You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需凭据从GKE Pod访问GCS遇403权限错误排查

GKE Pod访问私有GCS Bucket出现403权限错误

环境配置

  • 集群及节点池使用的服务账号(SA)拥有以下角色:
    "roles/compute.admin",
    "roles/compute.viewer",
    "roles/compute.securityAdmin",
    "roles/iam.serviceAccountUser",
    "roles/iam.serviceAccountAdmin",
    "roles/resourcemanager.projectIamAdmin",
    "roles/container.admin",
    "roles/artifactregistry.admin",
    "roles/storage.admin"
    
  • 节点池配置的OAuth Scopes:
    "https://www.googleapis.com/auth/cloud-platform",
    "https://www.googleapis.com/auth/devstorage.read_write",
    
  • 私有GCS Bucket已将上述服务账号设为权限主体,并赋予storage.admin角色

问题现象

从GKE Pod读写该Bucket时触发403权限错误:

# 读取操作报错
AccessDeniedException: 403 Caller does not have storage.objects.list access to the Google Cloud Storage bucket

# 写入操作报错
AccessDeniedException: 403 Caller does not have storage.objects.create access to the Google Cloud Storage object

补充信息

  • 已查阅相关解决方案,但均依赖凭据配置,不符合我们无需维护SA密钥或任何凭据即可实现读写的需求
  • 更新:经检查,GKE集群及节点池已通过Terraform的beta-private-cluster模块默认启用Workload Identity,但访问问题仍存在,附集群及节点池安全设置截图

内容的提问来源于stack exchange,提问作者Nitin G

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.22 19:45:51