An internal error occurred while calling service consumer manager for service account.
Creating App Engine application in projectPROJECT and REGION....failed. DEBUG: (gcloud.app.create) Error Response: [13] an internal error has occurred
请求日志
Service account creation is not allowed on this project.
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-20。"],[[["\u003cp\u003eThis page details common errors encountered during App Engine app initialization and serving, along with their troubleshooting methods.\u003c/p\u003e\n"],["\u003cp\u003eA permission error can occur when creating an App Engine app due to the organization policy constraint \u003ccode\u003econstraints/iam.disableServiceAccountCreation\u003c/code\u003e, which prevents the creation of the default service account.\u003c/p\u003e\n"],["\u003cp\u003eTo resolve the default service account creation error, temporarily remove the \u003ccode\u003econstraints/iam.disableServiceAccountCreation\u003c/code\u003e policy to allow for its provisioning, as it is required during app creation.\u003c/p\u003e\n"],["\u003cp\u003eWhen using legacy bundled services with Python 3 apps, a security error ("Attempted RPC call without active security ticket") may arise, particularly when accessing services like Memcache during startup.\u003c/p\u003e\n"],["\u003cp\u003eTo fix the security errors when using legacy bundled services, move the logic that causes the error to a warmup request.\u003c/p\u003e\n"]]],[],null,["# Troubleshoot serving issues in App Engine\n\n\u003cbr /\u003e\n\n\u003cbr /\u003e\n\n\nThis page describes common app initialization and serving errors in\nApp Engine and methods to troubleshoot them.\n\n### Permission error when creating an app with the default service account\n\nWhen you create an app after enabling the\nApp Engine API for the first time, it might fail with the following errors: \n\n### gcloud CLI\n\n An internal error occurred while calling service consumer manager for service account.\n Creating App Engine application in project\u003cvar translate=\"no\"\u003ePROJECT\u003c/var\u003e and \u003cvar translate=\"no\"\u003eREGION\u003c/var\u003e....failed. DEBUG: (gcloud.app.create) Error Response: [13] an internal error has occurred\n\n### Request logs\n\n Service account creation is not allowed on this project.\n\n### Console\n\n Error while initialising App Engine.\n\nThis error might occur due to the enforcement of the organization policy constraint [`constraints/iam.disableServiceAccountCreation`](/resource-manager/docs/organization-policy/restricting-service-accounts#disable_service_account_creation) when creating your\napp. This policy prevents the provisioning of the [App Engine default service account](/appengine/docs/standard/configure-service-accounts) `PROJECT_ID@appspot.gserviceaccount.com`.\n\nTo resolve this issue, you must temporarily remove the organization policy\nconstraint `constraints/iam.disableServiceAccountCreation` to allow for the\ncreation and deployment of the App Engine default service account. The default\nservice account is necessary for app creation and can't be skipped. This is also\napplicable when you use a per-version service account.\nThe App Engine default service account can be deleted or replaced\nwith a service account that you create after successful deployment.\n\nIf you are using a service account that you created, review the [Overview of role recommendations](/policy-intelligence/docs/role-recommendations-overview)\nto understand how to enforce restricting permissions, such as providing a\ntoken creator role on the service account you create for the service agent.\n\n### Security errors when using legacy bundled services for Python\n\nIf you use a legacy bundled services API when a Python 3 app is starting up,\nyou might see the following error message: \n\n Attempted RPC call without active security ticket\n\nThis error might occur in scenarios such as, reading certain values from\n[Memcache](/appengine/docs/standard/services/memcache) when your app is starting\nto configure a database connection or set a global variable.\n\nTo resolve this issue, you could try moving such logic into a\n[warmup request](/appengine/docs/standard/configuring-warmup-requests)."]]