如何解决Docker容器向Google Cloud Logging推送日志的权限问题?
I’ve run into this exact issue with COS and the gcplogs driver before—let’s walk through the key fixes that usually resolve this permission error, even when you think the service account roles are set correctly.
1. Verify the Correct Service Account is Being Used
Container Optimized OS defaults to using the instance's attached service account (via the metadata server) instead of any local service account key file you might have copied over. If you configured a separate service account with log.admin/log.writer but didn’t attach it to the COS instance, Docker will still use the instance’s default service account which likely lacks the necessary permissions.
- Go to your Google Cloud Console → Compute Engine → VM Instances
- Select your COS instance → Click Edit
- Under Service account, ensure the account listed has the
Logs Writer(roles/logging.logWriter) orLogging Admin(roles/logging.admin) role assigned at the project level. - If not, change the service account to the one you configured, or grant the required roles to the existing instance service account.
2. Properly Configure Local Service Account Keys (If Using Them)
If you’re explicitly using a service account key file instead of the instance metadata, you need to make sure Docker can access it correctly (remember COS is mostly read-only, so stick to allowed writable paths):
- Copy your service account key JSON file to
/var/lib/docker/gcp-service-account-key.json(this directory is writable on COS) - Update your Docker run command to include the key path:
Alternatively, set this as the default for all containers by editingdocker run --log-driver=gcplogs --log-opt gcp-project=your-project-id --log-opt gcp-logging-service-account-key=/var/lib/docker/gcp-service-account-key.json nginx/etc/docker/daemon.json(create it if it doesn’t exist):{ "log-driver": "gcplogs", "log-opts": { "gcp-project": "your-project-id", "gcp-logging-service-account-key": "/var/lib/docker/gcp-service-account-key.json" } } - Restart the Docker daemon to apply changes:
sudo systemctl restart docker
3. Validate Permissions and API Access
Even with the right roles, double-check these details:
- Ensure the Cloud Logging API is enabled for your project (Console → APIs & Services → Library → search for "Cloud Logging API" and confirm it’s enabled)
- Test the service account’s permissions directly on the COS instance:
If this command fails with permission errors, the issue is with the service account’s role assignment, not Docker’s configuration. Recheck that the roles are granted at the project level (not just a folder or resource level that doesn’t include your instance).# If using instance metadata service account gcloud logging entries list --limit 5 # If using a local key file gcloud auth activate-service-account --key-file=/var/lib/docker/gcp-service-account-key.json gcloud logging entries list --limit 5
4. Check for COS-Specific Restrictions
COS locks down most system directories, so avoid placing service account keys in paths like /home or /tmp (which are ephemeral or restricted). Stick to /var/lib/docker or /etc/docker for persistent, accessible files.
Once you’ve applied these steps, re-run your nginx container command—you should no longer see the permission denied error, and logs should flow to Google Logs Viewer.
内容的提问来源于stack exchange,提问作者GamerAtmos

