You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Deployment Manager未创建VPC对等连接问题求助

Troubleshooting VPC Peering Not Creating in GCP Deployment Manager

I’ve run into similar head-scratchers with Deployment Manager and VPC peering before—let’s break down the most likely causes and fixes to get your peering working:

1. Deployment Manager’s Service Account Lacks Required Permissions

When you create resources via Deployment Manager, it uses your project’s Cloud Services service account ([your-project-number]@cloudservices.gserviceaccount.com) instead of your personal account. Even if you can create the peering manually, this service account might be missing key permissions:

  • On your test project: It needs the compute.networks.addPeering permission (grant this via the roles/compute.networkPeeringAdmin role in IAM).
  • On the prod project: It needs the compute.networks.get permission (grant this via the roles/compute.networkViewer role in the prod project’s IAM).

Double-check both projects’ IAM settings to confirm the service account has these roles.

2. Embedding Peerings in the Network Resource Can Cause Silent Failures

While adding peerings directly to the compute.v1.network resource is technically allowed, it’s often less reliable than using a dedicated peering resource. Try refactoring your template to create the peering as a separate object:

# First, create the base network
- name: mytest-network
  type: compute.v1.network
  properties:
    name: mytest
    autoCreateSubnetworks: false

# Then, create the peering as a standalone resource
- name: mytest-to-prod-peering
  type: compute.v1.networkPeering
  properties:
    network: $(ref.mytest-network.selfLink)
    peerNetwork: projects/my-prod-project/global/networks/[YOUR_PROD_NETWORK_NAME]
    autoCreateRoutes: true # Set to false if you don't want automatic route creation

This ensures the network is fully provisioned before the peering is attempted, eliminating any potential race conditions.

3. Check for Hidden Errors in Deployment Logs

Even if the deployment shows as "successful", there might be silent warnings or failures buried in the logs. Use this command to pull detailed deployment information:

gcloud deployment-manager deployments describe [YOUR_DEPLOYMENT_NAME]

Or head to Cloud Logging, filter by Deployment Manager, and look for entries related to network peering—you might find clues about why the peering didn’t create.

4. Verify the Peer Network URL is Fully Correct

Make sure the network field in your peering config uses the complete, valid URL of the prod network:
projects/my-prod-project/global/networks/[ACTUAL_PROD_NETWORK_NAME]
A truncated or incorrect URL (like the ... in your snippet) will cause the peering to fail without a visible error.

5. Check for Peering Restrictions on the Prod Network

If the prod network has a peering whitelist enabled, your test project needs to be added to it. You can verify this in the GCP Console under VPC Network > Peerings for the prod network.

内容的提问来源于stack exchange,提问作者xref

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:55:59