Skip to content

Actor deletion stuck due to lacking permissions #64

Description

@rakyll

Deleting an actor fails when ate-api-server attempts to clean up snapshots from GCS:

rpc error: code = PermissionDenied desc = Caller does not have storage.objects.list access to the Google Cloud Storage bucket. Permission 'storage.objects.list' denied on resource '//storage.googleapis.com/projects/_/buckets/<bucket>'

Because snapshot cleanup fails, the actor remains permanently stuck in ACTOR_STATE_DELETING.

Cause

On GKE, default node service accounts only have read_only storage scopes. The ate-system/ate-api-server Kubernetes service account is not bound to a Google Service Account (GSA) via Workload Identity, leaving it without permissions to list or delete objects in the snapshots bucket.

Suggestions

  1. Document Workload Identity setup: Specify that ate-api-server requires roles/storage.objectAdmin on the snapshot bucket via Workload Identity (ate-system/ate-api-server).
  2. Handle cleanup failures gracefully: Allow actor deletion to complete (or report a warning) instead of trapping the actor in ACTOR_STATE_DELETING forever when bucket cleanup errors occur.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions