GCP Logging Router Sink更新调用sink.reload()出现403权限错误
GCP Logging Router Sink更新403报错解决方案
问题背景
调用sink.reload()更新GCP Logging Router Sink时触发403权限报错,提示“The caller does not have permission”,对应代码如下:
def update_sink(creds, sink_name, filter_): logging_client = logging.Client(credentials=creds) sink = logging_client.sink(sink_name) sink.reload() sink.filter_ = filter_ print("Updated sink {}".format(sink.name)) response = sink.update() return response if __name__ == "__main__": # Scope # "https://www.googleapis.com/auth/cloud-platform", # "https://www.googleapis.com/auth/cloud-platform.read-only", # "https://www.googleapis.com/auth/cloudplatformprojects", # "https://www.googleapis.com/auth/cloudplatformprojects.readonly", # "https://www.googleapis.com/auth/compute", # "https://www.googleapis.com/auth/cloudkms", # "https://www.googleapis.com/auth/pubsub", # "https://www.googleapis.com/auth/logging.read", # "https://www.googleapis.com/auth/logging.write", # "https://www.googleapis.com/auth/logging.admin" creds = {} # OAuth Credentials with above scope sink_name = "<sink path with project>" filter_ = "<filter>" response = update_sink(creds, sink_name, filter_) print(response)
解决方案
- IAM角色权限检查:操作账号(用户账号/服务账号)需要在Sink所属的资源层级(项目/组织/文件夹)持有
roles/logging.configWriter(最小权限)或roles/logging.admin(完整Sink操作权限),仅持有roles/logging.viewer等只读角色无法完成Sink更新操作。 - OAuth作用域配置检查:生成凭证时必须指定
https://www.googleapis.com/auth/logging.admin或https://www.googleapis.com/auth/cloud-platform作用域,仅配置logging.read、logging.write等作用域会触发权限拦截。 - Sink资源路径检查:
sink_name必须填写完整的资源路径,项目级Sink格式为projects/[项目ID]/sinks/[Sink名称],组织级Sink格式为organizations/[组织ID]/sinks/[Sink名称],路径错误会触发GCP的安全拦截返回403。 - 凭证有效性检查:确认传入的
creds凭证未过期、归属项目和Sink所属项目一致,可通过gcloud命令本地验证权限:# 生成当前账号的access token gcloud auth print-access-token # 调用API测试Sink访问权限,替换[]内的内容为实际参数 curl -H "Authorization: Bearer 替换为你的token" https://logging.googleapis.com/v2/替换为Sink完整资源路径
内容的提问来源于stack exchange,提问作者Purusottam
相关产品推荐
相关产品推荐

