通过Deployment Manager创建App Engine遇内部错误及API权限问题求助
Let’s tackle your two main issues—Deployment Manager’s 500 internal error and the 403 permission denied error when calling the apps.services.versions.create API—one by one.
1. Fixing the Deployment Manager 500 Internal Error
The 500 error often stems from invalid request formatting or missing prerequisites in your configuration. Here’s what to check:
a. Remove the unnecessary filesCount field
Looking at your create-app-engine-std.py code, you’re including a filesCount parameter in the deployment.zip object. The App Engine Admin API does not accept this field for version creation requests. Including invalid parameters can trigger unexpected internal errors.
Update your deployment logic to remove this field:
def GenerateConfig(cxt): deployment = {} if cxt.properties.get('zip'): deployment = { 'zip': { 'sourceUrl': cxt.properties['zip']['sourceUrl'] # Remove filesCount here—it's not a valid API parameter } } # ... rest of your code
b. Ensure the target service exists before creating a version
App Engine versions are tied to a specific service, and you can’t create a version for a service that doesn’t exist. Your current code hardcodes servicesId: 'app-engine-std-test-app', but if this service hasn’t been created yet, the API call will fail.
Add a dependency to create the service first in your Deployment Manager config:
def GenerateConfig(cxt): deployment = {} if cxt.properties.get('zip'): deployment = { 'zip': { 'sourceUrl': cxt.properties['zip']['sourceUrl'] } } # First, create the target service if it doesn't exist resources = [{ 'type': 'gcp-types/appengine-v1:apps.services', 'name': 'app-engine-std-test-service', 'properties': { 'appsId': cxt.properties['appsId'], 'id': 'app-engine-std-test-app' # Matches your servicesId } }, { 'type': 'gcp-types/appengine-v1:apps.services.versions', 'name': 'app-engine-std-app', 'properties': { 'servicesId': 'app-engine-std-test-app', 'appsId': cxt.properties['appsId'], 'deployment': deployment, 'runtime': cxt.properties['runtime'], 'threadsafe': True, 'id': cxt.properties['version'] }, # Ensure the service is created before the version 'metadata': { 'dependsOn': ['app-engine-std-test-service'] } }] return {'resources': resources}
c. Replace the placeholder appsId in your YAML
Your deployment-manager.yaml uses appsId: projectId—this is a literal string, not your actual GCP project ID. Replace it with your real project ID:
imports: - path: create-app-engine-std.py resources: - name: create-app-engine-std-app type: create-app-engine-std.py properties: name: app-engine-std-app appsId: your-real-gcp-project-id # Update this! zip: sourceUrl: https://storage.googleapis.com/some-bucket/xyz.zip version: v1 runtime: nodejs8
2. Resolving the 403 Permission Denied Error
Even as a project owner, you might hit this error due to missing API enablement or restricted permissions. Here’s how to fix it:
a. Enable the App Engine Admin API
First, confirm the App Engine Admin API is enabled for your project:
- Go to the GCP Console → APIs & Services → Library
- Search for "App Engine Admin API"
- If it’s not enabled, click "Enable"
Without this API enabled, even owner accounts can’t make version creation requests.
b. Verify your service account permissions
If you’re using Deployment Manager’s default service account, it needs the right permissions to deploy to App Engine:
- Find your Deployment Manager service account: it follows the format
[PROJECT_NUMBER]@cloudservices.gserviceaccount.com(you can get your project number from the GCP Console’s project settings). - Go to IAM & Admin → IAM in the GCP Console
- Find the service account, click "Edit" → "Add another role"
- Assign the App Engine Deployer role (or Owner for full access, though Deployer is more restrictive and secure)
If you’re manually calling the API with your own user account:
- Double-check that you’re actually listed as an Owner in the project’s IAM settings
- Ensure there are no organizational policies blocking your access (e.g., a policy restricting App Engine deployments to specific accounts)
c. Check for organizational policy restrictions
If your project belongs to an organization, some policies might limit App Engine operations:
- Go to IAM & Admin → Organizational Policies
- Look for policies like
constraints/appengine.disableCodeDeploymentsorconstraints/compute.trustedImageProjectsthat might block your deployment - If such policies exist, work with your organization’s admin to adjust them if needed
内容的提问来源于stack exchange,提问作者niklodeon

