(僅適用於 UDCA 和 Synchronizer) 如果專案的權限檢查失敗,驗證程序會繼續檢查 Apigee 環境的 IAM 政策權限。這些 SA 屬於環境層級,而環境支援更精細的權限。
如要更新特定環境的身分與存取權管理政策,請前往混合式 UI。依序前往「管理」>「環境」>「存取」
舉例來說,以下是權限檢查失敗的錯誤訊息:
Invalid Metrics Service Account. Service Account
"apigee-metrics@hybrid-project.iam.gserviceaccount.com" is missing 1 or more required
permissions [monitoring.metricDescriptors.create monitoring.metricDescriptors.get monitoring.metricDescriptors.list
monitoring.monitoredResourceDescriptors.get monitoring.monitoredResourceDescriptors.list monitoring.timeSeries.create].
Visit Service accounts and roles used by
hybrid components for more details on setting up Apigee hybrid service account permissions.
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-07-10 (世界標準時間)。"],[[["This documentation is for Apigee hybrid version 1.3, which is end-of-life, and users should upgrade to a newer version."],["Apigee hybrid includes a service account validation feature enabled by default, that ensures correct key locations and proper permissions in the GCP project."],["To enable validation of the service account's permissions, the Cloud Resource Manager API must be enabled in the GCP project, and the `validateServiceAccounts` property must be set to `true` in the overrides file."],["Service account JSON key format validation is always performed and cannot be disabled, while permission validation can be turned off by setting `validateServiceAccounts` to `false`."],["Service account permission validation checks permissions first on the project ID and, if that fails, proceeds to check permissions against the Apigee environment's IAM policy for UDCA and Synchronizer components."]]],[]]