You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud Functions Gen2通过API Gateway授权请求失败问题排查

Google Cloud Functions Gen2 与 API Gateway 身份验证问题

近期切换至Google Cloud Functions Gen2,遇到API Gateway身份验证问题:网关调用的Gen2云函数已设置禁止未授权用户访问,且网关已绑定具备Cloud Functions Invoker角色(排查期间还添加过Owner角色)的服务账号,但调用仍失败。

云函数日志错误信息

The request was not authenticated. Either allow unauthenticated invocations or set the proper Authorization header. Read more at https://cloud.google.com/run/docs/securing/authenticating Additional troubleshooting documentation can be found at: https://cloud.google.com/run/docs/troubleshooting#unauthorized-client

对比测试结果

  • 相同代码的Google Cloud Functions Gen1测试函数,禁止未授权访问,通过API Gateway调用正常
  • 允许未授权访问的Gen2函数,通过API Gateway调用正常
  • 仅禁止未授权访问的Gen2函数,无法通过API Gateway正常调用

API Gateway YAML配置(敏感信息已替换为XXX)

swagger: "2.0"
info:
  title: XXXXXXXX api gateway for carson blade analytics app
  description: Sample API on API Gateway with a Google Cloud Functions backend
  version: 1.0.0
schemes:
  - https
produces:
  - application/json
paths:
  /convert_csv:
    get:
      summary: Converts an XLSX file to a CSV file
      operationId: convert
      x-google-backend:
        address: https://convert-csv-XXXXX-ue.a.run.app
      responses:
        "200":
          description: A successful response
          schema:
            type: string

已验证的请求头信息

调用允许未授权访问的Gen2函数时,查看其收到的头部信息如下:

{     
 "aud": "https://convert-csv-XXXXX-ue.a.run.app/",
 "azp": "XXXX",
 "email": "XXX@XXX.iam.gserviceaccount.com",
 "email_verified": true,
 "exp": 1660101164,
 "iat": 1660097564,
 "iss": "https://accounts.google.com",
  "sub": "XXXXX"
}

其中email对应具备正确Cloud Functions Invoker角色的服务账号邮箱,aud与API Gateway YAML中的地址一致,网关已按预期用其服务账号替换发送的身份验证头部。已查阅相关文档并尝试多种YAML配置,问题仍未解决。

总结:通过Postman调用API Gateway绑定的函数时,仅禁止未授权访问的Gen2函数无法工作,恳请提供帮助。

内容的提问来源于stack exchange,提问作者Jad

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 01:54:22