Google Cloud Platform:GCP虚拟机个人凭据存储与删除问询
Hey there, let's break this down clearly for you since you're juggling service accounts and credential storage on your VM. I’ve dealt with this exact scenario countless times, so here’s what you need to know to get sorted:
一、VM上会存储哪些凭据?
There are three main types of credentials you might find on your VM tied to service accounts:
- 手动配置的服务账号密钥文件: A JSON file containing core auth details like
client_id,private_key, andclient_email. You’d upload this manually if your app needs direct, long-term access to cloud APIs. - SDK/CLI缓存的凭据: Tools like the gcloud CLI or language-specific SDKs (Python, Java, etc.) cache short-lived access tokens and auth data locally to avoid repeatedly hitting the metadata server.
- 元数据服务器临时凭据: If your VM is linked to a service account, it pulls short-lived (1-hour default) access/ID tokens from the metadata server (
http://metadata.google.internal). These are stored only in memory—never persisted to disk—so they’re gone when the VM restarts.
二、具体存储位置在哪里?
1. 手动上传的密钥文件
This is entirely up to where you placed it! Common spots include:
- Your user home directory (e.g.,
/home/your-username/service-key.json) - System-level config folders like
/etc/or/opt/ - App-specific directories
Pro tip: If you can’t track it down, run this command to search the entire filesystem:
find / -name "*.json" -type f | grep -i service
2. SDK/CLI cached credentials
- gcloud CLI: Credentials are stored in a SQLite database and token cache under your user’s config directory:
~/.config/gcloud/credentials.db(stores account details)~/.config/gcloud/access_tokens.db(stores short-lived tokens)
- Application Default Credentials (ADC): For SDKs that use ADC, the cached JSON file lives at:
- Linux/macOS:
~/.config/gcloud/application_default_credentials.json
- Linux/macOS:
3. Metadata server credentials
As mentioned earlier, these never hit the disk—you don’t need to worry about finding or deleting them, since they vanish when the VM restarts.
三、如何删除这些凭据?
1. Delete manual service account key files
Just use the standard rm command once you’ve found the path:
rm /path/to/your/service-account-key.json
If it’s a system-owned file, add sudo:
sudo rm /etc/service-keys/production-key.json
2. Clear gcloud CLI cached credentials
- Revoke all cached credentials (this logs you out of all gcloud accounts on the VM):
gcloud auth revoke --all
- Or revoke only a specific service account:
gcloud auth revoke your-service-account@your-project.iam.gserviceaccount.com
- For a full reset (deletes all gcloud configs, not just credentials):
rm -rf ~/.config/gcloud/
3. Delete Application Default Credentials (ADC)
Simply remove the cached JSON file:
rm ~/.config/gcloud/application_default_credentials.json
四、Important Notes
- Before deleting any credentials, make sure you’ve updated your apps to use new credentials or stopped services that depend on them—otherwise, you’ll trigger auth failures and downtime.
- If your VM is linked to a service account via the cloud console, deleting local cached tokens won’t stop the VM from pulling new ones. To fully cut that link, you need to unassign the service account from the VM in your cloud provider’s console.
内容的提问来源于stack exchange,提问作者drjrm3

