Objectify6部署至App Engine标准环境时触发认证缺失异常
Objectify 5 迁移至 Objectify 6:App Engine 生产环境认证异常解决
问题详情
本地运行正常,但部署到 App Engine Standard 生产环境后触发认证错误:
Caused by: com.google.datastore.v1.client.DatastoreException: Request is missing required authentication credential. Expected OAuth 2 access token, login cookie or other valid authentication credential. See https://developers.google.com/identity/sign-in/web/devconsole-project., code=UNAUTHENTICATED at com.google.datastore.v1.client.RemoteRpc.makeException(RemoteRpc.java:171) at com.google.datastore.v1.client.RemoteRpc.makeException(RemoteRpc.java:239) at com.google.datastore.v1.client.RemoteRpc.call(RemoteRpc.java:100) at com.google.datastore.v1.client.Datastore.lookup(Datastore.java:93) at com.google.cloud.datastore.spi.v1.HttpDatastoreRpc.lookup(HttpDatastoreRpc.java:171)
按照官方文档,App Engine Standard 环境下只需执行以下初始化代码:
ObjectifyService.init();
但问题依旧。尝试手动配置凭证:
String projectId = "my-project-id"; Credentials defaultCredentials = GoogleCredentials.getApplicationDefault(); DatastoreOptions.Builder datastoreOptionsBuilder = DatastoreOptions.newBuilder() .setProjectId(projectId) .setCredentials(defaultCredentials); ObjectifyService.init(new ObjectifyFactory(datastoreOptionsBuilder.build() .getService()));
又触发新异常:
Caused by: java.io.IOException: The Application Default Credentials are not available. They are available if running in Google Compute Engine. Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials for more information. at com.google.auth.oauth2.DefaultCredentialsProvider.getDefaultCredentials( DefaultCredentialsProvider.java:134) at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault( GoogleCredentials.java:125) at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault( GoogleCredentials.java:97) at media.vrtual.api.configuration.jersey.VrtualApiApplication.setUpDatabase( VrtualApiApplication.java:283)
解决办法
使用默认初始化逻辑,禁止手动配置凭证
App Engine Standard 环境会自动注入服务账号凭证,Objectify 6 原生支持该逻辑。确保初始化代码仅执行一次(建议放在静态代码块中):static { ObjectifyService.init(); // 注册你的实体类 ObjectifyService.register(YourEntity.class); }排查依赖冲突
检查项目依赖树,避免多个版本的google-cloud-datastore、google-auth-library或 Objectify 相关依赖共存。用 Maven 的mvn dependency:tree或 Gradle 的./gradlew dependencies查看依赖,排除冲突的旧版本。适配 App Engine 原生 Datastore 客户端
如果默认初始化仍失败,改用 App Engine 原生的 DatastoreService 构建 ObjectifyFactory:import com.google.appengine.api.datastore.DatastoreService; import com.google.appengine.api.datastore.DatastoreServiceFactory; import com.googlecode.objectify.ObjectifyService; import com.googlecode.objectify.impl.ObjectifyFactory; static { DatastoreService datastore = DatastoreServiceFactory.getDatastoreService(); ObjectifyService.init(new ObjectifyFactory(datastore)); ObjectifyService.register(YourEntity.class); }检查部署配置
确认app.yaml未修改服务账号相关配置,默认的 App Engine 服务账号已拥有 Datastore 读写权限(默认配置已包含该权限)。
内容的提问来源于stack exchange,提问作者Bogdan Oloeriu
相关产品推荐
相关产品推荐

