[英]Permission error in GCP when creating a new compute instance but service account does have permissions
I am running a cloudbuild.yaml
job in Google Cloud Platform that builds, pushes and tags a Docker Image and then it creates a Compute Engine instance to run that image via gcr.io/cloud-builders/gcloud.create-with-container
.我在 Google Cloud Platform 中运行
cloudbuild.yaml
作业,它构建、推送和标记 Docker 映像,然后它创建一个 Compute Engine 实例以通过gcr.io/cloud-builders/gcloud.create-with-container
运行该映像。 I also specify a service account to be used in this step:我还指定了要在此步骤中使用的服务帐户:
- id: "Create Compute Engine instance"
name: gcr.io/cloud-builders/gcloud
args: [
'compute',
'instances',
'create-with-container',
'${INSTANCE_NAME}',
'--container-image',
'eu.gcr.io/${PROJECT_ID}/${PROJECT_ID}-${REPO_NAME}',
'--zone',
'${ZONE}',
'--service-account',
'${SERVICE_ACCOUNT},
'--machine-type',
'n2-standard-4'
]
However I am getting an error:但是我收到一个错误:
Already have image (with digest): gcr.io/cloud-builders/gcloud
ERROR: (gcloud.compute.instances.create-with-container) Could not fetch resource:
- Required 'compute.instances.create' permission for 'projects/...'
The service account in use does have the permissions for that as it has been assigned "role": "roles/compute.instanceAdmin.v1"
, which includes compute.instances.*
as per documentation .正在使用的服务帐户确实具有权限,因为它已被分配
"role": "roles/compute.instanceAdmin.v1"
,其中包括根据文档计算compute.instances.*
。
Anyone has experienced this or a similar situation and can give a hint on how to proceed?任何人都经历过这种或类似的情况,并且可以提示如何进行? Am I missing something obvious?
我错过了一些明显的东西吗? I have tried using other service accounts, including the project default compute account and get the same error.
我尝试使用其他服务帐户,包括项目默认计算帐户并得到相同的错误。 One thing to note is I do not specify a service account for Docker steps (gcr.io/cloud-builders/docker).
需要注意的一点是,我没有为 Docker 步骤 (gcr.io/cloud-builders/docker) 指定服务帐户。
Make sure that you are not misinterpreting service accounts.确保您没有误解服务帐户。 There is a special service account used by Cloud Build.
Cloud Build 使用了一个特殊的服务帐号。 There is also the service account to "be used" by the VM/instance you are creating.
您正在创建的虚拟机/实例还可以“使用”服务帐户。
The "compute.instances.create" permission should be granted to the special Cloud Build account, not to the account for the instance. “compute.instances.create”权限应授予特殊 Cloud Build 帐户,而不是实例帐户。
The Cloud Build account has a name like 123123123@cloudbuild.gserviceaccount.com. Cloud Build 帐户的名称类似于 123123123@cloudbuild.gserviceaccount.com。
In the Cloud Console go to Cloud Build -> Settings -> Service Accounts and check if correct permissions are granted.在 Cloud Console 中,转到 Cloud Build -> Settings -> Service Accounts 并检查是否授予了正确的权限。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.