Skip to content

App default credentials do not work on App Engine Managed VMs. #513

Description

@theacodes

When running locally or on Google Compute Engine, app default credentials are used to provide authentication without needed to provide a private key. However, this does not work when deployed to Managed VMs.

Activity

  1. stephenplusplus commented on Apr 29, 2015

    @stephenplusplus
    Contributor

    Have you tried against master? We just started using google-auth-library, but haven't made a release yet.

  2. theacodes commented on Apr 29, 2015

    @theacodes
    Author

    Yes, this is against master. It's possible that managed VMs does not expose the service account from the underlying VM.

  3. ryanseys commented on Apr 29, 2015

    @ryanseys
    Contributor

    I think it should... I just came across this library which appears to provide that functionality (getting a token) from within Managed VMs.

  4. theacodes commented on Apr 29, 2015

    @theacodes
    Author

    This might be that the service account associated with the managed VM doesn't have the datastore scope. Investigating and will update.

  5. ryanseys commented on Apr 29, 2015

    @ryanseys
    Contributor

    Yeah they seem to be hitting the same endpoint as long as it's working as it should.

  6. theacodes commented on Apr 29, 2015

    @theacodes
    Author

    Okay. That is exactly the problem.

    • Managed VMs default service account doesn't include scopes to access datastore, pubsub, etc.
    • The .yaml config to add the scope isn't current documented (it's a beta setting)

    Once the settings are documented, we should add some documentation here around adding scopes to MVMs/GCE to allow access.

  7. ryanseys commented on Apr 29, 2015

    @ryanseys
    Contributor

    @jonparrott Thanks for investigating! Can you open a new issue and point to the docs that helped you resolve this issue so we know how to document it for our users?

  8. theacodes commented on Apr 29, 2015

    @theacodes
    Author

    It's not currently documented :( I'll create a new issue here once I get the docs published.

  9. ryanseys commented on Apr 29, 2015

    @ryanseys
    Contributor

    Okey doke! I'll reopen this to keep tracking the issue.

  10. stephenplusplus commented on Nov 23, 2015

    @stephenplusplus
    Contributor

    The .yaml config to add the scope isn't current documented (it's a beta setting)

    @jonparrott if that's documented now (?), that's probably good enough. Maybe a simple line could be added to https://github.com/GoogleCloudPlatform/gcloud-common/tree/master/authentication with something like "To enable the scopes on a managed VM, see ..."

  11. theacodes commented on Nov 23, 2015

    @theacodes
    Author

    This is a non-issue now, as all the requisite scopes for GCP APIs are now defaulted in MVMs. Users should never have to change the scopes. If they do, I consider that that's a bug on our end.

  12. 31 remaining items

  13. added a commit that references this issue on Feb 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

status: blockedResolving the issue is dependent on other work.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions