GCP Compute Engine SSH权限问题:无法通过sFTP及gcloud连接实例
Hey there, let’s work through this permission issue step by step—since both root and your regular account are hitting the same Insufficient Permission error when running gcloud compute ssh, this is almost definitely tied to Google Cloud IAM permissions or gcloud configuration, not local user settings on your VM.
First off, your Google Cloud account (the one linked to your gcloud CLI) needs specific permissions to SSH into GCE instances. Make sure your account has at least one of these roles assigned:
- Compute Instance Admin (v1): Full instance management access, including SSH
- Compute OS Login Admin: Required if your VM uses OS Login
- Compute Viewer + Compute SSH Admin: A more restricted combo that still allows SSH access
To verify and fix this:
- Log into the GCP Console, navigate to IAM & Admin > IAM
- Locate your account in the list and check its assigned roles
- If none of the above roles are present, click "Edit" and add one (start with Compute Instance Admin (v1) for testing)
If your VM has OS Login turned on, regular SSH keys won’t work unless your account is set up properly:
- Go to Compute Engine > VM Instances > [Your WordPress VM] > Edit
- Look for the "Enable OS Login" checkbox—if it’s checked:
- Ensure your account has the Compute OS Login role (add it via IAM if missing)
- Add your SSH public key to OS Login with this command:
gcloud compute os-login ssh-keys add --key-file=~/.ssh/id_rsa.pub
~/.ssh/id_rsa.pubwith the path to your actual public key file)
Sometimes cached auth credentials in gcloud get messed up. Resetting them often fixes permission glitches:
- Run this command to revoke all cached auth:
gcloud auth revoke --all - Then re-authenticate with your GCP account:
gcloud auth login - Make sure you log in with the same account you updated in IAM earlier
If OS Login isn’t enabled, your SSH public key needs to be in the VM’s metadata:
- Go to Compute Engine > VM Instances > [Your WordPress VM] > Edit
- Scroll to the "SSH keys" section and confirm your public key is listed (format:
ssh-rsa AAAAB3NzaC1yc2E... your-email@example.com) - If it’s missing, paste your public key here, save the changes, and wait 1-2 minutes before retrying SSH
Once gcloud compute ssh connects successfully, setting up FileZilla and fixing WordPress file permissions is straightforward:
FileZilla SFTP Setup
- Open FileZilla and create a new site:
- Protocol: SFTP - SSH File Transfer Protocol
- Host: Your VM’s external IP address
- Logon Type: Key file
- User:
- If using OS Login: Run
gcloud compute os-login describe-profileto get your assigned username - If not using OS Login: Use the default VM user (like
ubuntuor the user you created)
- If using OS Login: Run
- Key file: Select your private SSH key (e.g.,
~/.ssh/id_rsa)
Fix WordPress File Edit Permissions
To edit files via SFTP without permission errors:
- SSH into your VM and add your user to the
www-datagroup (WordPress files are usually owned by this group):sudo usermod -aG www-data your-username - Update the ownership and permissions of your WordPress directory (replace
/var/www/htmlwith your actual WordPress path if different):sudo chown -R www-data:www-data /var/www/html sudo chmod -R 755 /var/www/html
内容的提问来源于stack exchange,提问作者J Harry

