GCP Deployment Manager未创建VPC对等连接问题求助
I’ve run into similar head-scratchers with Deployment Manager and VPC peering before—let’s break down the most likely causes and fixes to get your peering working:
1. Deployment Manager’s Service Account Lacks Required Permissions
When you create resources via Deployment Manager, it uses your project’s Cloud Services service account ([your-project-number]@cloudservices.gserviceaccount.com) instead of your personal account. Even if you can create the peering manually, this service account might be missing key permissions:
- On your test project: It needs the
compute.networks.addPeeringpermission (grant this via theroles/compute.networkPeeringAdminrole in IAM). - On the prod project: It needs the
compute.networks.getpermission (grant this via theroles/compute.networkViewerrole in the prod project’s IAM).
Double-check both projects’ IAM settings to confirm the service account has these roles.
2. Embedding Peerings in the Network Resource Can Cause Silent Failures
While adding peerings directly to the compute.v1.network resource is technically allowed, it’s often less reliable than using a dedicated peering resource. Try refactoring your template to create the peering as a separate object:
# First, create the base network - name: mytest-network type: compute.v1.network properties: name: mytest autoCreateSubnetworks: false # Then, create the peering as a standalone resource - name: mytest-to-prod-peering type: compute.v1.networkPeering properties: network: $(ref.mytest-network.selfLink) peerNetwork: projects/my-prod-project/global/networks/[YOUR_PROD_NETWORK_NAME] autoCreateRoutes: true # Set to false if you don't want automatic route creation
This ensures the network is fully provisioned before the peering is attempted, eliminating any potential race conditions.
3. Check for Hidden Errors in Deployment Logs
Even if the deployment shows as "successful", there might be silent warnings or failures buried in the logs. Use this command to pull detailed deployment information:
gcloud deployment-manager deployments describe [YOUR_DEPLOYMENT_NAME]
Or head to Cloud Logging, filter by Deployment Manager, and look for entries related to network peering—you might find clues about why the peering didn’t create.
4. Verify the Peer Network URL is Fully Correct
Make sure the network field in your peering config uses the complete, valid URL of the prod network:projects/my-prod-project/global/networks/[ACTUAL_PROD_NETWORK_NAME]
A truncated or incorrect URL (like the ... in your snippet) will cause the peering to fail without a visible error.
5. Check for Peering Restrictions on the Prod Network
If the prod network has a peering whitelist enabled, your test project needs to be added to it. You can verify this in the GCP Console under VPC Network > Peerings for the prod network.
内容的提问来源于stack exchange,提问作者xref

