Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Stackdriver API: 403 Forbidden #48

Closed
bryan831 opened this issue Apr 30, 2019 · 4 comments
Closed

Stackdriver API: 403 Forbidden #48

bryan831 opened this issue Apr 30, 2019 · 4 comments
Labels

Comments

@bryan831
Copy link

I followed the tutorial steps in the README, and enabled the audit to Stackdriver (vault audit enable file file_path=stdout).
I also read the issue (#17) and checked that the Vault service account has access to write logs.

In Stackdriver logging, under Kubernetes Container logs, I see many lines that read
"message: "Failed to publish resource metadata: Unexpected response code from Stackdriver API: 403 Forbidden"

How can I resolve this?

@u2g-tg
Copy link

u2g-tg commented Apr 30, 2019

Hey, I'm just a newbie to TF and this project, but did you check Stackdriver API is enabled for your project?

You might need to add "stackdriver.googleapis.com" to the services list of the tf project resource.

Edit: there's a 'project_services' list var in terraform/variables.tf

@bryan831
Copy link
Author

in variables.tf there is already logging.googleapis.com in project_services list variable.
After i added stackdriver.googleapis.com, and did terraform apply again, I still see those error logs in Stackdriver logs

@davidebelloni
Copy link

Hi,
I've the same problem here with a GKE 1.12.7-gke.10 with a custom svc account (not compute engine default but with monitoring.metricWriter and monitoring.viewer roles assigned) and Stackdriver API enabled

All the request to google.cloud.stackdriver.v1beta3.ResourceService.PublishResourceMetadata return 403

Is there a solution?

@sethvargo
Copy link
Owner

Seems like a duplicate of Stackdriver/kubernetes-configs#25, which is a core platform issue. Sorry this is happening, but there’s nothing we can do in this repo to fix it. Please follow the link above and subscribe to that issue for updates. Thanks!

@sethvargo sethvargo added the bug label May 6, 2019
@lock lock bot locked as resolved and limited conversation to collaborators Aug 15, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

4 participants