删除默认Compute Engine服务账户后Firebase云函数部署失败求助
Firebase Cloud Functions部署错误:缺失默认Compute Engine服务账户解决方案
问题核心
删除超过30天的<number>-compute@developer.gserviceaccount.com默认Compute Engine服务账户无法恢复,导致Firebase CLI部署云函数时触发404错误。
1. 关于服务账户恢复的结论
不能恢复。Google Cloud明确规定:删除超过30天的服务账户属于不可逆操作,无法找回,只能通过创建新服务账户替代。
2. 配置Firebase CLI使用新服务账户的方法
针对你使用Bitbucket Firebase Deploy Pipe的场景,按以下步骤解决:
(1)创建并授权新服务账户
- 登录Google Cloud控制台,进入IAM与管理员 > 服务账户,创建新账户
- 为新账户分配以下必要权限:
- Cloud Functions Developer
- Cloud Build Editor
- Storage Admin
- Service Account User
- Firebase Admin SDK Administrator Service Agent(若依赖Firebase其他服务)
- 生成并下载该账户的JSON密钥文件
(2)修正Bitbucket Pipe配置
确保KEY_FILE指向新服务账户的密钥文件,同时显式指定项目ID,避免CLI读取旧缓存:
- pipe: atlassian/firebase-deploy:1.0.0 variables: KEY_FILE: '$BITBUCKET_CLONE_DIR/new-service-account-key.json' PROJECT_ID: '<你的项目ID>' COMMAND: 'deploy --only functions'
(3)清除CI环境的Firebase缓存
在部署步骤前添加缓存清理命令,避免CLI复用旧账户信息:
firebase logout --token || true firebase login:ci --token "$(cat $KEY_FILE)"
(4)项目级强制指定部署账户
如果需要在项目层面固定部署用账户,可在部署命令中添加--service-account参数:
firebase deploy --only functions --service-account <新服务账户邮箱>
也可在项目根目录的.firebaserc文件中明确项目配置,避免自动关联旧账户:
{ "projects": { "default": "<你的项目ID>" } }
额外排查项
- 检查CI环境变量是否残留旧账户信息,比如
GOOGLE_APPLICATION_CREDENTIALS是否指向旧密钥 - 确认新服务账户已获得GCR(Google Container Registry)访问权限,添加
Storage Admin或Artifact Registry Writer权限解决镜像推送报错
内容的提问来源于stack exchange,提问作者Ibrahim Itani
相关产品推荐
相关产品推荐

