Cloud Run中Java应用调用Cloud KMS无需显式凭证失败咨询
问题:Cloud Run部署的Spring Boot应用访问Cloud KMS时ADC认证失败
我在GCP Cloud Run上部署了Java Spring Boot应用,调用Cloud KMS的KeyManagementServiceClient.create()时失败,报错如下:
java.io.IOException: The Application Default Credentials are not available. They are available if running in Google Compute Engine. Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials for more information. at com.google.auth.oauth2.DefaultCredentialsProvider.getDefaultCredentials(DefaultCredentialsProvider.java:134) at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault(GoogleCredentials.java:125) at com.google.auth.oauth2.GoogleCredentials.getApplicationDefault(GoogleCredentials.java:97) at com.google.api.gax.core.GoogleCredentialsProvider.getCredentials(GoogleCredentialsProvider.java:70) at com.google.api.gax.rpc.ClientContext.create(ClientContext.java:168) at com.google.cloud.kms.v1.stub.GrpcKeyManagementServiceStub.create(GrpcKeyManagementServiceStub.java:458) at com.google.cloud.kms.v1.stub.KeyManagementServiceStubSettings.createStub(KeyManagementServiceStubSettings.java:668) at com.google.cloud.kms.v1.KeyManagementServiceClient.<init>(KeyManagementServiceClient.java:191) at com.google.cloud.kms.v1.KeyManagementServiceClient.create(KeyManagementServiceClient.java:173) at com.google.cloud.kms.v1.KeyManagementServiceClient.create(KeyManagementServiceClient.java:164) at ..................................................................................
按道理Cloud Run服务使用的服务账号只要具备Cloud KMS的访问权限,就应该自动通过应用默认凭据(ADC)完成认证,为什么还要求显式指定GOOGLE_APPLICATION_CREDENTIALS环境变量?
解决方案排查
Cloud Run确实支持自动挂载服务账号的ADC,无需手动指定密钥文件,出现这个问题的常见原因及排查步骤如下:
1. 服务账号配置验证
- 确认服务账号关联正确:检查Cloud Run控制台「安全」标签下的服务账号,确保服务使用的是你配置了KMS权限的账号,而非默认的Compute Engine服务账号(若未手动指定,Cloud Run会使用项目默认的Compute Engine服务账号,可能未配置KMS权限)。
- 验证权限绑定生效:确认服务账号已绑定Cloud KMS所需角色(如
roles/cloudkms.cryptoKeyEncrypterDecrypter或更细粒度的权限),且角色绑定已生效(权限绑定通常需要1-2分钟同步,若刚配置需等待)。可通过gcloud命令核对:gcloud projects get-iam-policy YOUR_PROJECT_ID --filter="bindings.members:serviceAccount:SERVICE_ACCOUNT_EMAIL" --format=json
2. 客户端依赖版本检查
旧版本的Google Cloud客户端库对Cloud Run的ADC支持可能存在缺陷,建议升级以下依赖到最新稳定版:
google-cloud-kms(推荐2.x及以上)google-auth-library-oauth2-httpgoogle-api-gax
3. 代码初始化逻辑排查
- 若代码中存在自定义认证逻辑(如硬编码
GOOGLE_APPLICATION_CREDENTIALS、手动加载密钥文件),会覆盖默认ADC加载流程,需移除这类代码。 - 可尝试显式指定使用默认凭据初始化客户端,确保逻辑正确:
import com.google.cloud.kms.v1.KeyManagementServiceClient; import com.google.cloud.kms.v1.KeyManagementServiceSettings; import com.google.api.gax.core.GoogleCredentialsProvider; // ... KeyManagementServiceSettings settings = KeyManagementServiceSettings.newBuilder() .setCredentialsProvider(GoogleCredentialsProvider.create()) .build(); try (KeyManagementServiceClient client = KeyManagementServiceClient.create(settings)) { // 你的KMS操作逻辑 }
4. Cloud Run运行环境配置检查
- 网络访问限制:若启用了VPC连接器,需确保VPC网络允许访问Cloud KMS的公共端点(
cloudkms.googleapis.com),虽然当前报错是认证问题,但网络不通可能间接导致ADC加载失败。 - 服务部署状态:确认Cloud Run服务部署成功,没有配置错误导致服务账号无法正常挂载。可重新部署一次服务,确保配置生效。
5. 本地模拟验证
在本地使用gcloud auth application-default login获取ADC,运行Spring Boot应用,若能正常访问KMS,则说明代码逻辑无问题,问题出在Cloud Run的配置上;若本地也报错,则排查代码或依赖问题。
内容的提问来源于stack exchange,提问作者Sabari
相关产品推荐
相关产品推荐

