Repository navigation
App default credentials do not work on App Engine Managed VMs. #513
Description
Activity
Have you tried against master? We just started using google-auth-library, but haven't made a release yet.
Yes, this is against master. It's possible that managed VMs does not expose the service account from the underlying VM.
I think it should... I just came across this library which appears to provide that functionality (getting a token) from within Managed VMs.
This might be that the service account associated with the managed VM doesn't have the datastore scope. Investigating and will update.
Yeah they seem to be hitting the same endpoint as long as it's working as it should.
Okay. That is exactly the problem.
- Managed VMs default service account doesn't include scopes to access datastore, pubsub, etc.
- The .yaml config to add the scope isn't current documented (it's a beta setting)
Once the settings are documented, we should add some documentation here around adding scopes to MVMs/GCE to allow access.
@jonparrott Thanks for investigating! Can you open a new issue and point to the docs that helped you resolve this issue so we know how to document it for our users?
It's not currently documented :( I'll create a new issue here once I get the docs published.
Okey doke! I'll reopen this to keep tracking the issue.
- addedstatus: blockedResolving the issue is dependent on other work.Resolving the issue is dependent on other work.
on Jun 30, 2015 The .yaml config to add the scope isn't current documented (it's a beta setting)
@jonparrott if that's documented now (?), that's probably good enough. Maybe a simple line could be added to https://github.com/GoogleCloudPlatform/gcloud-common/tree/master/authentication with something like "To enable the scopes on a managed VM, see ..."
This is a non-issue now, as all the requisite scopes for GCP APIs are now defaulted in MVMs. Users should never have to change the scopes. If they do, I consider that that's a bug on our end.
31 remaining items
- added a commit that references this issue
on Feb 2, 2026 - added a commit that references this issue
on Feb 3, 2026 - added a commit that references this issue
on Feb 4, 2026 - added a commit that references this issue
on Feb 25, 2026 - added a commit that references this issue
on Feb 25, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 12, 2026 - added a commit that references this issue
on Mar 18, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on May 5, 2026
When running locally or on Google Compute Engine, app default credentials are used to provide authentication without needed to provide a private key. However, this does not work when deployed to Managed VMs.