【问题标题】:Running Google App Engine Deployment to an other Project trough CloudBuild通过 Cloud Build 将 Google App Engine 部署运行到另一个项目
【发布时间】:2021-07-22 08:40:46
【问题描述】:

我在所有存储库和 CloudBuild 触发器所在的 Google Cloud 中有一个名为“RnD”(ID:1111111)的项目。 现在我想在“RnD”项目中运行 CloudBuild 触发器,然后部署到项目“X”中的 App Engine(ID:99999999)。我在项目“X”中为“RnD”项目中的 CloudBuild 服务帐户授予以下权限:

  • App 引擎管理员
  • 服务帐号用户
  • 项目浏览器

在 RnD 项目中,App Engine 处于活动状态并已配置。在 RnD 项目上没有,因为它没有在那里使用。

这是我的 cloudbuild.yaml 文件:

steps:
- name: 'gcr.io/google.com/cloudsdktool/cloud-sdk'
  dir: 'api'
  entrypoint: 'bash'
  args: ['-c', 'gcloud config set project ${_TARGET_PROJECT_NAME} && gcloud config set app/cloud_build_timeout 1600 && gcloud app deploy ']

timeout: '1600s'

_TARGET_PROJECT_NAME 是在触发器上配置的替换,值是项目“X”的名称。 运行构建会返回以下日志。

starting build "xxxxxxxxxx"

FETCHSOURCE
hint: Using 'master' as the name for the initial branch. This default branch name
hint: is subject to change. To configure the initial branch name to use in all
hint: of your new repositories, which will suppress this warning, call:
hint: 
hint:   git config --global init.defaultBranch <name>
hint: 
hint: Names commonly chosen instead of 'master' are 'main', 'trunk' and
hint: 'development'. The just-created branch can be renamed via this command:
hint: 
hint:   git branch -m <name>
Initialized empty Git repository in /workspace/.git/
From https://source.developers.google.com/p/rnd/r/my_reponame
 * branch            xxxxxxxxxxxx -> FETCH_HEAD
HEAD is now at xxxxxx
BUILD
Pulling image: gcr.io/google.com/cloudsdktool/cloud-sdk
Using default tag: latest
latest: Pulling from google.com/cloudsdktool/cloud-sdk
0bc3020d05f1: Already exists
a5178f1195d4: Pulling fs layer
... blah blah
cc6c9aaa8146: Pull complete
Digest: sha256:xxxxxxxxx
Status: Downloaded newer image for gcr.io/google.com/cloudsdktool/cloud-sdk:latest
gcr.io/google.com/cloudsdktool/cloud-sdk:latest
Updated property [core/project].
WARNING: You do not appear to have access to project [X] or it does not exist.
Updated property [app/cloud_build_timeout].
API [appengine.googleapis.com] not enabled on project [1111111]. 
Would you like to enable and retry (this will take a few minutes)? 
(y/N)?  
ERROR: (gcloud.app.deploy) User [1111111@cloudbuild.gserviceaccount.com] does not have permission to access apps instance [X] (or it may not exist): App Engine Admin API has not been used in project 1111111 before or it is disabled. Enable it by visiting https://console.developers.google.com/apis/api/appengine.googleapis.com/overview?project= 1111111 then retry. If you enabled this API recently, wait a few minutes for the action to propagate to our systems and retry.
- '@type': type.googleapis.com/google.rpc.Help
  links:
  - description: Google developers console API activation
    url: https://console.developers.google.com/apis/api/appengine.googleapis.com/overview?project= 1111111
- '@type': type.googleapis.com/google.rpc.ErrorInfo
  domain: googleapis.com
  metadata:
    consumer: projects/1111111
    service: appengine.googleapis.com
  reason: SERVICE_DISABLED
ERROR
ERROR: build step 0 "gcr.io/google.com/cloudsdktool/cloud-sdk" failed: step exited with non-zero status: 1

【问题讨论】:

    标签: google-app-engine google-cloud-platform continuous-integration continuous-deployment google-cloud-build


    【解决方案1】:

    看起来我也必须在 RnD 项目上激活“App Engine”。我越想越觉得有道理。

    除此之外,我还必须授予项目“X”中的 Cloud Build 服务帐户更多权限。我还没有弄清楚此服务帐户的最低权限集。如果我授予服务帐户项目所有者权利(我不应该知道;),它会起作用。

    【讨论】:

    • 当然,但我还要再等 2 天
    猜你喜欢
    • 1970-01-01
    • 2020-12-22
    • 1970-01-01
    • 1970-01-01
    • 2021-01-21
    • 1970-01-01
    • 2017-12-24
    • 1970-01-01
    • 2019-02-06
    相关资源
    最近更新 更多