DEBUG: Making request: GET http://metadata.google.internal/computeMetadata/v1/instance/service-accountsmetadata.google.internal:80
DEBUG: http://metadata.google.internal:80 "GET /computeMetadata/v1/instance/service-account
我创建了GSA和KSA,并执行了将两者关联起来的命令(gcloud iam service-accounts add-iam-policy-binding...)。如何检查绑定以确保调用成功?我本以为会有一个像gcloud iam service-accounts list-iam-policy-binding ...这样的命令来显示状态。
plugin failed with error: Failed to retrieve http://metadata.google.internal/computeMetadata/v1/instance/service-accountsplugin failed with error: Failed to retrieve http://metadata.google.internal/computeMetadata/v1/instance/s
*[master][~]$ gcloud iam service-accounts add-iam-policy-binding some-project --member="serviceAccountgcloud.iam.service-accounts.add-iam-policy-binding) NOT_FOUND: Unknown service account
*[master][~]$ gcloud iam service-accountsgcloud.iam.service-accounts.add-iam-policy-bin
我试图过滤附加在服务帐户上的IAM策略
gcloud iam service-accounts get-iam-policy foo@bar.iam.gserviceaccount.com --project对于SQL实例,我添加了一个带有集群名称的标签,但是对于命令gcloud iam service-accounts返回的策略,我们没有标签,所以我决定将集群添加到描述中,并通过description过滤集群名称
site-packages/google/auth/compute_engine/_metadata.py", line 208, in get_service_account_token 'instance/service-accountsgoogle.auth.exceptions.TransportError: ("Failed to retrieve http://metadata.google.internal/computeMetadata/v1