You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CircleCI本地作业中SOPS无法通过GCP KMS解密文件求助

Fixing SOPS GCP KMS Decryption Failure in Local CircleCI Execution

I get it—you’ve got a working service account that decrypts SOPS files locally, but when running the same setup in a local CircleCI job with the google/cloud-sdk:latest image, it’s throwing a "could not find default credentials" error. Even though you’ve verified the service account is activated, the credential file is valid, and the environment variable is set correctly, something’s still off. Let’s break this down and fix it.

Root Cause: Sudo Resets Environment Variables

The biggest clue here is that you’re running your script with sudo ./<RunJob.sh>. By default, sudo strips almost all environment variables from the new process context—including the GOOGLE_APPLICATION_CREDENTIALS you set earlier. That’s why SOPS can’t find the credentials, even though everything checks out right before running the script.

Solution 1: Use sudo -E to Preserve Environment Variables

The simplest fix is to pass your current environment to the sudo session using the -E flag. This keeps variables like GOOGLE_APPLICATION_CREDENTIALS intact for the script running under sudo:

- run:
    name: <MyJob>
    command: |
      apt-get install -y docker
      # The google/cloud-sdk image already includes sudo, so this line is unnecessary
      # apt-get install -y sudo
      cd $(pwd)/path/to/jobcode
      echo $GCLOUD_SERVICE_KEY | base64 -d > ${HOME}/<MyGoogleServiceAccountJsonFile.json>
      export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>"
      gcloud auth activate-service-account --key-file ${GOOGLE_APPLICATION_CREDENTIALS}
      # Use sudo -E to retain environment variables
      sudo -E ./<RunJob.sh>

Solution 2: Explicitly Pass Credentials to the Sudo Context

If you don’t want to use sudo -E for security reasons, you can directly inject the credential path into the sudo command’s environment:

- run:
    name: <MyJob>
    command: |
      apt-get install -y docker
      cd $(pwd)/path/to/jobcode
      echo $GCLOUD_SERVICE_KEY | base64 -d > ${HOME}/<MyGoogleServiceAccountJsonFile.json>
      export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>"
      gcloud auth activate-service-account --key-file ${GOOGLE_APPLICATION_CREDENTIALS}
      # Explicitly set the variable for the sudo process
      sudo GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} ./<RunJob.sh>

Alternatively, you can update your RunJob.sh to load credentials from a fixed path instead of relying on environment variables:

# Inside RunJob.sh
export GOOGLE_APPLICATION_CREDENTIALS="/home/circleci/<MyGoogleServiceAccountJsonFile.json>"
# Rest of your script that uses SOPS

Solution 3: Debug SOPS Credentials Directly

To confirm the issue is isolated to the sudo context, add a debug step to run SOPS directly before your script. This will verify if credentials are being picked up correctly without sudo:

- run:
    name: Debug SOPS Credentials
    command: |
      export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>"
      # Test decryption with SOPS verbose mode to see credential details
      sops --decrypt --verbose path/to/your/encrypted/file.yaml

If this works, you can be 100% sure the problem is with sudo stripping environment variables.


内容的提问来源于stack exchange,提问作者ltcolumb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 14:37:43