agent-substrate / agent-substrate/env
Actor deletion stuck due to lacking permissions
- Ngôn ngữ chính
- Go
- Star
- 2
- Fork
- 2
- Merge trung bình
- 21 giờ 1 phút
- Pull request đã merge (30 ngày)
- 28
Mô tả
Deleting an actor fails when `ate-api-server` attempts to clean up snapshots from GCS:
```
rpc error: code = PermissionDenied desc = Caller does not have storage.objects.list access to the Google Cloud Storage bucket. Permission 'storage.objects.list' denied on resource '//storage.googleapis.com/projects/_/buckets/'
```
Because snapshot cleanup fails, the actor remains permanently stuck in `ACTOR_STATE_DELETING`.
#### **Cause**
On GKE, default node service accounts only have `read_only` storage scopes. The `ate-system/ate-api-server` Kubernetes service account is not bound to a Google Service Account (GSA) via Workload Identity, leaving it without permissions to list or delete objects in the snapshots bucket.
#### **Suggestions**
1. **Document Workload Identity setup:** Specify that `ate-api-server` requires `roles/storage.objectAdmin` on the snapshot bucket via Workload Identity (`ate-system/ate-api-server`).
2. **Handle cleanup failures gracefully:** Allow actor deletion to complete (or report a warning) instead of trapping the actor in `ACTOR_STATE_DELETING` forever when bucket cleanup errors occur.
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.