Google Cloud Functions Gen2通过API Gateway授权请求失败问题排查
近期切换至Google Cloud Functions Gen2,遇到API Gateway身份验证问题:网关调用的Gen2云函数已设置禁止未授权用户访问,且网关已绑定具备Cloud Functions Invoker角色(排查期间还添加过Owner角色)的服务账号,但调用仍失败。
云函数日志错误信息
The request was not authenticated. Either allow unauthenticated invocations or set the proper Authorization header. Read more at https://cloud.google.com/run/docs/securing/authenticating Additional troubleshooting documentation can be found at: https://cloud.google.com/run/docs/troubleshooting#unauthorized-client
对比测试结果
- 相同代码的Google Cloud Functions Gen1测试函数,禁止未授权访问,通过API Gateway调用正常
- 允许未授权访问的Gen2函数,通过API Gateway调用正常
- 仅禁止未授权访问的Gen2函数,无法通过API Gateway正常调用
API Gateway YAML配置(敏感信息已替换为XXX)
swagger: "2.0" info: title: XXXXXXXX api gateway for carson blade analytics app description: Sample API on API Gateway with a Google Cloud Functions backend version: 1.0.0 schemes: - https produces: - application/json paths: /convert_csv: get: summary: Converts an XLSX file to a CSV file operationId: convert x-google-backend: address: https://convert-csv-XXXXX-ue.a.run.app responses: "200": description: A successful response schema: type: string
已验证的请求头信息
调用允许未授权访问的Gen2函数时,查看其收到的头部信息如下:
{ "aud": "https://convert-csv-XXXXX-ue.a.run.app/", "azp": "XXXX", "email": "XXX@XXX.iam.gserviceaccount.com", "email_verified": true, "exp": 1660101164, "iat": 1660097564, "iss": "https://accounts.google.com", "sub": "XXXXX" }
其中email对应具备正确Cloud Functions Invoker角色的服务账号邮箱,aud与API Gateway YAML中的地址一致,网关已按预期用其服务账号替换发送的身份验证头部。已查阅相关文档并尝试多种YAML配置,问题仍未解决。
总结:通过Postman调用API Gateway绑定的函数时,仅禁止未授权访问的Gen2函数无法工作,恳请提供帮助。
内容的提问来源于stack exchange,提问作者Jad

