You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修复通过OIDC从Bitbucket部署到GCP App Engine时的JWT受众不匹配错误

问题根因

报错The audience in JWT does not match the expected values的核心原因是:Bitbucket Pipelines生成的OIDC令牌中的aud(受众)字段取值,与GCP Workload Identity Federation身份提供程序配置的预期受众列表不匹配。


修复步骤

步骤1:获取Bitbucket侧的官方Audience取值

找到你在Bitbucket仓库配置OIDC时拿到的Audience值,Bitbucket默认的OIDC受众格式为ari:cloud:bitbucket::workspace/你的工作空间ID,如果自定义过就取你自定义的值,确保取值完全准确。

步骤2:更新GCP身份提供程序的受众配置(推荐方案)

  1. 打开GCP控制台,进入「工作负载身份联合」页面,找到你创建的对应Bitbucket的身份提供程序
  2. 进入编辑页,找到「受众配置」模块,将步骤1拿到的Bitbucket Audience值添加到允许的受众列表中,不要删除原来的//iam.googleapis.com/开头的原有受众,两个值同时保留即可

步骤3:快速验证的替代方案(修改clientLibraryConfig.json)

如果需要先快速验证逻辑是否通顺,可以直接修改你当前使用的clientLibraryConfig.json,新增服务账号模拟的受众配置,示例如下:

{
  "type": "external_account",
  "audience": "//iam.googleapis.com/projects/837282586571/locations/global/workloadIdentityPools/fakfake-com/providers/bitbucket-fakfake-com",
  "subject_token_type": "urn:ietf:params:oauth:token-type:jwt",
  "token_url": "https://sts.googleapis.com/v1/token",
  "service_account_impersonation_url": "https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/bitbucket@fakfake-com.iam.gserviceaccount.com:generateAccessToken",
  // 新增以下配置,audience值替换为步骤1拿到的Bitbucket官方Audience
  "service_account_impersonation_options": {
    "audience": "ari:cloud:bitbucket::workspace/你的实际工作空间ID"
  },
  "credential_source": {
    "file": "identity-token",
    "format": {
      "type": "text"
    }
  }
}

步骤4:流水线配置优化(可选)

你也可以不用单独将OIDC令牌写入本地文件,直接通过环境变量传递给gcloud命令生成凭证配置,修改后的bitbucket-pipelines.yml部署步骤参考:

- step:
  name: Deploy to Production
  image: google/cloud-sdk:latest
  oidc: true
  script:
    - gcloud iam workload-identity-pools create-cred-config \
      projects/837282586571/locations/global/workloadIdentityPools/fakfake-com/providers/bitbucket-fakfake-com \
      --service-account=bitbucket@fakfake-com.iam.gserviceaccount.com \
      --output-file=credential.json \
      --subject-token=$BITBUCKET_STEP_OIDC_TOKEN
    - gcloud auth login --cred-file=credential.json --update-adc
    - gcloud app deploy

修改完成后重新运行流水线,报错即可解决。

内容的提问来源于stack exchange,提问作者Null

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.25 10:54:01