You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Logging Router Sink更新调用sink.reload()出现403权限错误

GCP Logging Router Sink更新403报错解决方案

问题背景

调用sink.reload()更新GCP Logging Router Sink时触发403权限报错,提示“The caller does not have permission”,对应代码如下:

def update_sink(creds, sink_name, filter_):
    logging_client = logging.Client(credentials=creds)

    sink = logging_client.sink(sink_name)
    sink.reload()

    sink.filter_ = filter_
    print("Updated sink {}".format(sink.name))

    response = sink.update()

    return response

if __name__ == "__main__":
    # Scope
    # "https://www.googleapis.com/auth/cloud-platform",
    # "https://www.googleapis.com/auth/cloud-platform.read-only",
    # "https://www.googleapis.com/auth/cloudplatformprojects",
    # "https://www.googleapis.com/auth/cloudplatformprojects.readonly",
    # "https://www.googleapis.com/auth/compute",
    # "https://www.googleapis.com/auth/cloudkms",
    # "https://www.googleapis.com/auth/pubsub",
    # "https://www.googleapis.com/auth/logging.read",
    # "https://www.googleapis.com/auth/logging.write",
    # "https://www.googleapis.com/auth/logging.admin"
    creds = {} # OAuth Credentials with above scope
    sink_name = "<sink path with project>"
    filter_ = "<filter>"
    
    response = update_sink(creds, sink_name, filter_)
    
    print(response)

解决方案

  • IAM角色权限检查:操作账号(用户账号/服务账号)需要在Sink所属的资源层级(项目/组织/文件夹)持有roles/logging.configWriter(最小权限)或roles/logging.admin(完整Sink操作权限),仅持有roles/logging.viewer等只读角色无法完成Sink更新操作。
  • OAuth作用域配置检查:生成凭证时必须指定https://www.googleapis.com/auth/logging.admin或https://www.googleapis.com/auth/cloud-platform作用域,仅配置logging.read、logging.write等作用域会触发权限拦截。
  • Sink资源路径检查:sink_name必须填写完整的资源路径,项目级Sink格式为projects/[项目ID]/sinks/[Sink名称],组织级Sink格式为organizations/[组织ID]/sinks/[Sink名称],路径错误会触发GCP的安全拦截返回403。
  • 凭证有效性检查:确认传入的creds凭证未过期、归属项目和Sink所属项目一致,可通过gcloud命令本地验证权限:
    # 生成当前账号的access token
    gcloud auth print-access-token
    # 调用API测试Sink访问权限,替换[]内的内容为实际参数
    curl -H "Authorization: Bearer 替换为你的token" https://logging.googleapis.com/v2/替换为Sink完整资源路径
    

内容的提问来源于stack exchange,提问作者Purusottam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 22:30:03