Github认证GCP:解决CI/CD中Pub/Sub的DefaultCredentialsError问题
问题:Github CI/CD中Google Pub/Sub认证失败
我的应用在本地及Cloud Run部署环境均能正常运行,但在Github CI/CD工作流执行测试时失败,执行代码publisher = pubsub_v1.PublisherClient()触发错误:google.auth.exceptions.DefaultCredentialsError: File *** was not found.
完整报错栈信息:
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/cloud/pubsub_v1/publisher/client.py:139: in __init__ super().__init__(**kwargs) /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/client.py:492: in __init__ self._transport = Transport( /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/transports/grpc.py:153: in __init__ super().__init__( /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/transports/base.py:104: in __init__ credentials, _ = google.auth.default( /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:615: in default credentials, project_id = checker() /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:608: in <lambda> lambda: _get_explicit_environ_credentials(quota_project_id=quota_project_id), /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:228: in _get_explicit_environ_credentials credentials, project_id = load_credentials_from_file( _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ filename = '***' scopes = None, default_scopes = None, quota_project_id = None, request = None def load_credentials_from_file( filename, scopes=None, default_scopes=None, quota_project_id=None, request=None ): """Loads Google credentials from a file. The credentials file must be a service account key, stored authorized user credentials, external account credentials, or impersonated service account credentials. Args: filename (str): The full path to the credentials file. scopes (Optional[Sequence[str]]): The list of scopes for the credentials. If specified, the credentials will automatically be scoped if necessary default_scopes (Optional[Sequence[str]]): Default scopes passed by a Google client library. Use 'scopes' for user-defined scopes. quota_project_id (Optional[str]): The project ID used for quota and billing. request (Optional[google.auth.transport.Request]): An object used to make HTTP requests. This is used to determine the associated project ID for a workload identity pool resource (external account credentials). If not specified, then it will use a google.auth.transport.requests.Request client to make requests. Returns: Tuple[google.auth.credentials.Credentials, Optional[str]]: Loaded credentials and the project ID. Authorized user credentials do not have the project ID information. External account credentials project IDs may not always be determined. Raises: google.auth.exceptions.DefaultCredentialsError: if the file is in the wrong format or is missing. """ if not os.path.exists(filename): > raise exceptions.DefaultCredentialsError( "File {} was not found.".format(filename) ) E google.auth.exceptions.DefaultCredentialsError: File *** was not found. /opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:116: DefaultCredentialsError
我已按照官方教程的「直接工作负载身份联合」部分,将Github认证配置为工作流的第一步,但教程第5步的资源授权示例过于具体,针对Pub/Sub场景,我不知道应该使用什么授权命令,问题仍未解决。
解决方案
1. 确认工作负载身份联合的Github Actions配置
确保工作流中已正确配置身份认证步骤,示例:
- name: 认证到Google Cloud uses: google-github-actions/auth@v1 with: workload_identity_provider: 'projects/[你的项目ID]/locations/global/workloadIdentityPools/[你的池ID]/providers/[你的提供者ID]' service_account: '[你的服务账号邮箱]'
2. 为服务账号授予Pub/Sub权限
根据测试需要的操作,给用于身份联合的服务账号添加对应角色:
- 仅发布消息:授予
roles/pubsub.publisher - 订阅消息:授予
roles/pubsub.subscriber - 完整管理权限:授予
roles/pubsub.editor
执行以下gcloud命令完成授权(替换占位符):
gcloud projects add-iam-policy-binding [你的项目ID] \ --member="serviceAccount:[你的服务账号邮箱]" \ --role="roles/pubsub.publisher"
3. 移除代码中硬编码的凭证配置
检查代码是否强制指定了凭证文件路径,或者是否在工作流中错误设置了GOOGLE_APPLICATION_CREDENTIALS环境变量。工作负载身份联合模式下,Google客户端库会自动获取凭证,无需指定本地文件。
4. 验证工作流环境
确保Github Actions运行环境中没有遗留的旧凭证配置,避免干扰自动认证流程。
内容的提问来源于stack exchange,提问作者Sarah
相关产品推荐
相关产品推荐

