You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Deployment Manager创建GCS Bucket时遇403 Forbidden错误求助

Deployment Manager GCS Bucket 403 Permission Issue: Answers to Your Questions

Hey there, let's break down your questions and get your Deployment Manager setup working smoothly.

1. Why is 205531008256@cloudservices.gserviceaccount.com being used?

That service account is Google's managed default service account for Deployment Manager. When you create a deployment without specifying a custom service account, Deployment Manager automatically uses this Google-owned account to handle all resource operations—like checking if your GCS bucket exists before creating it. It’s not a service account you manage directly in your project; any IAM roles you assign to it apply across Google’s infrastructure for your Deployment Manager workflows.

2. How to fix the 403 error and successfully create the GCS Bucket?

The error mentions a storage.buckets.get permission issue, even with broad roles like Project Owner or Storage Admin assigned. Here are the most effective fixes to try:

First: Confirm your bucket name is truly globally unique

GCS bucket names are globally unique across all Google Cloud projects. If the name <unique-bucket-name> you’re using already exists in someone else’s project (even one you don’t own), your service account will get a 403 when trying to check its existence (since it has no access to another project’s bucket).

Try swapping in a new, unique name (e.g., <your-project-id>-upload-bucket-2024) and re-run the deployment. This is the most common fix for this exact error.

Second: Verify permissions and API status

  • Wait for permission propagation: IAM role assignments can take 1-2 minutes to fully apply. Give it a few minutes after adding roles, then retry the deployment.
  • Check role bindings: Use this gcloud command to confirm the service account has the roles you assigned:
    gcloud projects get-iam-policy <your-project-id> --filter="bindings.members:serviceAccount:205531008256@cloudservices.gserviceaccount.com"
    
    You should see roles like roles/editor, roles/storage.admin, or roles/owner listed in the output.
  • Enable required APIs: Make sure both Deployment Manager and Cloud Storage APIs are enabled in your project:
    gcloud services enable deploymentmanager.googleapis.com storage.googleapis.com
    

Third: Use a custom service account (if the default still fails)

If the managed service account continues to have issues, create a custom service account in your project and use it for the deployment:

  1. Create the service account:
    gcloud iam service-accounts create dm-custom-sa --display-name "Deployment Manager Custom SA"
    
  2. Assign it necessary roles:
    gcloud projects add-iam-policy-binding <your-project-id> \
      --member="serviceAccount:dm-custom-sa@<your-project-id>.iam.gserviceaccount.com" \
      --role="roles/storage.admin"
    gcloud projects add-iam-policy-binding <your-project-id> \
      --member="serviceAccount:dm-custom-sa@<your-project-id>.iam.gserviceaccount.com" \
      --role="roles/deploymentmanager.editor"
    
  3. Deploy using this custom service account:
    gcloud deployment-manager deployments create the-bucket --config your-config.yaml --service-account dm-custom-sa@<your-project-id>.iam.gserviceaccount.com
    

内容的提问来源于stack exchange,提问作者tomphp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:45:23