You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Github认证GCP:解决CI/CD中Pub/Sub的DefaultCredentialsError问题

问题:Github CI/CD中Google Pub/Sub认证失败

我的应用在本地及Cloud Run部署环境均能正常运行,但在Github CI/CD工作流执行测试时失败,执行代码publisher = pubsub_v1.PublisherClient()触发错误:google.auth.exceptions.DefaultCredentialsError: File *** was not found.

完整报错栈信息:

/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/cloud/pubsub_v1/publisher/client.py:139: in __init__
    super().__init__(**kwargs)
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/client.py:492: in __init__
    self._transport = Transport(
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/transports/grpc.py:153: in __init__
    super().__init__(
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/pubsub_v1/services/publisher/transports/base.py:104: in __init__
    credentials, _ = google.auth.default(
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:615: in default
    credentials, project_id = checker()
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:608: in <lambda>
    lambda: _get_explicit_environ_credentials(quota_project_id=quota_project_id),
/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:228: in _get_explicit_environ_credentials
    credentials, project_id = load_credentials_from_file(
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 

filename = '***'
scopes = None, default_scopes = None, quota_project_id = None, request = None

    def load_credentials_from_file(
        filename, scopes=None, default_scopes=None, quota_project_id=None, request=None
    ):
        """Loads Google credentials from a file.
    
        The credentials file must be a service account key, stored authorized
        user credentials, external account credentials, or impersonated service
        account credentials.
    
        Args:
            filename (str): The full path to the credentials file.
            scopes (Optional[Sequence[str]]): The list of scopes for the credentials. If
                specified, the credentials will automatically be scoped if
                necessary
            default_scopes (Optional[Sequence[str]]): Default scopes passed by a
                Google client library. Use 'scopes' for user-defined scopes.
            quota_project_id (Optional[str]):  The project ID used for
                quota and billing.
            request (Optional[google.auth.transport.Request]): An object used to make
                HTTP requests. This is used to determine the associated project ID
                for a workload identity pool resource (external account credentials).
                If not specified, then it will use a
                google.auth.transport.requests.Request client to make requests.
    
        Returns:
            Tuple[google.auth.credentials.Credentials, Optional[str]]: Loaded
                credentials and the project ID. Authorized user credentials do not
                have the project ID information. External account credentials project
                IDs may not always be determined.
    
        Raises:
            google.auth.exceptions.DefaultCredentialsError: if the file is in the
                wrong format or is missing.
        """
        if not os.path.exists(filename):
>           raise exceptions.DefaultCredentialsError(
                "File {} was not found.".format(filename)
            )
E           google.auth.exceptions.DefaultCredentialsError: File *** was not found.

/opt/hostedtoolcache/Python/3.10.13/x64/lib/python3.10/site-packages/google/auth/_default.py:116: DefaultCredentialsError

我已按照官方教程的「直接工作负载身份联合」部分,将Github认证配置为工作流的第一步,但教程第5步的资源授权示例过于具体,针对Pub/Sub场景,我不知道应该使用什么授权命令,问题仍未解决。


解决方案

1. 确认工作负载身份联合的Github Actions配置

确保工作流中已正确配置身份认证步骤,示例:

- name: 认证到Google Cloud
  uses: google-github-actions/auth@v1
  with:
    workload_identity_provider: 'projects/[你的项目ID]/locations/global/workloadIdentityPools/[你的池ID]/providers/[你的提供者ID]'
    service_account: '[你的服务账号邮箱]'

2. 为服务账号授予Pub/Sub权限

根据测试需要的操作,给用于身份联合的服务账号添加对应角色:

  • 仅发布消息:授予roles/pubsub.publisher
  • 订阅消息:授予roles/pubsub.subscriber
  • 完整管理权限:授予roles/pubsub.editor

执行以下gcloud命令完成授权(替换占位符):

gcloud projects add-iam-policy-binding [你的项目ID] \
  --member="serviceAccount:[你的服务账号邮箱]" \
  --role="roles/pubsub.publisher"

3. 移除代码中硬编码的凭证配置

检查代码是否强制指定了凭证文件路径,或者是否在工作流中错误设置了GOOGLE_APPLICATION_CREDENTIALS环境变量。工作负载身份联合模式下,Google客户端库会自动获取凭证,无需指定本地文件。

4. 验证工作流环境

确保Github Actions运行环境中没有遗留的旧凭证配置,避免干扰自动认证流程。


内容的提问来源于stack exchange,提问作者Sarah

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 03:24:54