You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何无需服务账号访问密钥实现Cloud Run与Firestore认证连接

无需服务账号密钥连接Cloud Run到Firestore(Node.js)

核心思路

Cloud Run 运行的容器会自动关联一个GCP服务账号(默认是项目的App Engine服务账号),通过给这个账号配置Firestore权限,结合Google Cloud SDK的Application Default Credentials (ADC),就能无需手动配置密钥文件实现连接。

步骤1:配置Cloud Run服务账号的Firestore权限

  • 找到你的Cloud Run服务使用的服务账号:
    • 默认服务账号格式:[你的项目ID]@appspot.gserviceaccount.com
    • 如果用了自定义服务账号,直接用对应的账号邮箱
  • 进入GCP控制台的IAM页面,给该服务账号添加Firestore相关角色:
    • 基础读写用 Cloud Datastore User(兼容Firestore)
    • 更细粒度权限可选 Firestore Editor(读写)或 Firestore Reader(只读)

步骤2:Node.js代码实现(无需密钥)

使用官方@google-cloud/firestore SDK,ADC会自动在Cloud Run环境中获取凭据:

  1. 安装依赖:
npm install @google-cloud/firestore
  1. 初始化Firestore客户端(无需指定密钥路径):
const { Firestore } = require('@google-cloud/firestore');

// ADC会自动获取Cloud Run服务账号的凭据,无需手动传入密钥
const db = new Firestore({
  projectId: '你的GCP项目ID' // 可省略,ADC会自动检测当前项目
});

// 示例:读取Firestore文档
async function fetchDocument() {
  try {
    const docSnapshot = await db.collection('your-collection').doc('your-doc-id').get();
    if (docSnapshot.exists) {
      console.log('文档内容:', docSnapshot.data());
    } else {
      console.log('指定文档不存在');
    }
  } catch (err) {
    console.error('操作失败:', err);
  }
}

fetchDocument();

关键说明

  • 本地开发时:ADC会优先使用gcloud auth application-default login登录的账号,或者GOOGLE_APPLICATION_CREDENTIALS环境变量指定的密钥文件(这就是你之前本地配置的方式)
  • Cloud Run部署后:ADC会自动使用服务账号的临时凭据,无需任何密钥文件或额外环境变量
  • 确保部署Cloud Run时不要设置GOOGLE_APPLICATION_CREDENTIALS环境变量,避免覆盖自动凭据获取逻辑

内容的提问来源于stack exchange,提问作者actuallyatiger

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 02:41:56