You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已部署的GAE实例无权限访问Google Secrets Manager

问题

已在GAE实例部署apollo-server-express,但实例无法从Google Secrets Manager获取密钥,日志报错:

Error: 7 PERMISSION_DENIED: The caller does not have permission

本地环境通过google-service-key.json使用具备Secrets Access、SQL Client角色的自定义服务账号可正常运行,但部署到GAE后,应用使用admin.credentials.applicationDefault()认证,默认凭据权限不足。

相关代码(index.ts):

// @note `SECRET_NAMES` is a comma separated string of the secrets' paths
const secretNames = process.env.SECRET_NAMES?.split(',') ?? []
for (const secretName of secretNames) {
  // @note `loadSecret` will use Google Secrets Manager SDK to download the payload
  // @note `secretName` is the fully qualified path to the secret located in Google Secret Manager API
  Object.assign(process.env, await loadSecret(secretName))
}

app.yml配置:

runtime: nodejs16
service: <service-name>
instance_class: F1
env_variables:
  SECRET_NAMES: '<path-1>/versions/latest,<path-2>/versions/latest'
解决方案

GAE实例默认使用App Engine默认服务账号(格式为[你的项目ID]@appspot.gserviceaccount.com),这个账号的权限和你本地用的自定义服务账号完全独立,需单独配置权限:

  1. 打开GCP控制台的IAM与管理员页面,找到该默认服务账号。
  2. 点击账号右侧的编辑按钮,添加以下必要角色:
    • Secret Manager Secret Accessor:用于获取Secret Manager密钥
    • Cloud SQL Client:如果应用需要访问Cloud SQL则添加
  3. 保存权限配置后,重新部署GAE应用或重启实例,即可解决权限不足问题。

内容的提问来源于stack exchange,提问作者matabeitt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 10:33:59