使用Google官方客户端遇400错误:RESOURCE_PROJECT_INVALID求助
问题
使用Google官方Python客户端调用Artifact Registry API时触发400错误,错误码RESOURCE_PROJECT_INVALID。已通过Google Cloud IAM创建服务账号并生成credentials.json,确认其中的project ID正确。
执行代码如下:
from google.cloud import artifactregistry_v1 from google.oauth2 import service_account credentials = service_account.Credentials.from_service_account_file('credentials.json') client = artifactregistry_v1.ArtifactRegistryClient(credentials=credentials) client.list_files()
错误信息:
InvalidArgument: 400 Invalid resource field value in the request. [reason: "RESOURCE_PROJECT_INVALID" domain: "googleapis.com" metadata { key: "service" value: "artifactregistry.googleapis.com" } metadata { key: "method" value: "google.devtools.artifactregistry.v1.ArtifactRegistry.ListFiles" } ]
credentials.json内容(Google生成):
{ "type": "service_account", "project_id": "myproject", "private_key_id": "cccccccccccccccccc", "private_key": "-----BEGIN PRIVATE KEY-----\naaaaaaaabbbbbbbb=\n-----END PRIVATE KEY-----\n", "client_email": "myservice@myproject.iam.gserviceaccount.com", "client_id": "1000000000000000", "auth_uri": "https://accounts.google.com/o/oauth2/auth", "token_uri": "https://oauth2.googleapis.com/token", "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs", "client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/myservice%40myproject.iam.gserviceaccount.com" }
原因与解决办法
原因
list_files()方法需要指定完整的仓库资源路径作为参数,直接调用该方法而不传参数时,API无法识别要操作的具体资源,因此返回RESOURCE_PROJECT_INVALID错误。
解决办法
调用list_files()时必须传入包含项目ID、区域、仓库名称的父资源路径,格式为:projects/{project_id}/locations/{location}/repositories/{repository_name}
修改后的代码示例:
from google.cloud import artifactregistry_v1 from google.oauth2 import service_account credentials = service_account.Credentials.from_service_account_file('credentials.json') client = artifactregistry_v1.ArtifactRegistryClient(credentials=credentials) # 替换为实际的项目ID、区域、仓库名称 parent = "projects/myproject/locations/us-central1/repositories/my-repo" response = client.list_files(parent=parent) for file in response: print(file.name)
额外注意事项:
- 确保服务账号拥有
Artifact Registry Reader或更高权限(如roles/artifactregistry.reader) - 确认指定的区域、仓库名称在目标项目中真实存在
- 建议升级到最新版
google-cloud-artifactregistry客户端库,避免版本兼容性问题
内容的提问来源于stack exchange,提问作者Pithikos
相关产品推荐
相关产品推荐

