本地使用gcloud SDK访问Firebase项目遇PERMISSION_DENIED问题求助
问题描述
我用Node.js开发后端微服务,搭配@google-cloud/firestore,通过gcloud SDK本地访问Firebase项目。已执行gcloud init完成登录并选中目标项目,但操作数据库时始终收到7 PERMISSION_DENIED: Missing or insufficient permissions错误。
我确认当前账号在项目中拥有全部权限,但发现给首次安装SDK时添加的旧账号赋予权限后,就能正常访问数据库——推测SDK始终在使用这个旧账号,而非当前登录的账号。
尝试过删除SDK所有账号、删除配置列表、两次卸载重装SDK、重新执行gcloud init登录等操作,问题依旧。
补充信息
Firestore连接代码
import 'reflect-metadata'; import { Firestore } from '@google-cloud/firestore'; import { GCP_PROJECT } from '@util'; export const firestore = new Firestore({ projectId: GCP_PROJECT });
gcloud init配置流程
-> gcloud init Welcome! This command will take you through the configuration of gcloud. Settings from your current configuration [coordinadora-work] are: core: account: diego.cifuentes@coordinadora.com disable_usage_reporting: 'True' project: cm-reparto-dev Pick configuration to use: [1] Re-initialize this configuration [coordinadora-work] with new settings [2] Create a new configuration Please enter your numeric choice: 1 Your current configuration has been set to: [coordinadora-work] You can skip diagnostics next time by using the following flag: gcloud init --skip-diagnostics Network diagnostic detects and fixes local network connection issues. Checking network connection...done. Reachability Check passed. Network diagnostic passed (1/1 checks passed). Choose the account you would like to use to perform operations for this configuration: [1] diego.cifuentes@coordinadora.com [2] Log in with a new account -> Please enter your numeric choice: 1 You are logged in as: [...my account that is having problems...]. Pick cloud project to use: ... -> Please enter numeric choice or text value (must exactly match list item): 21 Your current project has been set to: [...project that i'm having problems with...]. -> Do you want to configure a default Compute Region and Zone? (Y/n)? n Your Google Cloud SDK is configured and ready to use!
解决方法
- 检查环境变量优先级:Google Cloud客户端库会优先读取
GOOGLE_APPLICATION_CREDENTIALS环境变量,若该变量指向旧账号的密钥文件,会直接绕过gcloud配置。执行echo $GOOGLE_APPLICATION_CREDENTIALS查看变量是否存在,若有则删除或修改为当前账号的密钥路径。 - 重置应用默认凭据:执行
gcloud auth application-default login,重新生成应用默认凭据,覆盖旧的缓存文件。此命令生成的凭据会被@google-cloud/firestore优先使用(无环境变量时)。 - 代码中指定凭据路径:直接在Firestore初始化代码里指定当前账号的密钥文件,强制使用正确身份:
export const firestore = new Firestore({ projectId: GCP_PROJECT, keyFilename: '/path/to/your/current-account-key.json' }); - 清理旧凭据缓存:手动删除默认凭据存储文件,不同系统路径如下:
- macOS/Linux:
~/.config/gcloud/application_default_credentials.json - Windows:
%APPDATA%\gcloud\application_default_credentials.json
删除后重新执行gcloud auth application-default login生成新凭据。
- macOS/Linux:
- 确认gcloud活跃配置:执行
gcloud config list检查输出的account和project是否正确,若有误手动设置:gcloud config set account diego.cifuentes@coordinadora.com gcloud config set project cm-reparto-dev
内容的提问来源于stack exchange,提问作者Diego Davincci
相关产品推荐
相关产品推荐

