You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform部署中隐式配置GCP API Gateway的Cloud Run后端路径?

解决方案:动态生成OpenAPI规格文件

你可以通过Terraform的模板渲染功能,在部署阶段动态插入Cloud Run服务的端点信息,无需分两次部署。下面是两种具体实现方式:

方法1:动态注入Cloud Run完整URL

步骤1:将静态规格文件改为模板

把原来的spec.yaml重命名为spec.tpl.yaml,将需要替换的Cloud Run端点用变量占位:

openapi: 3.0.1
info:
  title: 我的API
  version: "1.0"
paths:
  /hello:
    get:
      x-google-backend:
        address: ${cloud_run_service_url}  # 用变量占位Cloud Run端点
      responses:
        '200':
          description: 成功响应

步骤2:在Terraform配置中渲染模板并传入API Gateway

修改google_api_gateway_api_config资源,用templatefile函数加载模板,传入Cloud Run服务的URL后编码为base64:

# 先定义Cloud Run服务
resource "google_cloud_run_service" "my_service" {
  name     = "my-demo-service"
  location = "us-central1"

  template {
    spec {
      containers {
        image = "gcr.io/your-project/your-image:latest"
      }
    }
  }

  traffic {
    percent         = 100
    latest_revision = true
  }
}

# 配置API Gateway
resource "google_api_gateway_api_config" "api_cfg" {
  provider = google-beta
  api      = google_api_gateway_api.api.api_id
  api_config_id = "cfg"

  openapi_documents {
    document {
      path = "spec.yaml"
      # 动态渲染模板并编码
      contents = base64encode(templatefile("spec.tpl.yaml", {
        cloud_run_service_url = google_cloud_run_service.my_service.status[0].url
      }))
    }
  }

  lifecycle {
    create_before_destroy = true
  }
}

Terraform会自动处理依赖顺序:先创建Cloud Run服务并获取其URL,再渲染生成完整的OpenAPI规格,最后创建API Gateway配置,全程一次terraform apply即可完成。

方法2:使用Cloud Run服务资源名称(更稳定)

如果不想依赖动态生成的URL,可以直接用Cloud Run服务的资源名称配置后端,这种方式需要提前配置IAM权限:

步骤1:修改模板使用服务资源名称

openapi: 3.0.1
info:
  title: 我的API
  version: "1.0"
paths:
  /hello:
    get:
      x-google-backend:
        # 使用Cloud Run服务的资源名称
        serviceName: projects/${project_id}/locations/${location}/services/${cloud_run_service_name}
        # 指定API Gateway调用Cloud Run的服务账号
        serviceAccount: ${api_gateway_sa_email}
      responses:
        '200':
          description: 成功响应

步骤2:配置IAM权限与Terraform资源

# 创建API Gateway专用服务账号
resource "google_service_account" "api_gateway_sa" {
  account_id = "api-gateway-invoker"
}

# 给服务账号添加调用Cloud Run的权限
resource "google_cloud_run_service_iam_binding" "api_gateway_access" {
  service  = google_cloud_run_service.my_service.name
  location = google_cloud_run_service.my_service.location
  role     = "roles/run.invoker"

  members = [
    "serviceAccount:${google_service_account.api_gateway_sa.email}",
  ]
}

# 渲染模板并配置API Gateway
resource "google_api_gateway_api_config" "api_cfg" {
  provider = google-beta
  api      = google_api_gateway_api.api.api_id
  api_config_id = "cfg"

  openapi_documents {
    document {
      path = "spec.yaml"
      contents = base64encode(templatefile("spec.tpl.yaml", {
        project_id           = var.project_id
        location             = google_cloud_run_service.my_service.location
        cloud_run_service_name = google_cloud_run_service.my_service.name
        api_gateway_sa_email = google_service_account.api_gateway_sa.email
      }))
    }
  }

  lifecycle {
    create_before_destroy = true
  }
}

这种方式不需要等待Cloud Run生成URL,直接用预定义的服务名称,权限配置完成后即可正常调用,适合对稳定性要求更高的场景。

内容的提问来源于stack exchange,提问作者Dan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 15:20:33