate GET/PUT signed URLs for objects in bucket ${local.gcs_bucket}"
  permissions = [
    "storage.objects.get",
    "storage.objects.create",
  ]
}

# Bind the custom role to the App Engine SA, restricted to bucket B1
resource "google_storage_bucket_iam_member" "bucket_permissions" {
  bucket = local.gcs_bucket
  role   = google_project_iam_custom_role.gcs_signed_url_role.id
  member = "serviceAccount:${local.app_engine_sa}"
}

# Grant signing permission to the SA (scoped to itself for security)
resource "google_service_account_iam_member" "sign_blob_access" {
  service_account_id = local.app_engine_sa
  role               = "roles/iam.serviceAccountTokenCreator"
  member             = "serviceAccount:${local.app_engine_sa}"
}

Key Notes:

  • Replace your-gcp-project-id and adjust the region as needed
  • The roles/iam.serviceAccountTokenCreator built-in role is used here because it safely includes the required iam.serviceAccounts.signBlob permission without overgranting
  • The custom role is explicitly bound only to bucket B1, so the SA can't touch other buckets
  • If you want to avoid the built-in role, you can create a second custom role with just iam.serviceAccounts.signBlob and grant that instead

How to Verify

After applying the Terraform config, double-check permissions in the GCP Console:

  1. Go to IAM & Admin > IAM
  2. Find your App Engine default service account
  3. Confirm it has:
    • The custom GCS Signed URL Generator (GET/PUT) role for bucket B1
    • The Service Account Token Creator role (scoped to itself)

This setup ensures your service account has exactly what it needs—no extra permissions to risk.

内容的提问来源于stack exchange,提问作者Aseem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 17:50:22