Terraform部署Google Cloud Functions 2失败:容器健康检查未通过
问题描述
部署Terraform配置的Google Cloud Functions 2nd gen函数时持续失败,报错如下:
Error: Error waiting to create function: Error waiting for Creating function: Error code 3, message: Could not create or update Cloud Run service ramowka-357-schedule, Container Healthcheck failed. Revision 'ramowka-357-schedule-00001-few' is not ready and cannot serve traffic. The user-provided container failed to start and listen on the port defined provided by the PORT=8080 environment variable. Logs for this revision might contain more information.
在Google Cloud控制台中观察到:函数被创建为HTTP触发器,未生成对应的Eventarc触发器;手动通过控制台编辑函数并添加Pub/Sub主题的Eventarc触发器后,函数重新部署可正常运行。
Terraform配置代码:
resource "google_cloudfunctions2_function" "default" { name = var.function_name location = var.function_location build_config { runtime = "python38" entry_point = var.function_name source { storage_source { bucket = google_storage_bucket.source.name object = google_storage_bucket_object.zip.name } } } service_config { max_instance_count = 1 available_memory = "128Mi" timeout_seconds = 120 environment_variables = { USER_EMAIL = var.user_email SCHEDULE_URL = var.schedule_url DRY_RUN = var.dry_run } } event_trigger { trigger_region = var.function_location event_type = "google.cloud.pubsub.topic.v1.messagePublished" pubsub_topic = google_pubsub_topic.default.id retry_policy = "RETRY_POLICY_RETRY" } depends_on = [ google_pubsub_topic.default ] }
简化后的函数代码:
main.py
import functions_framework @functions_framework.cloud_event def subscribe(event): print('test')
requirements.txt
functions-framework==3.*
问题原因与解决方案
核心原因
你的函数代码采用Cloud Event模式(@functions_framework.cloud_event装饰器),但Terraform实际创建的是HTTP触发器。HTTP触发器要求函数监听PORT环境变量指定的端口(默认8080),而Cloud Event模式的函数不会启动HTTP服务,因此触发健康检查失败。
Terraform未正确创建Eventarc触发器的原因通常是权限缺失或依赖未配置。
解决方案
- 启用Eventarc API
Cloud Functions 2nd gen的Eventarc触发器依赖Eventarc API,需确保项目中已启用该API。可通过Terraform添加以下资源:
resource "google_project_service" "eventarc" { service = "eventarc.googleapis.com" }
并将其加入google_cloudfunctions2_function的depends_on列表:
depends_on = [ google_pubsub_topic.default, google_project_service.eventarc ]
- 确保服务账号具备足够权限
Terraform使用的服务账号需要拥有以下关键权限:
eventarc.triggers.create:创建Eventarc触发器pubsub.topics.setIamPolicy:为Eventarc服务账号配置Pub/Sub主题的订阅权限cloudfunctions.functions.create:创建Cloud Functions
可直接为服务账号绑定roles/eventarc.admin、roles/cloudfunctions.developer、roles/pubsub.editor等预定义角色。
- 明确指定Eventarc触发器的服务账号
在event_trigger块中添加service_account_email字段,使用项目的App Engine默认服务账号(格式为{PROJECT_ID}@appspot.gserviceaccount.com)或自定义服务账号:
event_trigger { trigger_region = var.function_location event_type = "google.cloud.pubsub.topic.v1.messagePublished" pubsub_topic = google_pubsub_topic.default.id retry_policy = "RETRY_POLICY_RETRY" service_account_email = "${var.project_id}@appspot.gserviceaccount.com" }
- 验证函数入口配置
确保build_config中的entry_point与函数代码中的函数名一致。你的配置中entry_point是var.function_name,需确认该变量值等于代码中的subscribe,或者直接改为entry_point = "subscribe"。
完成以上配置后重新部署,Terraform将正确创建Eventarc触发器,函数以Cloud Event模式运行,无需监听HTTP端口,即可通过Pub/Sub消息触发执行。
内容的提问来源于stack exchange,提问作者mrp1nk
相关产品推荐
相关产品推荐

