Skip to main content
Question

Policy Troubleshooter v3beta returns PAB UNKNOWN_INFO for Cloud Run service agent

  • October 11, 2026
  • 0 replies
  • 17 views

leonid04

We are performing read-only security checks before setting up private Cloud Run staging.

We evaluated artifactregistry.repositories.downloadArtifacts on an existing Artifact Registry repository for the project's Cloud Run service agent:
[removed by moderator]

Using POST https://policytroubleshooter.googleapis.com/v3beta/iam:troubleshoot with an explicit x-goog-user-project header, the response returned:

overallAccessState: UNKNOWN_INFO
allowAccessState: ALLOW_ACCESS_STATE_GRANTED
denyAccessState: DENY_ACCESS_STATE_NOT_DENIED
principalAccessBoundaryAccessState: PAB_ACCESS_STATE_UNKNOWN_INFO

No top-level errors were returned. The PAB explanation contained only its UNKNOWN_INFO state; explainedBindingsAndPolicies was omitted.

The requesting user has project Owner access. The project has no organization or folder parent. The Cloud Run service agent has roles/run.serviceAgent, and the existing production service is operational.

We understand that Google-managed service agents cannot be inspected as ordinary customer-owned service accounts. We are not interpreting UNKNOWN as either authorization or denial.

Is conclusive PAB evaluation supported for Google-managed Cloud Run service agents? Could this result reflect information unavailable to a customer-project administrator?

What supported read-only verification can establish image-access authorization without broader IAM grants, agent impersonation, service-agent creation, or deployment?