Cloud Functions指定服务账号生成GCS签名URL报错排查
Python Cloud Functions生成签名URL时的服务账号认证错误
我正尝试在Python Cloud Functions中生成签名URL,初始化google-cloud-storage客户端SDK的代码如下:
firebase_admin.initialize_app() storage_client = storage.Client() # Use default credentials bucket_name = os.environ.get("BUCKET_NAME") bucket = storage_client.get_bucket(bucket_name)
部署Cloud Function时,我通过--service-account参数指定了服务账号邮箱。
上传并运行云端函数后,出现如下错误:
you need a private key to sign credentials. the credentials you are currently using <class 'google.auth.compute_engine.credentials.Credentials'> just contains a token. see https://googleapis.dev/python/google-api-core/latest/auth.html#setting-up-a-service-account for more details.
但在Mac本地使用functions-framework --target myfunction --debug --port=8081运行该函数时一切正常。
我确定这是服务账号相关问题,但本地仅使用了为Firebase Admin SDK生成的该服务账号,已执行:
export GOOGLE_APPLICATION_CREDENTIALS=/Users/foxtom/PycharmProjects/MyProject/firebase-adminsdk.json
且firebase-adminsdk.json中的邮箱与部署时gcloud deploy myfunction --service-account="firebase-adminsdk-email@gserviceaccount.com"指定的一致。
- 注:奇怪的是,服务账号实际已被使用,因为我未在
firebase_admin.initialize_app()中指定特定账号,但auth模块的verify_token方法可正常调用。 - 注2:Cloud Function详情的
General information中显示了正确的服务账号,但仅storage.Client()无法正常工作。
我遗漏了什么?
编辑补充:我已为该服务账号添加了Cloud Storage存储桶的Storage Object Viewer和Storage Object Creator权限(也尝试过Storage Admin权限),但问题仍未解决。
内容的提问来源于stack exchange,提问作者Tom3652
相关产品推荐
相关产品推荐

