You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Run中Java应用调用Cloud KMS无需显式凭证失败咨询

问题:Cloud Run部署的Spring Boot应用访问Cloud KMS时ADC认证失败

我在GCP Cloud Run上部署了Java Spring Boot应用,调用Cloud KMS的KeyManagementServiceClient.create()时失败,报错如下:

java.io.IOException: The Application Default Credentials are not available. 
They are available if running in Google Compute Engine. 
Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS 
must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials 
for more information. 
    at com.google.auth.oauth2.DefaultCredentialsProvider.getDefaultCredentials(DefaultCredentialsProvider.java:134) 
    at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault(GoogleCredentials.java:125) 
    at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault(GoogleCredentials.java:97) 
    at com.google.api.gax.core.GoogleCredentialsProvider.getCredentials(GoogleCredentialsProvider.java:70) 
    at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:168) 
    at com.google.cloud.kms.v1.stub.GrpcKeyManagementServiceStub.create(GrpcKeyManagementServiceStub.java:458) 
    at com.google.cloud.kms.v1.stub.KeyManagementServiceStubSettings.createStub(KeyManagementServiceStubSettings.java:668) 
    at com.google.cloud.kms.v1.KeyManagementServiceClient.<init>(KeyManagementServiceClient.java:191) 
    at com.google.cloud.kms.v1.KeyManagementServiceClient.create(KeyManagementServiceClient.java:173) 
    at com.google.cloud.kms.v1.KeyManagementServiceClient.create(KeyManagementServiceClient.java:164) 
    at ..................................................................................

按道理Cloud Run服务使用的服务账号只要具备Cloud KMS的访问权限,就应该自动通过应用默认凭据(ADC)完成认证,为什么还要求显式指定GOOGLE_APPLICATION_CREDENTIALS环境变量?


解决方案排查

Cloud Run确实支持自动挂载服务账号的ADC,无需手动指定密钥文件,出现这个问题的常见原因及排查步骤如下:

1. 服务账号配置验证

  • 确认服务账号关联正确:检查Cloud Run控制台「安全」标签下的服务账号,确保服务使用的是你配置了KMS权限的账号,而非默认的Compute Engine服务账号(若未手动指定,Cloud Run会使用项目默认的Compute Engine服务账号,可能未配置KMS权限)。
  • 验证权限绑定生效:确认服务账号已绑定Cloud KMS所需角色(如roles/cloudkms.cryptoKeyEncrypterDecrypter或更细粒度的权限),且角色绑定已生效(权限绑定通常需要1-2分钟同步,若刚配置需等待)。可通过gcloud命令核对:
    gcloud projects get-iam-policy YOUR_PROJECT_ID --filter="bindings.members:serviceAccount:SERVICE_ACCOUNT_EMAIL" --format=json
    

2. 客户端依赖版本检查

旧版本的Google Cloud客户端库对Cloud Run的ADC支持可能存在缺陷,建议升级以下依赖到最新稳定版:

  • google-cloud-kms(推荐2.x及以上)
  • google-auth-library-oauth2-http
  • google-api-gax

3. 代码初始化逻辑排查

  • 若代码中存在自定义认证逻辑(如硬编码GOOGLE_APPLICATION_CREDENTIALS、手动加载密钥文件),会覆盖默认ADC加载流程,需移除这类代码。
  • 可尝试显式指定使用默认凭据初始化客户端,确保逻辑正确:
    import com.google.cloud.kms.v1.KeyManagementServiceClient;
    import com.google.cloud.kms.v1.KeyManagementServiceSettings;
    import com.google.api.gax.core.GoogleCredentialsProvider;
    
    // ...
    
    KeyManagementServiceSettings settings = KeyManagementServiceSettings.newBuilder()
        .setCredentialsProvider(GoogleCredentialsProvider.create())
        .build();
    try (KeyManagementServiceClient client = KeyManagementServiceClient.create(settings)) {
        // 你的KMS操作逻辑
    }
    

4. Cloud Run运行环境配置检查

  • 网络访问限制:若启用了VPC连接器,需确保VPC网络允许访问Cloud KMS的公共端点(cloudkms.googleapis.com),虽然当前报错是认证问题,但网络不通可能间接导致ADC加载失败。
  • 服务部署状态:确认Cloud Run服务部署成功,没有配置错误导致服务账号无法正常挂载。可重新部署一次服务,确保配置生效。

5. 本地模拟验证

在本地使用gcloud auth application-default login获取ADC,运行Spring Boot应用,若能正常访问KMS,则说明代码逻辑无问题,问题出在Cloud Run的配置上;若本地也报错,则排查代码或依赖问题。


内容的提问来源于stack exchange,提问作者Sabari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 02:57:32