You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API Gateway配置调用Google Cloud Workflows及相关问题处理

问题解答

1. Workflows API是否强制要求使用OAuth?是否有替代方案?

Google Cloud Workflows 执行API强制要求使用OAuth 2.0身份验证,不支持单独使用API密钥完成身份校验。你之前调用Cloud Functions可以仅传API密钥,是因为Cloud Functions开放了API密钥作为合法身份凭证的支持,但Workflows属于Google Cloud标准托管API,API密钥仅可用于项目配额统计,无法替代OAuth完成身份验证,这也是你当前返回401错误的核心原因:日志显示API密钥已验证通过,但上游Workflows API拒绝了无有效OAuth令牌的请求。

可用的替代方案有两种:

  • 保留现有API Gateway→Cloud Function的调用逻辑,在Cloud Function中使用服务账号身份调用Workflows,无需调整前端调用方式
  • 直接在API Gateway中配置后端身份验证,由API Gateway自动向Workflows API附加OAuth令牌,无需额外中间层

2. 如何在API Gateway配置中指定Workflow的调用参数?

首先你需要先给API Gateway的运行服务账号授予目标Workflows资源的roles/workflows.invoker权限,之后修改你的openapi2-functions.yaml配置即可:

配置后端自动附加OAuth令牌

在x-google-backend下添加authentication字段,让API Gateway自动生成符合Workflows要求的OAuth令牌:

x-google-backend:
  address: https://workflowexecutions.googleapis.com/v1/projects/us-central1-quick-hangout-329722/locations/us-central1/workflows/create-site-and-project/executions
  path_translation: APPEND_PATH_TO_ADDRESS
  authentication:
    jwt_audience: https://workflowexecutions.googleapis.com

配置Workflows调用参数

  • 如果你需要将前端请求的Body直接作为Workflows的输入参数,无需额外配置,API Gateway会自动转发请求Body,Workflows会默认读取Body中argument字段的内容作为工作流输入
  • 如果你需要在API Gateway侧添加固定参数或做参数映射,可以添加request_parameters配置,示例如下:
x-google-backend:
  address: <你的Workflows执行地址>
  request_parameters:
    # 给Workflows输入添加固定参数
    body.argument.env: "production"
    # 把请求头中的参数映射到Workflows输入
    body.argument.user_id: "$request.header.x-user-id"

修改完成后重新部署API网关即可解决当前401错误。


内容的提问来源于stack exchange,提问作者PaulyP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 20:15:05