简体   繁体   English

(GCP,Terraform)创建服务帐户时出错:googleapi:错误 403:需要权限 iam.serviceAccounts.create 才能执行此操作

[英](GCP, Terraform) Error creating service account: googleapi: Error 403: Permission iam.serviceAccounts.create is required to perform this operation on

On GCP , I'm trying to create a service account with this Terraform code below:GCP上,我正在尝试使用以下Terraform代码创建一个服务帐户

provider "google" {
  credentials = file("myCredentials.json")
  project     = "myproject-173831"
  region      = "asia-northeast1"
}

resource "google_service_account" "service_account" {
  display_name = "My Service Account"
  account_id   = "my-service-account"
}

But I got this error:但我得到了这个错误:

Error creating service account: googleapi: Error 403: Permission iam.serviceAccounts.create is required to perform this operation on project projects/myproject-173831., forbidden创建服务帐户时出错:googleapi:错误 403:需要权限 iam.serviceAccounts.create 才能对项目 projects/myproject-173831 执行此操作。,禁止

So now, I'm trying to add a role to solve this error above but there are too many roles to choose:所以现在,我正在尝试添加一个角色来解决上面的这个错误,但是有太多角色可供选择:

在此处输入图像描述

What role do I need to choose?我需要选择什么角色?

You need to choose the role "Create Service Accounts" to create service accounts:您需要选择角色“创建服务帐户”来创建服务帐户:

在此处输入图像描述

In addition, you can choose the role "Delete Service Accounts" to delete service accounts:此外,您可以选择角色“删除服务帐户”来删除服务帐户:

在此处输入图像描述

Otherwise, you cannot delete service accounts then you will get this error below:否则,您无法删除服务帐户,然后您将在下面收到此错误:

Error 403: Permission iam.serviceAccounts.delete is required to perform this operation on service account projects/myproject-173831/serviceAccounts/my-service-account@myproject-173831.iam.gserviceaccount.com., forbidden错误 403:需要权限 iam.serviceAccounts.delete 才能对服务帐户 projects/myproject-173831/serviceAccounts/my-service-account@myproject-173831.iam.gserviceaccount.com. 执行此操作,禁止

Finally, if you want to create and delete service accounts with one role, you can choose the more abstract role "Service Account Admin" :最后,如果你想创建和删除一个角色的服务账户,你可以选择更抽象的角色“服务账户管理员”

在此处输入图像描述

暂无
暂无

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

相关问题 (Terraform,GCP)错误 403:需要权限 iam.serviceAccounts.setIamPolicy 才能对服务帐户项目/myproject-17 执行此操作 - (Terraform, GCP) Error 403: Permission iam.serviceAccounts.setIamPolicy is required to perform this operation on service account projects/myproject-17 "403:对项目projects\/xyz执行此操作需要权限iam.serviceAccounts.create" - 403: Permission iam.serviceAccounts.create is required to perform this operation on project projects/xyz Terraform 抛出为服务帐户设置 IAM 策略时出错...需要权限 iam.serviceAccounts.setIamPolicy - Terraform throws Error setting IAM policy for service account ... Permission iam.serviceAccounts.setIamPolicy is required 需要 iam.serviceAccounts.getIamPolicy 才能对服务帐户执行此操作 - iam.serviceAccounts.getIamPolicy is required to perform this operation on service account 创建作业时出错:googleapi:错误 403:缺少 IAM 权限 - Error creating Job: googleapi: Error 403: lacks IAM permission (GCP)创建 GlobalAddress 时出错:googleapi:错误 403:必需 > 'compute.globalAddresses.create' 权限 > 'projects/myproject-638932/ - (GCP) Error creating GlobalAddress: googleapi: Error 403: Required > 'compute.globalAddresses.create' permission for > 'projects/myproject-638932/ (Terraform,Cloud Run)创建服务时出错:googleapi:错误 403:资源 'namespaces/myproject-173831/ 上的权限 'run.services.create' 被拒绝 - (Terraform, Cloud Run) Error creating Service: googleapi: Error 403: Permission 'run.services.create' denied on resource 'namespaces/myproject-173831/ Terraform:“创建防火墙时出错:googleapi:错误 403:需要‘compute.firewalls.create’” - Terraform: “ Error creating Firewall: googleapi: Error 403: Required 'compute.firewalls.create' ” 创建 RegionNetworkEndpointGroup 时出错:googleapi:错误 403:“projects/myproj”需要“compute.regionNetworkEndpointGroups.create”权限 - Error creating RegionNetworkEndpointGroup: googleapi: Error 403: Required 'compute.regionNetworkEndpointGroups.create' permission for 'projects/myproj 创建网络时出错:googleapi:错误 403:资源项目 myProject 的权限被拒绝。 详细信息:[],禁止(Terraform) - Error creating Network: googleapi: Error 403: Permission denied on resource project myProject. Details:[], forbidden (Terraform)
 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM