如何在Heroku上安全使用Google服务账号调用Cloud Vision API?
Secure Google Cloud Vision Authentication on Heroku (Node.js)
Absolutely! You don’t need to upload your service account key file directly to Heroku or commit it to your repo—there are two secure, practical ways to handle authentication, both keeping your credentials safe.
Recommended Method: Use Heroku Config Vars to Inject Credentials Directly
This approach avoids file handling entirely and is the cleanest option:
- First, open your Google Cloud service account JSON key file, select all the content, and copy it.
- Go to your Heroku app’s dashboard, navigate to Settings > Config Vars, and add a new variable. Name it something like
GOOGLE_APPLICATION_CREDENTIALS_JSON, then paste the full JSON content as its value. - In your Node.js code, instead of relying on a file path, parse the environment variable and pass the credentials directly to the Vision client:
const { ImageAnnotatorClient } = require('@google-cloud/vision'); // Parse the JSON from the environment variable const googleCredentials = JSON.parse(process.env.GOOGLE_APPLICATION_CREDENTIALS_JSON); const visionClient = new ImageAnnotatorClient({ credentials: googleCredentials });
The Google Cloud SDK will use these credentials directly, no file required.
Alternative: Generate a Temporary Key File at Startup
If your codebase relies on the GOOGLE_APPLICATION_CREDENTIALS environment variable pointing to a file, you can dynamically create a temporary file when your app starts (Heroku’s filesystem is ephemeral, but this works because the file is recreated on each dyno restart):
- Add your full service account JSON content to a Heroku Config Var (e.g.,
GOOGLE_SERVICE_ACCOUNT_JSON). - In your app’s entry file, write the JSON content to a temporary file and set the required environment variable before initializing the Vision client:
const fs = require('fs'); const path = require('path'); const { ImageAnnotatorClient } = require('@google-cloud/vision'); // Create a temporary file path in your app directory const tempKeyFilePath = path.join(__dirname, 'temp-gcp-key.json'); // Write the JSON content from the environment variable to the file fs.writeFileSync(tempKeyFilePath, process.env.GOOGLE_SERVICE_ACCOUNT_JSON); // Set the Google Cloud SDK's required environment variable process.env.GOOGLE_APPLICATION_CREDENTIALS = tempKeyFilePath; // Now initialize the client normally const visionClient = new ImageAnnotatorClient();
Critical Notes
- Never commit your service account JSON file to Git: Always use Heroku Config Vars for sensitive credentials.
- The first method is preferred: It’s simpler, faster, and eliminates the need for file I/O operations.
- Double-check your JSON content in Config Vars: Make sure there are no missing brackets or syntax errors when pasting.
内容的提问来源于stack exchange,提问作者tputkonen
相关产品推荐
相关产品推荐

