You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Streamlit Cloud部署Google Cloud Vision时的凭证格式与安全问题求助

解决Streamlit Cloud部署Google Cloud Vision的凭证格式冲突问题

核心思路

不用强行让Google Cloud读取.toml文件,而是通过从Streamlit Secrets加载凭证内容绕过格式限制,同时避免将敏感凭证上传到GitHub。


方案1:直接用凭证内容初始化GCP客户端(推荐)

跳过环境变量设置,直接从Streamlit Secrets读取GCP凭证并构建客户端:

  1. 准备Secrets配置
    打开你的GCP服务账号JSON凭证文件,复制全部内容。在本地项目的.streamlit/secrets.toml中添加:

    GCP_CREDENTIALS = '''
    {
      "type": "service_account",
      "project_id": "你的项目ID",
      "private_key_id": "你的私钥ID",
      "private_key": "-----BEGIN PRIVATE KEY-----\n你的私钥内容\n-----END PRIVATE KEY-----\n",
      "client_email": "你的服务账号邮箱",
      "client_id": "你的客户端ID",
      "auth_uri": "https://accounts.google.com/o/oauth2/auth",
      "token_uri": "https://oauth2.googleapis.com/token",
      "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
      "client_x509_cert_url": "你的证书URL"
    }
    '''
    
  2. 修改代码
    替换原有认证逻辑,直接加载凭证初始化客户端:

    import json
    import io
    from google.cloud import vision
    from google.oauth2 import service_account
    import streamlit as st
    
    def detect_document(path):
        # 从Streamlit Secrets加载并解析凭证
        gcp_creds_info = json.loads(st.secrets["GCP_CREDENTIALS"])
        credentials = service_account.Credentials.from_service_account_info(gcp_creds_info)
        client = vision.ImageAnnotatorClient(credentials=credentials)
    
        with io.open(path, 'rb') as image_file:
            content = image_file.read()
    
        image = vision.Image(content=content)
        # 后续的文档检测逻辑...
    

方案2:临时生成JSON文件适配环境变量

如果依赖GOOGLE_APPLICATION_CREDENTIALS环境变量的逻辑,可以通过临时文件中转:

  1. 配置Secrets
    同样在.streamlit/secrets.toml中存入完整的JSON凭证字符串:

    GOOGLE_APPLICATION_CREDENTIALS_JSON = '''
    {
      "type": "service_account",
      ... 你的完整GCP凭证内容 ...
    }
    '''
    
  2. 修改代码
    创建临时JSON文件,设置环境变量后再初始化客户端:

    import os
    import io
    import tempfile
    from google.cloud import vision
    import streamlit as st
    
    def detect_document(path):
        # 创建临时JSON文件存储凭证
        with tempfile.NamedTemporaryFile(mode='w', suffix='.json', delete=False) as temp_file:
            temp_file.write(st.secrets["GOOGLE_APPLICATION_CREDENTIALS_JSON"])
            temp_path = temp_file.name
    
        # 设置环境变量
        os.environ["GOOGLE_APPLICATION_CREDENTIALS"] = temp_path
    
        client = vision.ImageAnnotatorClient()
        with io.open(path, 'rb') as image_file:
            content = image_file.read()
    
        image = vision.Image(content=content)
        # 后续逻辑...
    
        # 清理临时文件
        os.unlink(temp_path)
    

部署注意事项

  • 本地开发时,确保.streamlit/secrets.toml被加入.gitignore,禁止上传到GitHub
  • 在Streamlit Cloud部署时,无需上传本地的secrets文件:进入项目仪表盘 → Settings → Secrets,直接粘贴上述toml格式的凭证内容即可

内容的提问来源于stack exchange,提问作者Abhi Nandan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 13:25:18