Streamlit Cloud部署Google Cloud Vision时的凭证格式与安全问题求助
解决Streamlit Cloud部署Google Cloud Vision的凭证格式冲突问题
核心思路
不用强行让Google Cloud读取.toml文件,而是通过从Streamlit Secrets加载凭证内容绕过格式限制,同时避免将敏感凭证上传到GitHub。
方案1:直接用凭证内容初始化GCP客户端(推荐)
跳过环境变量设置,直接从Streamlit Secrets读取GCP凭证并构建客户端:
准备Secrets配置
打开你的GCP服务账号JSON凭证文件,复制全部内容。在本地项目的.streamlit/secrets.toml中添加:GCP_CREDENTIALS = ''' { "type": "service_account", "project_id": "你的项目ID", "private_key_id": "你的私钥ID", "private_key": "-----BEGIN PRIVATE KEY-----\n你的私钥内容\n-----END PRIVATE KEY-----\n", "client_email": "你的服务账号邮箱", "client_id": "你的客户端ID", "auth_uri": "https://accounts.google.com/o/oauth2/auth", "token_uri": "https://oauth2.googleapis.com/token", "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs", "client_x509_cert_url": "你的证书URL" } '''修改代码
替换原有认证逻辑,直接加载凭证初始化客户端:import json import io from google.cloud import vision from google.oauth2 import service_account import streamlit as st def detect_document(path): # 从Streamlit Secrets加载并解析凭证 gcp_creds_info = json.loads(st.secrets["GCP_CREDENTIALS"]) credentials = service_account.Credentials.from_service_account_info(gcp_creds_info) client = vision.ImageAnnotatorClient(credentials=credentials) with io.open(path, 'rb') as image_file: content = image_file.read() image = vision.Image(content=content) # 后续的文档检测逻辑...
方案2:临时生成JSON文件适配环境变量
如果依赖GOOGLE_APPLICATION_CREDENTIALS环境变量的逻辑,可以通过临时文件中转:
配置Secrets
同样在.streamlit/secrets.toml中存入完整的JSON凭证字符串:GOOGLE_APPLICATION_CREDENTIALS_JSON = ''' { "type": "service_account", ... 你的完整GCP凭证内容 ... } '''修改代码
创建临时JSON文件,设置环境变量后再初始化客户端:import os import io import tempfile from google.cloud import vision import streamlit as st def detect_document(path): # 创建临时JSON文件存储凭证 with tempfile.NamedTemporaryFile(mode='w', suffix='.json', delete=False) as temp_file: temp_file.write(st.secrets["GOOGLE_APPLICATION_CREDENTIALS_JSON"]) temp_path = temp_file.name # 设置环境变量 os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = temp_path client = vision.ImageAnnotatorClient() with io.open(path, 'rb') as image_file: content = image_file.read() image = vision.Image(content=content) # 后续逻辑... # 清理临时文件 os.unlink(temp_path)
部署注意事项
- 本地开发时,确保
.streamlit/secrets.toml被加入.gitignore,禁止上传到GitHub - 在Streamlit Cloud部署时,无需上传本地的secrets文件:进入项目仪表盘 →
Settings→Secrets,直接粘贴上述toml格式的凭证内容即可
内容的提问来源于stack exchange,提问作者Abhi Nandan
相关产品推荐
相关产品推荐

