GKE启用Workload Identity后Java应用无法找到ADC求助
GKE Workload Identity迁移后Java应用无法获取默认凭据问题
背景
正在将GKE集群上运行的服务迁移至使用Workload Identity认证访问GCP资源,此前服务通过环境变量GOOGLE_APPLICATION_CREDENTIALS指向SA JSON密钥完成认证。
报错情况
运行代码LOG.info("Default credentials: " + ServiceAccountCredentials.getApplicationDefault());时,应用抛出以下错误:
"Your default credentials were not found. To set up Application Default Credentials for your environment, see https://cloud.google.com/docs/authentication/external/set-up-adc.","message":"Your default credentials were not found. To set up Application Default Credentials for your environment, see https://cloud.google.com/docs/authentication/external/set-up-adc.","name":"java.io.IOException","extendedStackTrace":[{"class":"com.google.auth.oauth2.DefaultCredentialsProvider","method":"getDefaultCredentials","file":"DefaultCredentialsProvider.java","line":127,"exact":false,"location":"com.google.auth.google-auth-library-oauth2-http-1.22.0.jar","version":"1.22.0"},{"class":"com.google.auth.oauth2.GoogleCredentials","method":"getApplicationDefault","file":"GoogleCredentials.java","line":152,"exact":false,"location":"com.google.auth.google-auth-library-oauth2-http-1.22.0.jar","version":"1.22.0"},
使用HikariCP建立Cloud SQL连接时,也会出现相同错误。
已完成的验证与配置
- 已完成KSA与GSA的创建、绑定及注解配置,GSA被授予Editor角色
- 容器内执行
gcloud auth list可看到对应GSA为活跃账户 - 以下curl请求元数据服务器均成功:
curl http://metadata.google.internal/computeMetadata/v1/ -H "Metadata-Flavor: Google"curl http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token -H "Metadata-Flavor: Google" - 确认
/var/run/secrets/kubernetes.io/serviceaccount/token文件存在 gcloud storage buckets list、gcloud sql instances list、gcloud alpha bq datasets list等命令可正常访问GCP资源,但Java应用仍无法获取ADC
相关配置文件
deployment.yaml
apiVersion: apps/v1 kind: Deployment metadata: labels: app: my-app name: my-app namespace: dataservice spec: progressDeadlineSeconds: 600 replicas: 2 revisionHistoryLimit: 10 selector: matchLabels: app: my-app strategy: rollingUpdate: maxSurge: 25% maxUnavailable: 25% type: RollingUpdate template: metadata: annotations: timestamp: "2025-01-01T00:00:00Z" labels: app: my-app spec: serviceAccountName: service-account-experimental nodeSelector: iam.gke.io/gke-metadata-server-enabled: "true" initContainers: - name: init image: gcr.io/google.com/cloudsdktool/cloud-sdk:alpine command: - sh - -c - | /bin/bash <<'EOF' #!/bin/bash echo starting install neo4j user; neou=$(gcloud secrets versions access "latest" --secret="username-ro") neop=$(gcloud secrets versions access "latest" --secret="password-ro") mkdir -p /etc/my-app; cp /keys/sase/neo4j_config.properties /etc/my-app/neo4j_config.properties; cp /keys/sase/config.json /etc/my-app/config.json; sed -i "s/SECRETS_NEO4J_RO_USER/$neou/" /etc/my-app/neo4j_config.properties; sed -i "s/SECRETS_NEO4J_RO_PASSWD/$neop/" /etc/my-app/neo4j_config.properties; echo done; EOF volumeMounts: - mountPath: /keys/sase/ name: my-app readOnly: true - name: key-storage mountPath: /etc/my-app/ containers: - image: my-image:latest name: dataservice livenessProbe: httpGet: path: /health/live port: 8080 initialDelaySeconds: 60 periodSeconds: 10 failureThreshold: 2 timeoutSeconds: 5 readinessProbe: httpGet: path: /health/ready port: 8080 initialDelaySeconds: 10 periodSeconds: 10 resources: requests: cpu: "1" memory: "1Gi" limits: cpu: "2" memory: "2Gi" env: - name: JAVA_OPTS value: "-Xmx512m -Xms512m" ports: - containerPort: 8080 volumeMounts: - mountPath: /etc/secrets name: secrets readOnly: true - mountPath: /etc/config name: config readOnly: true dnsPolicy: ClusterFirst restartPolicy: Always terminationGracePeriodSeconds: 30 volumes: - name: secrets secret: secretName: my-secrets - name: config configMap: name: my-config - name: app-config secret: secretName: app-config - name: key-storage emptyDir: {}
serviceaccount.yaml
apiVersion: v1 kind: ServiceAccount metadata: name: service-account-experimental namespace: dataservice annotations: iam.gke.io/gcp-service-account: gservice-account-test@my_project_id.iam.gserviceaccount.com
内容的提问来源于stack exchange,提问作者Dhruthick Gowda Mohan
相关产品推荐
相关产品推荐

