You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

将Python代码部署到Google Cloud Run时遇权限错误求助

解决Google Cloud Run部署时的Artifact Registry权限错误

问题描述

我是Python新手,部署代码到Google Cloud Run时失败,终端输出如下:

Deploying from source. To deploy a container use [--image]. See https://cloud.google.com/run/docs/deploying-source-code for more details.
Source code location (/Users/name/......):  
Next time, use `gcloud run deploy --source .` to deploy the current directory.

Service name (google-cloud-run):  
Please specify a region:
 [1] asia-east1
 ......
Please enter your numeric choice:  27

To make this the default region, run `gcloud config set run/region us-central1`.

This command is equivalent to running `gcloud builds submit --tag [IMAGE] /Users/name/......` and `gcloud run deploy google-cloud-run --image [IMAGE]`

Allow unauthenticated invocations to [google-cloud-run] (y/N)?  y

Building using Dockerfile and deploying container to Cloud Run service [google-cloud-run] in project [project-id] region [us-central1]
X Building and deploying new service... Building Container.                                                                                    
  ✓ Uploading sources...                                                                                                                       
  - Building Container... Logs are available at [https://console.cloud.google.com/cloud-build/builds/bdaf9cea-3e87-46e4-81f8-33b2675808f8?proje
  ct=1044629281917].                                                                                                                           
  . Creating Revision...                                                                                                                       
  . Routing traffic...                                                                                                                         
  . Setting IAM Policy...                                                                                                                      
Deployment failed                                                                                                                              
ERROR: (gcloud.run.deploy) Build failed; check build logs for details

查看构建日志后发现核心错误:

denied: Permission "artifactregistry.repositories.downloadArtifacts" denied on resource "projects/project-id/locations/us-central1/repositories/cloud-run-source-deploy" (or it may not exist)

我的Python代码:

import os

from flask import Flask

app = Flask(__name__)


@app.route("/")
def hello_world():
    name = os.environ.get("NAME", "World")
    return "Hello {}!".format(name)


if __name__ == "__main__":
    app.run(debug=True, host="0.0.0.0", port=int(os.environ.get("PORT", 8080)))

我的IAM账号已拥有以下角色:

  • Artifact Registry Administrator
  • Artifact Registry Reader
  • Artifact Registry Repository Administrator
  • Artifact Registry Writer
  • Cloud Build Editor
  • Cloud Run Admin
  • Container Registry Service Agent
  • Service Account Admin
  • Service Account User
  • Service Usage Admin
  • Service Usage Consumer
  • Source Repository Administrator
  • Source Repository Reader
  • Source Repository Writer
  • Storage Admin
  • Storage Object Admin
  • Viewer

解决方案

1. 为Cloud Build服务账号添加权限

部署过程中,实际执行构建操作的是Cloud Build服务账号,而非你当前登录的IAM账号。你需要给该服务账号授予Artifact Registry相关权限:

  • 找到你的Cloud Build服务账号,格式为[你的项目编号]@cloudbuild.gserviceaccount.com
  • 进入Google Cloud控制台的IAM页面,找到该服务账号,点击编辑权限
  • 添加Artifact Registry Reader角色(该角色包含artifactregistry.repositories.downloadArtifacts权限)

2. 确认Artifact Registry仓库存在

检查错误提示中的仓库projects/project-id/locations/us-central1/repositories/cloud-run-source-deploy是否存在:

  • 如果不存在,前往Artifact Registry页面,手动创建同区域、同名的Docker类型仓库
  • 或者确保你的账号拥有创建Artifact Registry仓库的权限,让Cloud Run部署流程自动创建

3. 重新执行部署

完成上述操作后,重新运行部署命令:

gcloud run deploy --source .

内容的提问来源于stack exchange,提问作者My Car

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 01:31:35