CircleCI本地作业中SOPS无法通过GCP KMS解密文件求助
I get it—you’ve got a working service account that decrypts SOPS files locally, but when running the same setup in a local CircleCI job with the google/cloud-sdk:latest image, it’s throwing a "could not find default credentials" error. Even though you’ve verified the service account is activated, the credential file is valid, and the environment variable is set correctly, something’s still off. Let’s break this down and fix it.
Root Cause: Sudo Resets Environment Variables
The biggest clue here is that you’re running your script with sudo ./<RunJob.sh>. By default, sudo strips almost all environment variables from the new process context—including the GOOGLE_APPLICATION_CREDENTIALS you set earlier. That’s why SOPS can’t find the credentials, even though everything checks out right before running the script.
Solution 1: Use sudo -E to Preserve Environment Variables
The simplest fix is to pass your current environment to the sudo session using the -E flag. This keeps variables like GOOGLE_APPLICATION_CREDENTIALS intact for the script running under sudo:
- run: name: <MyJob> command: | apt-get install -y docker # The google/cloud-sdk image already includes sudo, so this line is unnecessary # apt-get install -y sudo cd $(pwd)/path/to/jobcode echo $GCLOUD_SERVICE_KEY | base64 -d > ${HOME}/<MyGoogleServiceAccountJsonFile.json> export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>" gcloud auth activate-service-account --key-file ${GOOGLE_APPLICATION_CREDENTIALS} # Use sudo -E to retain environment variables sudo -E ./<RunJob.sh>
Solution 2: Explicitly Pass Credentials to the Sudo Context
If you don’t want to use sudo -E for security reasons, you can directly inject the credential path into the sudo command’s environment:
- run: name: <MyJob> command: | apt-get install -y docker cd $(pwd)/path/to/jobcode echo $GCLOUD_SERVICE_KEY | base64 -d > ${HOME}/<MyGoogleServiceAccountJsonFile.json> export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>" gcloud auth activate-service-account --key-file ${GOOGLE_APPLICATION_CREDENTIALS} # Explicitly set the variable for the sudo process sudo GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} ./<RunJob.sh>
Alternatively, you can update your RunJob.sh to load credentials from a fixed path instead of relying on environment variables:
# Inside RunJob.sh export GOOGLE_APPLICATION_CREDENTIALS="/home/circleci/<MyGoogleServiceAccountJsonFile.json>" # Rest of your script that uses SOPS
Solution 3: Debug SOPS Credentials Directly
To confirm the issue is isolated to the sudo context, add a debug step to run SOPS directly before your script. This will verify if credentials are being picked up correctly without sudo:
- run: name: Debug SOPS Credentials command: | export GOOGLE_APPLICATION_CREDENTIALS="${HOME}/<MyGoogleServiceAccountJsonFile.json>" # Test decryption with SOPS verbose mode to see credential details sops --decrypt --verbose path/to/your/encrypted/file.yaml
If this works, you can be 100% sure the problem is with sudo stripping environment variables.
内容的提问来源于stack exchange,提问作者ltcolumb

