You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用deploy-cloud-functions GitHub Action部署云函数遇权限错误

问题描述

使用google-github-actions/deploy-cloud-functions部署GCP云函数时,同一项目、同一服务账号、同一工作流下,第一个函数部署成功,第二个函数出现权限错误:

Run google-github-actions/deploy-cloud-functions@v0
Extracted project ID 'my-project' from $GCLOUD_PROJECT
Created zip file from './' at '/tmp/cfsrc-50378e4a065cfb06ed27a123.zip'
Error: google-github-actions/deploy-cloud-functions failed with: failed to upload zip file: The caller does not have permission

已完成的配置:

  • 为服务账号github-actions-sa@my-project.iam.gserviceaccount.com分配了项目级iam.serviceAccountUser和iam.cloudFunctionsDeveloper角色
  • 配置了Workload Identity Federation,步骤如下:
    创建池:
    gcloud iam workload-identity-pools create github-pool \
        --location="global" \
        --display-name="GitHub pool"
    
    创建提供商:
    gcloud iam workload-identity-pools providers create-oidc github-provider \
        --location='global' \
        --workload-identity-pool=github-pool \
        --display-name='GitHub provider' \
        --attribute-mapping='google.subject=assertion.sub,attribute.actor=assertion.actor,attribute.repository=assertion.repository' \
        --issuer-uri='https://token.actions.githubusercontent.com'
    
    授权服务账号 impersonation:
    gcloud iam service-accounts add-iam-policy-binding \
        github-actions-sa@my-project.iam.gserviceaccount.com \
        --role="roles/iam.workloadIdentityUser" \
        --member="principalSet://iam.googleapis.com/projects/1234567891234/locations/global/workloadIdentityPools/github-pool/attribute.repository/my-org/my-repo"
    
  • 使用的GitHub Actions工作流:
    name: CD
    
    on:
      push:
        branches: [main]
    
      workflow_dispatch:
    
    jobs:
      deploy:
        runs-on: ubuntu-latest
    
        permissions:
          contents: "read"
          id-token: "write"
    
        steps:
          - name: "Checkout repository"
            uses: actions/checkout@v3
    
          - id: "auth"
            name: "Authenticate to Google Cloud"
            uses: "google-github-actions/auth@v0"
            with:
              workload_identity_provider: "projects/1234567891234/locations/global/workloadIdentityPools/github-pool"
              service_account: "github-actions-sa@my-project.iam.gserviceaccount.com"
    
          - id: "deploy"
            uses: "google-github-actions/deploy-cloud-functions@v0"
            with:
              name: "my-function"
              runtime: "python310"
              entry_point: "main"
              region: "europe-west6"
              service_account_email: github-actions-sa@my-project.iam.gserviceaccount.com
    
排查与解决步骤
  1. 补充存储桶权限
    云函数部署时会自动将代码包上传到项目默认云存储桶(gs://[PROJECT_ID].appspot.com),iam.cloudFunctionsDeveloper角色的存储权限可能被自定义策略覆盖。给服务账号添加roles/storage.objectCreator角色,或直接授权storage.objects.create、storage.objects.get权限,解决代码包上传的权限缺口。

  2. 核对第二个函数的部署参数差异
    确认第二个函数的配置是否有特殊点:比如函数在子目录(需指定source参数)、函数已存在(检查现有函数的权限绑定)、启用了VPC/私有网络(需额外的网络权限)。

  3. 通过GCP Audit Logs定位具体权限
    进入GCP控制台的日志资源管理器,筛选resource.type="cloud_function"和protoPayload.methodName="google.cloud.functions.v1.CloudFunctionsService.CreateFunction",查看权限拒绝的详细日志,日志会明确显示缺失的权限名称和调用主体,精准定位问题。

  4. 验证Workload Identity身份有效性
    本地模拟GitHub身份验证流程,生成凭证并验证:

    gcloud iam workload-identity-pools create-cred-config \
        projects/1234567891234/locations/global/workloadIdentityPools/github-pool/providers/github-provider \
        --service-account=github-actions-sa@my-project.iam.gserviceaccount.com \
        --output-file=cred.json
    export GOOGLE_APPLICATION_CREDENTIALS=./cred.json
    gcloud auth print-identity-token
    

    若能成功获取令牌,说明身份配置正常;否则检查attribute.repository是否与GitHub仓库路径完全匹配(区分大小写)。

  5. 升级GitHub Action版本
    当前使用的deploy-cloud-functions@v0是旧版本,存在权限处理相关的已知bug。升级到最新稳定版(如@v2),新版本优化了权限逻辑和错误提示:

    uses: "google-github-actions/deploy-cloud-functions@v2"
    
  6. 检查函数运行服务账号权限
    如果第二个函数指定了不同的运行服务账号(非部署用的github-actions-sa),需确保部署服务账号拥有iam.serviceAccountUser权限来扮演该运行服务账号。

内容的提问来源于stack exchange,提问作者ianyoung

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 08:40:33