使用deploy-cloud-functions GitHub Action部署云函数遇权限错误
使用google-github-actions/deploy-cloud-functions部署GCP云函数时,同一项目、同一服务账号、同一工作流下,第一个函数部署成功,第二个函数出现权限错误:
Run google-github-actions/deploy-cloud-functions@v0 Extracted project ID 'my-project' from $GCLOUD_PROJECT Created zip file from './' at '/tmp/cfsrc-50378e4a065cfb06ed27a123.zip' Error: google-github-actions/deploy-cloud-functions failed with: failed to upload zip file: The caller does not have permission
已完成的配置:
- 为服务账号
github-actions-sa@my-project.iam.gserviceaccount.com分配了项目级iam.serviceAccountUser和iam.cloudFunctionsDeveloper角色 - 配置了Workload Identity Federation,步骤如下:
创建池:
创建提供商:gcloud iam workload-identity-pools create github-pool \ --location="global" \ --display-name="GitHub pool"
授权服务账号 impersonation:gcloud iam workload-identity-pools providers create-oidc github-provider \ --location='global' \ --workload-identity-pool=github-pool \ --display-name='GitHub provider' \ --attribute-mapping='google.subject=assertion.sub,attribute.actor=assertion.actor,attribute.repository=assertion.repository' \ --issuer-uri='https://token.actions.githubusercontent.com'gcloud iam service-accounts add-iam-policy-binding \ github-actions-sa@my-project.iam.gserviceaccount.com \ --role="roles/iam.workloadIdentityUser" \ --member="principalSet://iam.googleapis.com/projects/1234567891234/locations/global/workloadIdentityPools/github-pool/attribute.repository/my-org/my-repo" - 使用的GitHub Actions工作流:
name: CD on: push: branches: [main] workflow_dispatch: jobs: deploy: runs-on: ubuntu-latest permissions: contents: "read" id-token: "write" steps: - name: "Checkout repository" uses: actions/checkout@v3 - id: "auth" name: "Authenticate to Google Cloud" uses: "google-github-actions/auth@v0" with: workload_identity_provider: "projects/1234567891234/locations/global/workloadIdentityPools/github-pool" service_account: "github-actions-sa@my-project.iam.gserviceaccount.com" - id: "deploy" uses: "google-github-actions/deploy-cloud-functions@v0" with: name: "my-function" runtime: "python310" entry_point: "main" region: "europe-west6" service_account_email: github-actions-sa@my-project.iam.gserviceaccount.com
补充存储桶权限
云函数部署时会自动将代码包上传到项目默认云存储桶(gs://[PROJECT_ID].appspot.com),iam.cloudFunctionsDeveloper角色的存储权限可能被自定义策略覆盖。给服务账号添加roles/storage.objectCreator角色,或直接授权storage.objects.create、storage.objects.get权限,解决代码包上传的权限缺口。核对第二个函数的部署参数差异
确认第二个函数的配置是否有特殊点:比如函数在子目录(需指定source参数)、函数已存在(检查现有函数的权限绑定)、启用了VPC/私有网络(需额外的网络权限)。通过GCP Audit Logs定位具体权限
进入GCP控制台的日志资源管理器,筛选resource.type="cloud_function"和protoPayload.methodName="google.cloud.functions.v1.CloudFunctionsService.CreateFunction",查看权限拒绝的详细日志,日志会明确显示缺失的权限名称和调用主体,精准定位问题。验证Workload Identity身份有效性
本地模拟GitHub身份验证流程,生成凭证并验证:gcloud iam workload-identity-pools create-cred-config \ projects/1234567891234/locations/global/workloadIdentityPools/github-pool/providers/github-provider \ --service-account=github-actions-sa@my-project.iam.gserviceaccount.com \ --output-file=cred.json export GOOGLE_APPLICATION_CREDENTIALS=./cred.json gcloud auth print-identity-token若能成功获取令牌,说明身份配置正常;否则检查
attribute.repository是否与GitHub仓库路径完全匹配(区分大小写)。升级GitHub Action版本
当前使用的deploy-cloud-functions@v0是旧版本,存在权限处理相关的已知bug。升级到最新稳定版(如@v2),新版本优化了权限逻辑和错误提示:uses: "google-github-actions/deploy-cloud-functions@v2"检查函数运行服务账号权限
如果第二个函数指定了不同的运行服务账号(非部署用的github-actions-sa),需确保部署服务账号拥有iam.serviceAccountUser权限来扮演该运行服务账号。
内容的提问来源于stack exchange,提问作者ianyoung

