You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

删除默认Compute Engine服务账户后Firebase云函数部署失败求助

Firebase Cloud Functions部署错误:缺失默认Compute Engine服务账户解决方案

问题核心

删除超过30天的<number>-compute@developer.gserviceaccount.com默认Compute Engine服务账户无法恢复,导致Firebase CLI部署云函数时触发404错误。


1. 关于服务账户恢复的结论

不能恢复。Google Cloud明确规定:删除超过30天的服务账户属于不可逆操作,无法找回,只能通过创建新服务账户替代。


2. 配置Firebase CLI使用新服务账户的方法

针对你使用Bitbucket Firebase Deploy Pipe的场景,按以下步骤解决:

(1)创建并授权新服务账户

  • 登录Google Cloud控制台,进入IAM与管理员 > 服务账户,创建新账户
  • 为新账户分配以下必要权限:
    • Cloud Functions Developer
    • Cloud Build Editor
    • Storage Admin
    • Service Account User
    • Firebase Admin SDK Administrator Service Agent(若依赖Firebase其他服务)
  • 生成并下载该账户的JSON密钥文件

(2)修正Bitbucket Pipe配置

确保KEY_FILE指向新服务账户的密钥文件,同时显式指定项目ID,避免CLI读取旧缓存:

- pipe: atlassian/firebase-deploy:1.0.0
  variables:
    KEY_FILE: '$BITBUCKET_CLONE_DIR/new-service-account-key.json'
    PROJECT_ID: '<你的项目ID>'
    COMMAND: 'deploy --only functions'

(3)清除CI环境的Firebase缓存

在部署步骤前添加缓存清理命令,避免CLI复用旧账户信息:

firebase logout --token || true
firebase login:ci --token "$(cat $KEY_FILE)"

(4)项目级强制指定部署账户

如果需要在项目层面固定部署用账户,可在部署命令中添加--service-account参数:

firebase deploy --only functions --service-account <新服务账户邮箱>

也可在项目根目录的.firebaserc文件中明确项目配置,避免自动关联旧账户:

{
  "projects": {
    "default": "<你的项目ID>"
  }
}

额外排查项

  • 检查CI环境变量是否残留旧账户信息,比如GOOGLE_APPLICATION_CREDENTIALS是否指向旧密钥
  • 确认新服务账户已获得GCR(Google Container Registry)访问权限,添加Storage Admin或Artifact Registry Writer权限解决镜像推送报错

内容的提问来源于stack exchange,提问作者Ibrahim Itani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 13:13:15