You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP中Google Colab访问Secret Manager权限丢失问题排查

解决Colab调用GCP Secret Manager的权限问题

问题重现

运行以下代码时触发权限相关报错:

client = secretmanager.SecretManagerServiceClient()
name = f"projects/my_project_here/secrets/my_secret_name_here/versions/latest"
response = client.access_secret_version(request={"name": name})

报错信息:

ERROR:grpc._plugin_wrapping:AuthMetadataPluginCallback "<google.auth.transport.grpc.AuthMetadataPlugin object at 0x7fb313b41850>" raised exception!
Traceback (most recent call last):
  File "/usr/local/lib/python3.7/dist-packages/google/auth/compute_engine/credentials.py", line 111, in refresh
    self._retrieve_info(request)
  File "/usr/local/lib/python3.7/dist-packages/google/auth/compute_engine/credentials.py", line 88, in _retrieve_info
    request, service_account=self._service_account_email
  File "/usr/local/lib/python3.7/dist-packages/google/auth/compute_engine/_metadata.py", line 234, in get_service_account_info
    return get(request, path, params={"recursive": "true"})
  File "/usr/local/lib/python3.7/dist-packages/google/auth/compute_engine/_metadata.py", line 187, in get
    response,
google.auth.exceptions.TransportError: ("Failed to retrieve http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/?recursive=true from the Google Compute Enginemetadata service. Status: 404 Response:\nb''", <google.auth.transport.requests._Response object at 0x7fb313b9c290>)

The above exception was the direct cause of the following exception:

Traceback (most recent call last):
  File "/usr/local/lib/python3.7/dist-packages/grpc/_plugin_wrapping.py", line 90, in __call__
    context, _AuthMetadataPluginCallback(callback_state, callback))
  File "/usr/local/lib/python3.7/dist-packages/google/auth/transport/grpc.py", line 101, in __call__
    callback(self._get_authorization_headers(context), None)
  File "/usr/local/lib/python3.7/dist-packages/google/auth/transport/grpc.py", line 88, in _get_authorization_headers
    self._request, context.method_name, context.service_url, headers
  File "/usr/local/lib/python3.7/dist-packages/google/auth/credentials.py", line 133, in before_request
    self.refresh(request)
  File "/usr/local/lib/python3.7/dist-packages/google/auth/compute_engine/credentials.py", line 117, in refresh
    six.raise_from(new_exc, caught_exc)
  File "<string>", line 3, in raise_from
google.auth.exceptions.RefreshError: ("Failed to retrieve http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/?recursive=true from the Google Compute Enginemetadata service. Status: 404 Response:\nb''", <google.auth.transport.requests._Response object at 0x7fb313b9c290>)

1. 查看Colab当前使用的身份

用以下两种方法确认Colab当前的认证主体:

  • 方法1:通过gcloud命令查看
    在Colab单元格中运行:

    !gcloud auth list
    

    输出中带有*标记的就是当前活跃的认证账号。

  • 方法2:通过Python代码获取详细信息
    运行以下代码,区分是用户账号还是服务账号:

    from google.auth import default
    credentials, project_id = default()
    if hasattr(credentials, 'service_account_email'):
        print(f"当前使用服务账号: {credentials.service_account_email}")
    else:
        print(f"当前使用用户账号: {credentials.id_token['email']}")
    

2. 为当前身份配置Secret Manager权限

根据获取到的身份,在GCP控制台中配置权限:

  1. 打开GCP项目的IAM页面,找到对应账号(用户邮箱或服务账号邮箱)
  2. 点击账号右侧的编辑按钮,添加Secret Manager Secret Accessor角色(角色ID:roles/secretmanager.secretAccessor)
  3. 保存变更后,回到Colab重新运行代码测试

如果之前是依赖App Engine默认服务账号(格式:[项目ID]@appspot.gserviceaccount.com),需额外确认:

  • 该服务账号是否仍存在于项目中
  • 该服务账号的Secret Manager Secret Accessor角色是否被移除

3. 权限无人工干预变更的可能原因

  • 组织级政策变更:若项目属于某个GCP组织,组织管理员可能修改了IAM继承规则,移除了相关角色权限
  • 服务账号自动清理:GCP的闲置资源清理机制可能误删了服务账号的角色,或服务账号被禁用/删除
  • Colab认证方式切换:Colab可能默认使用了临时身份(而非你之前配置的服务账号密钥),新身份未配置对应权限
  • 资源权限调整:Secret本身的权限设置被修改,或项目IAM绑定被覆盖(比如批量更新操作)
  • 角色权限范围调整:GCP极少会调整角色权限,但如果有调整可能影响现有访问(通常会提前通知)

内容的提问来源于stack exchange,提问作者Mark McGown

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 10:35:42