agent-substrate / agent-substrate/env

Actor deletion stuck due to lacking permissions

Đang mở
#64 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Go
Star
2
Fork
2
Merge trung bình
21 giờ 1 phút
Pull request đã merge (30 ngày)
28

Mô tả

Deleting an actor fails when `ate-api-server` attempts to clean up snapshots from GCS:

```
rpc error: code = PermissionDenied desc = Caller does not have storage.objects.list access to the Google Cloud Storage bucket. Permission 'storage.objects.list' denied on resource '//storage.googleapis.com/projects/_/buckets/'
```

Because snapshot cleanup fails, the actor remains permanently stuck in `ACTOR_STATE_DELETING`.

#### **Cause**
On GKE, default node service accounts only have `read_only` storage scopes. The `ate-system/ate-api-server` Kubernetes service account is not bound to a Google Service Account (GSA) via Workload Identity, leaving it without permissions to list or delete objects in the snapshots bucket.

#### **Suggestions**
1. **Document Workload Identity setup:** Specify that `ate-api-server` requires `roles/storage.objectAdmin` on the snapshot bucket via Workload Identity (`ate-system/ate-api-server`).
2. **Handle cleanup failures gracefully:** Allow actor deletion to complete (or report a warning) instead of trapping the actor in `ACTOR_STATE_DELETING` forever when bucket cleanup errors occur.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.