无需凭据从GKE Pod访问GCS遇403权限错误排查
GKE Pod访问私有GCS Bucket出现403权限错误
环境配置
- 集群及节点池使用的服务账号(SA)拥有以下角色:
"roles/compute.admin", "roles/compute.viewer", "roles/compute.securityAdmin", "roles/iam.serviceAccountUser", "roles/iam.serviceAccountAdmin", "roles/resourcemanager.projectIamAdmin", "roles/container.admin", "roles/artifactregistry.admin", "roles/storage.admin" - 节点池配置的OAuth Scopes:
"https://www.googleapis.com/auth/cloud-platform", "https://www.googleapis.com/auth/devstorage.read_write", - 私有GCS Bucket已将上述服务账号设为权限主体,并赋予
storage.admin角色
问题现象
从GKE Pod读写该Bucket时触发403权限错误:
# 读取操作报错 AccessDeniedException: 403 Caller does not have storage.objects.list access to the Google Cloud Storage bucket # 写入操作报错 AccessDeniedException: 403 Caller does not have storage.objects.create access to the Google Cloud Storage object
补充信息
- 已查阅相关解决方案,但均依赖凭据配置,不符合我们无需维护SA密钥或任何凭据即可实现读写的需求
- 更新:经检查,GKE集群及节点池已通过Terraform的beta-private-cluster模块默认启用Workload Identity,但访问问题仍存在,附集群及节点池安全设置截图
内容的提问来源于stack exchange,提问作者Nitin G
相关产品推荐
相关产品推荐

