Python脚本访问GCP Pub/Sub除服务账号外可用的认证方式有哪些?
GCP Pub/Sub Python客户端无服务账号认证方案
问题描述
实操Pub/Sub客户端官方教程时,在publisher.py中调用publisher = pubsub_v1.PublisherClient()代码时报错如下:
google.auth.exceptions.DefaultCredentialsError: Could not automatically determine credentials. Please set GOOGLE_APPLICATION_CREDENTIALS or explicitly create credentials and re-run the application.
场景说明
- 所属GCP用户组已配置pubsub.publisher、pubsub.subscriber角色
- 本地设备已登录个人GCP账号,终端执行CLI命令
gcloud pubsub topics publish <topic-name> --message="help me"可正常运行 - 受部门政策限制,无权限为服务账号分配对应角色,无法创建符合要求的服务账号,需找到不依赖服务账号、直接使用用户账号IAM权限作为Python脚本认证凭证的可行方案
可行解决方案
执行以下gcloud命令即可解决该问题,无需创建服务账号:gcloud auth application-default login
该命令会生成对应用户身份的应用默认凭据,供GCP客户端库自动读取使用,完全适配本地开发时使用个人账号权限运行脚本的场景。
内容的提问来源于stack exchange,提问作者zzaebok
相关产品推荐
相关产品推荐

