使用GitHub Actions部署Google Cloud Function时凭据加载失败
解决GitHub Actions部署Google Cloud Function时的凭据加载失败问题
问题描述
此前通过GitLab CI/CD成功部署Google Cloud Function,切换到GitHub Actions后已调整参数名(如source改为source_dir、my_env_vars改为environment_variables),但执行部署时出现错误:上传zip文件失败,无法加载默认凭据。
工作流代码
name: CI Workflow on: push: branches: - main jobs: deploy-gloud-functions_new: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Setup GCP Service Account uses: google-github-actions/setup-gcloud@main with: project_id: "cicdtest-421422" service_account_key: ${{ secrets.GCP_ACCOUNT_KEY }} - name: Set up Python uses: actions/setup-python@v4 with: python-version: 3.11 - name: Install dependencies run: pip install -r requirements.txt - name: deploy cloud function id: deploy uses: google-github-actions/deploy-cloud-functions@main with: name: generate_weather_summary runtime: python310 project_id: "cicdtest-421422" entry_point: generate_weather_summary region: europe-west1 source_dir: . event_trigger_type: topic weather-topic memory: 512MB environment_variables: "API_KEY=${{ secrets.API_KEY }},SLACK_TOKEN=${{ secrets.SLACK_TOKEN }}"
错误日志
Run google-github-actions/deploy-cloud-functions@main with: name: generate_weather_summary runtime: python310 project_id: cicdtest-421422 entry_point: generate_weather_summary region: europe-west1 source_dir: . event_trigger_type: topic weather-topic memory: 512MB environment_variables: API_KEY=***,SLACK_TOKEN=*** universe: googleapis.com environment: GEN_2 all_traffic_on_latest_revision: true ingress_settings: ALLOW_ALL service_timeout: 60s vpc_connector_egress_settings: PRIVATE_RANGES_ONLY event_trigger_retry: true env: CLOUDSDK_METRICS_ENVIRONMENT: github-actions-setup-gcloud CLOUDSDK_METRICS_ENVIRONMENT_VERSION: 2.1.0 pythonLocation: /opt/hostedtoolcache/Python/3.11.9/x64 PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.9/x64/lib/pkgconfig Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.9/x64 Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.9/x64 Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.9/x64 LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.9/x64/lib Created zip file from '.' at '/tmp/cfsrc-0ae0bbd4b761ae3f1003cd51.zip' Error: google-github-actions/deploy-cloud-functions failed with: failed to upload zip file: Could not load the default credentials. Browse to https://cloud.google.com/docs/authentication/getting-started for more information.
解决方案
错误根源是部署步骤未正确获取GCP凭据,可通过以下两种方式修复:
方案1:让setup-gcloud导出默认凭据
修改Setup GCP Service Account步骤,添加export_default_credentials: true参数,确保后续步骤能继承凭据:
- name: Setup GCP Service Account uses: google-github-actions/setup-gcloud@main with: project_id: "cicdtest-421422" service_account_key: ${{ secrets.GCP_ACCOUNT_KEY }} export_default_credentials: true
方案2:直接在部署步骤传入凭据
跳过setup-gcloud的凭据传递,直接在deploy-cloud-functions步骤中指定credentials参数:
- name: deploy cloud function id: deploy uses: google-github-actions/deploy-cloud-functions@main with: name: generate_weather_summary runtime: python310 project_id: "cicdtest-421422" entry_point: generate_weather_summary region: europe-west1 source_dir: . event_trigger_type: topic weather-topic memory: 512MB environment_variables: "API_KEY=${{ secrets.API_KEY }},SLACK_TOKEN=${{ secrets.SLACK_TOKEN }}" credentials: ${{ secrets.GCP_ACCOUNT_KEY }}
额外检查项
- 确认GitHub Secrets中的
GCP_ACCOUNT_KEY是完整且格式正确的GCP服务账号JSON密钥 - 确保该服务账号拥有
Cloud Functions Developer和Storage Object Admin权限(部署需上传代码到GCS存储桶)
内容的提问来源于stack exchange,提问作者KurczakChrupiacy2
相关产品推荐
相关产品推荐

