You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

加载服务账号凭据后无法用其访问Firestore下载数据求助

问题解决步骤

核心原因

你的代码虽然指定了服务账号凭证,但Google的默认凭证加载机制优先选取了gcloud CLI存储的终端用户凭证(quehoraesxxxx@gmail.com),导致实际未使用代码中配置的服务账号。

解决方法

1. 强制固定使用指定的服务账号凭证

修改FirestoreOptions构建逻辑,使用FixedCredentialsProvider明确指定服务账号,跳过默认凭证链的自动查找:

import com.google.api.gax.core.FixedCredentialsProvider;

// 原有获取Gcredentials的代码保持不变

FirestoreOptions firestoreOptions_custom54 = FirestoreOptions.getDefaultInstance().toBuilder()
    .setProjectId("steprate220901")
    .setCredentialsProvider(FixedCredentialsProvider.create(Gcredentials))
    .build();
Firestore db_custom54 = firestoreOptions_custom54.getService();

2. 验证服务账号权限

确保服务账号拥有Firestore数据读取权限:

  • 登录Google Cloud控制台,进入目标项目steprate220901的IAM页面
  • 找到对应服务账号(可从json文件的client_email字段获取)
  • 为其添加Firestore Reader或Cloud Datastore User角色

3. 排除环境变量干扰

检查系统环境变量中是否存在GOOGLE_APPLICATION_CREDENTIALS,如果该变量指向了其他凭证文件,会覆盖代码中的配置,建议暂时移除该变量或设置为你的服务账号json路径。

4. 清理本地gcloud用户凭证(可选)

如果不需要保留gcloud的终端用户认证,执行以下命令移除本地存储的用户凭证:

gcloud auth revoke quehoraesxxxx@gmail.com

内容的提问来源于stack exchange,提问作者Kuni Shiina

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 19:13:20