You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何确定Google Cloud Policy Troubleshooter中需填写的资源?

Google Cloud Monitoring IAM权限问题解决指南

问题概述

同事访问Google Cloud Monitoring的告警事件页面时,出现加载错误:

Error loading /monitoring/alerting/incidents/[incident id]?project=[project]

从错误中明确需要的权限为:

  • monitoring.incidents.get
  • stackdriver.projects.get

Policy Troubleshooter使用障碍

尝试通过Policy Troubleshooter排查所需IAM角色时,遇到以下问题:

  • 工具UI未提供资源格式填写的明确入口,无错误提示
  • 尝试使用monitoring.googleapis.com相关的完整资源路径仍无法正常验证
  • 未开启日志服务,无法借助日志探索者辅助排查

解决方案

1. 直接分配预定义角色(最快解决)

无需纠结工具问题,直接给同事分配包含目标权限的预定义角色,遵循最小权限原则:

  • Monitoring Viewer (roles/monitoring.viewer):包含monitoring.incidents.get和stackdriver.projects.get,完全满足查看告警事件的需求
  • 若需要编辑权限,可选择Monitoring Editor (roles/monitoring.editor),但Viewer角色更安全

2. 正确调用Policy Troubleshooter(命令行方式)

如果仍需用工具验证权限,可放弃UI,改用gcloud命令行:

gcloud policy-troubleshoot iam check-permissions \
  --project=[你的项目ID] \
  --principal=user:[同事邮箱] \
  --permissions=monitoring.incidents.get,stackdriver.projects.get

该命令会直接返回权限验证结果,以及缺失权限对应的角色建议。

3. 权限验证

分配角色后,可通过以下命令确认权限已生效:

gcloud projects get-iam-policy [你的项目ID] --filter="bindings.members:user:[同事邮箱]"

让同事重新访问告警事件页面,验证加载是否正常。

内容的提问来源于stack exchange,提问作者Kalle Richter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 06:09:50