通过Terraform部署Identity Platform后,如何获取API key与auth domain?
从Terraform获取Google Identity Platform的API Key与Auth Domain
完全可以直接从Terraform中提取所需的API Key和Auth Domain,不用手动去控制台复制,以下是具体实现方式:
1. 获取API Key
Google Identity Platform默认会自动创建一个关联的API Key,你可以通过Terraform的google_apikeys_key数据源过滤获取:
# 自动匹配Identity Platform生成的API Key data "google_apikeys_key" "idp_api_key" { filter = "displayName:Identity Platform API Key" } # 输出API Key(标记为敏感信息,避免明文泄露) output "idp_api_key" { value = data.google_apikeys_key.idp_api_key.string_value sensitive = true }
如果是你自己通过Terraform创建的API Key并关联到Identity Platform,直接引用该资源的string_value字段即可。
2. 获取Auth Domain
使用google_identity_platform_project_default_config数据源可以直接读取Identity Platform的默认配置,其中包含官方的Auth Domain:
data "google_identity_platform_project_default_config" "idp_config" { project = var.google_project_id } # 输出Auth Domain output "idp_auth_domain" { value = data.google_identity_platform_project_default_config.idp_config.auth_domain }
如果不想用数据源,也可以直接通过项目ID拼接——纯Identity Platform项目的Auth Domain格式固定为[你的项目ID].firebaseapp.com,不过用数据源获取的结果更准确,避免区域或配置差异导致的错误。
3. 在Web应用部署中引用
将这些值直接传入Web应用的环境变量即可,以Cloud Run部署为例:
resource "google_cloud_run_service" "web_app" { name = "your-web-app" location = var.google_region template { spec { containers { image = "your-web-app-image-url" env { name = "FIREBASE_API_KEY" value = data.google_apikeys_key.idp_api_key.string_value } env { name = "FIREBASE_AUTH_DOMAIN" value = data.google_identity_platform_project_default_config.idp_config.auth_domain } } } } }
权限注意事项
确保你的Terraform服务账号拥有以下权限:
roles/apikeys.viewer:用于读取API Key信息roles/identityplatform.admin:用于读取Identity Platform配置
内容的提问来源于stack exchange,提问作者Jonatan
相关产品推荐
相关产品推荐

