GCP中Artifact Repository的Keyring认证无法正常工作
Let's walk through step-by-step checks to figure out why pip is still prompting for a username instead of using keyring automatically:
Install the required Google Artifact Registry auth tool
Google's private PyPI repositories rely on theartifactregistry-authpackage to integrate with keyring. Make sure you've installed it via pip:pip install artifactregistry-auth
This package sets up the necessary keyring backend to handle authentication for Artifact Registry.Test if keyring can retrieve credentials
Run this command to directly check if keyring can fetch valid credentials for your repository:keyring get https://us-west1-python.pkg.dev/mno-415182/pqr/ ''
If this returns an error or prompts for input, it means keyring isn't properly configured to access your credentials. If it returns a token-like string, the issue might be with pip's keyring integration instead.Ensure pip is configured to use keyring
Some pip versions need explicit enablement of keyring support. Try either:- Setting the environment variable temporarily when running pip:
PIP_USE_KEYRING=1 pip install stringcase - Adding this to your
pip.conf(usually located at~/.config/pip/pip.confor%APPDATA%\pip\pip.inion Windows):[global] use-keyring = true
- Setting the environment variable temporarily when running pip:
Verify your active gcloud identity
Even though you logged in as the service account's owner, pip/keyring might need the service account's identity directly. Activate the service account explicitly:gcloud auth activate-service-account --key-file=$GOOGLE_APPLICATION_CREDENTIALS
Then rungcloud auth listto confirm this service account is marked asACTIVE. Also, verify the service account has theroles/artifactregistry.writer(or appropriate) permission on the repository via Google Cloud Console.Check if environment variables are passed to pip
Sometimes terminal environment variables don't propagate correctly (especially if running pip from an IDE like PyCharm). First, confirm the variable exists in the same shell where you run pip:echo $GOOGLE_APPLICATION_CREDENTIALS
If it's correct, try explicitly passing it with the pip command to rule out propagation issues:GOOGLE_APPLICATION_CREDENTIALS=/home/jkl/.googlekeys/serviceaccount.json pip install stringcase
If you're using PyCharm, go to Settings > Project > Python Interpreter > Show All > Interpreter Paths and add the environment variable there.Validate keyring backend priority
Keyring might be using a default backend that doesn't handle Google Artifact Registry. List available backends with:keyring --list-backends
Look forGoogleArtifactsAuthBackendin the output. If it's missing, reinstallartifactregistry-auth. If it's present but not the top priority, force it with an environment variable:KEYRING_BACKEND=keyring.backends.google_artifacts_auth.GoogleArtifactsAuthBackend pip install stringcaseTest repository accessibility with curl
Rule out issues with the repository itself by testing access using a gcloud-generated token:curl -H "Authorization: Bearer $(gcloud auth print-access-token)" https://us-west1-python.pkg.dev/mno-415182/pqr/simple/
If this returns a 403 error, double-check the service account's permissions. If it works, the problem is definitely in the keyring-pip integration.
内容的提问来源于stack exchange,提问作者Stéphane

