You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform Apply触发403错误:GCP项目结算账户异常排查求助

问题描述

执行terraform apply时触发403错误:

{"error":{"code":403,"message":"The billing account for the owning project is disabled in state absent","errors":[{"message":"The billing account for the owning project is disabled in state absent","domain":"global","reason":"accountDisabled","locationType":"header","location":"Authorization"}]}}: timestamp=2022-12-31T00:04:43.690-0500

已完成以下验证操作:

  • 为项目关联了结算账户
  • 使用同一服务账号在Shell执行gcloud命令无异常:
terraform_gcp % gcloud auth activate-service-account --key-file=sakey.json
Activated service account credentials for: [gcp-terraform@saproject.iam.gserviceaccount.com]
terraform_gcp % gsutil ls
gs://mygcptfstatebucket/
terraform_gcp % gcloud compute instances list
Listed 0 items.

当前main.tf配置:

terraform {
  required_providers {
    google = {
      source  = "hashicorp/google"
      version = "4.47.0"
    }
  }
}


provider "google" {
  project = "my-gcp-project"
  region  = "us-east1"
  zone    = "us-east1-b"
}

需要排查该错误的解决思路。


排查思路
  • 确认Terraform使用的服务账号与gcloud一致
    检查Terraform是否确实使用了你激活的sakey.json密钥文件,避免环境变量或其他配置干扰。可以在provider块中显式指定credentials路径:

    provider "google" {
      project     = "my-gcp-project"
      region      = "us-east1"
      zone        = "us-east1-b"
      credentials = file("sakey.json")
    }
    

    也可以临时设置环境变量验证:

    export GOOGLE_APPLICATION_CREDENTIALS="./sakey.json"
    terraform apply
    
  • 检查项目结算账户的状态与关联关系
    即使已关联结算账户,也要确认:

    1. 结算账户本身处于活跃状态(无暂停、禁用情况),可通过GCP控制台结算页面查看
    2. 项目与结算账户的关联是生效状态,无待激活或关联失败情况
    3. 确认my-gcp-project是实际关联结算账户的项目,避免项目ID输入错误
  • 验证服务账号的权限
    gcloud执行的gsutil ls和compute instances list仅需基础查看权限,但Terraform创建资源需要更全面的权限。检查服务账号是否拥有:

    • 项目的结算查看/管理权限(如roles/billing.user或更高)
    • 目标资源的创建权限(如创建VM需roles/compute.instanceAdmin)
  • 检查Terraform状态文件的影响
    若之前使用过其他项目或服务账号执行Terraform,状态文件可能残留旧信息:

    1. 备份当前terraform.tfstate文件
    2. 执行terraform init -reconfigure重新初始化配置
    3. 临时使用terraform plan -refresh=false跳过状态刷新,验证是否能正常执行(仅用于排查,不建议长期使用)
  • 核对GCP provider版本
    使用的4.47.0版本可能存在结算相关已知问题,尝试升级到较新稳定版本:

    terraform {
      required_providers {
        google = {
          source  = "hashicorp/google"
          version = "~> 4.60.0"
        }
      }
    }
    

    执行terraform init -upgrade完成升级

内容的提问来源于stack exchange,提问作者Bhanu Pratap

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 05:51:28