You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GAE部署Java Endpoints应用启动失败:app_identity_service异常排查

问题排查:GAE部署后抛出app_identity_service.GetAccessToken异常

问题场景

基于Java开发的Google Endpoints应用,添加Google Storage依赖后,本地通过mvn appengine:run运行完全正常,但部署到Google App Engine(GAE)生产环境后,Web实例无法启动,日志抛出核心异常:

com.google.apphosting.api.ApiProxy$FeatureNotEnabledException: app_identity_service.GetAccessToken

完整日志片段:

c.g.a.r.j.AppEngineWebAppContext@442bff20{/,file:///workspace/,UNAVAILABLE}{/workspace}
com.google.apphosting.api.ApiProxy$FeatureNotEnabledException: app_identity_service.GetAccessToken 
    at java.base/java.lang.Thread.getStackTrace(Thread.java:1602)
    at com.google.apphosting.runtime.ApiProxyImpl.doSyncCall(ApiProxyImpl.java:362)
    ...(完整栈信息见原文)

项目Maven依赖关键配置:

<!-- See https://cloud.google.com/java/docs/bom -->
<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>com.google.cloud</groupId>
      <artifactId>libraries-bom</artifactId>
      <version>25.4.0</version>
      <type>pom</type>
      <scope>import</scope>
    </dependency>
  </dependencies>
</dependencyManagement>

<dependencies>
  <dependency>
    <groupId>com.google.endpoints</groupId>
    <artifactId>endpoints-management-control-appengine-all</artifactId>
    <version>1.0.14</version>
  </dependency>
  ...(完整依赖见原文)
</dependencies>

原因分析

  1. GAE环境权限未启用:App Engine标准环境中,app_identity_service.GetAccessToken接口依赖的App Engine Identity API默认可能未开启;或者应用默认服务账号缺少生成访问令牌的权限。
  2. 依赖版本冲突:引入的Cloud Libraries BOM(版本25.4.0)和Endpoints管理依赖(版本1.0.14)存在兼容性问题,导致在GAE生产环境中调用身份服务时触发未启用特性的报错。
  3. 本地与生产环境差异:本地开发服务器模拟了完整的身份服务能力,但GAE生产环境对服务调用有更严格的权限校验和特性启用要求。

解决方法

方法1:启用API并配置服务账号权限

  • 登录Google Cloud控制台,进入目标GAE项目。
  • 打开API和服务 > 库,搜索并启用App Engine Identity API。
  • 找到应用默认服务账号(格式:PROJECT_ID@appspot.gserviceaccount.com),为其添加Service Account Token Creator角色,该角色允许服务账号生成访问令牌。

方法2:调整依赖版本消除兼容性问题

  • 降低Cloud Libraries BOM版本至与Endpoints依赖兼容的版本,比如验证过的20.1.0:
<dependency>
  <groupId>com.google.cloud</groupId>
  <artifactId>libraries-bom</artifactId>
  <version>20.1.0</version>
  <type>pom</type>
  <scope>import</scope>
</dependency>
  • 或者升级Endpoints管理依赖到最新兼容版本,避免跨版本调用的适配问题。

方法3:配置GAE应用的服务账号

  • 在appengine-web.xml中明确指定使用的服务账号,确保权限配置生效:
<service-account>PROJECT_ID@appspot.gserviceaccount.com</service-account>
  • 如果使用自定义服务账号,需提前授权该账号访问Google Storage,同时确保其拥有生成访问令牌的权限。

内容的提问来源于stack exchange,提问作者Fabio C.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 04:43:20