【问题标题】:Starting virtual machine on gcp compute engine with web-uri使用 web-uri 在 gcp 计算引擎上启动虚拟机
【发布时间】:2019-11-20 20:36:05
【问题描述】:

我在 CE 上设置了一个虚拟机。我想通过 API 使用带有 HTTP 请求的 instances().stop 和 instances().start 方法来启动和关闭这个 VM。

使用 API 资源管理器 (https://cloud.google.com/compute/docs/reference/rest/v1/instances/start) 并输入项目名称、区域和实例名称,一切正常,我可以启动和停止 VM。我被转发到谷歌登录 -> 我授权 -> 它有效。

但是,当我尝试通过浏览器中提供的 html 执行此操作时:https://www.googleapis.com/compute/v1/projects/{my_projekt}/zones/{my_zone}/instances/{my_instance}/start",它不起作用。错误:不是找到了。我认为缺少某种自动化,所以我也尝试添加 ?key={my_key}。

在文档中我发现: 需要以下 OAuth 范围之一: https://www.googleapis.com/auth/compute https://www.googleapis.com/auth/cloud-platform

但我不知道如何设置。有人可以帮我吗?有没有可能我正在尝试做的事情?

在下一步中,我希望通过授予其他人 IAM 角色来允许其他人启动和停止此 vm。他们也可以使用 http post 请求吗?

我是 GCP 的新手,自动化过程让我头疼……

提前致谢。 你好, 奥利

【问题讨论】:

    标签: google-cloud-platform virtual-machine google-compute-engine api-key


    【解决方案1】:

    好的,你有 3 种方法来实现这一点,它们在 here 中有很好的记录,我会从最简单到最难的顺序列出它们:

    A.- 谷歌云控制台。

    B.- 谷歌云 SDK CLI 工具“gcloud”。

    C.- 谷歌云 HTTP API 调用。

    帐户执行实例停止/启动所需的权限为:

    compute.instances.stop
    compute.instances.start
    

    重置:

    compute.instances.reset
    

    具有这些权限的角色是“compute.instanceAdmin”,但您始终可以创建具有所需权限的客户角色。


    A.- 谷歌云控制台

    这是最用户友好的方式,因为它使用 GUI。转到 Cloud Console,在您的 Compute Engine Instances 上。如果您没有在列表中看到您的实例,请确保您选择了正确的项目。

    单击您要停止/启动的实例,然后根据您要执行的操作单击上面的按钮。


    B.- 谷歌云 SDK CLI 工具“gcloud”

    Install CLI 工具“gcloud”,authenticate 使用:

    gcloud auth login [ACCOUNT] 
    

    然后你就可以使用Stop/Start/Reset实例的命令了

    gcloud compute instances stop example-instance-1 example-instance-2
    
    gcloud compute instances start example-instance
    
    gcloud compute instances reset example-instance
    

    C.- 谷歌云 HTTP API 调用

    这是您当前尝试使用的方法,您必须向 Google Cloud API 发出 HTTP 请求:Start、Stop、Reset。

    您需要将“访问令牌”添加到请求标头的“身份验证”字段中。使用“授权:不记名在这里-你的长令牌”。有关它的更多信息here。

    如何获取“访问令牌”可能因您使用的语言而异,以下是 javascript 中的示例:

    var {google} = require("googleapis");
    
    // Load the service account key JSON file.
    var serviceAccount = require("path/to/serviceAccountKey.json");
    
    // Define the required scopes.
    var scopes = [
      "https://www.googleapis.com/auth/cloud-platform",
      "https://www.googleapis.com/auth/compute"
    ];
    
    // Authenticate a JWT client with the service account.
    var jwtClient = new google.auth.JWT(
      serviceAccount.client_email,
      null,
      serviceAccount.private_key,
      scopes
    );
    
    // Use the JWT client to generate an access token.
    jwtClient.authorize(function(error, tokens) {
      if (error) {
        console.log("Error making request to generate access token:", error);
      } else if (tokens.access_token === null) {
        console.log("Provided service account does not have permission to generate access tokens");
      } else {
        var accessToken = tokens.access_token;
        // here you have the token, you can use it on your API request.
      }
    });
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-12-10
      • 2018-07-30
      • 1970-01-01
      • 2020-09-27
      • 1970-01-01
      相关资源
      最近更新 更多