Repository navigation
Issue with auth and Docker GCE VM instance #815
Description
Activity
Thanks for sharing! Is there a time stamp when that was filed? Also would be great to get the reporter here for further questions.
All that should be required in GCE is a project ID. If this is managed VMs, authentication is manual. It's been a while since I've dug into this though, perhaps things have changed. I'll try to look into this soon.
Oh you're right, time of file was Dec 1, 2014 :( This might be obsolete.
I've learned a few things while digging into this. I used a new GCE vm with all scopes enabled.
We have a bug with how we instantiate Datastore (PR coming soon)fixed- From GCE, getting a bearer token from the google auth library is successful
- Making requests to the Storage API works
- Making requests to the Datastore API does not work
Here's my app: http://130.211.180.58:8080/
Here's a detailed view of the failed Datastore API request.
var query = dataset.createQuery(["Users"]) dataset.runQuery(query, function() {...});
Which makes the request:
{ method: 'POST', uri: 'https://www.googleapis.com/datastore/v1beta2/datasets/nth-circlet-705/runQuery', headers: { 'Content-Type': 'application/x-protobuf', Authorization: 'Bearer ya29....', // same token that works with Storage calls 'User-Agent': 'gcloud-node/0.20.0', 'Content-Length': 13 } }And responds with:
{ statusCode: 401, body: undefined, headers: { vary: 'X-Origin, Origin,Accept-Encoding', 'www-authenticate': 'Bearer realm="https://accounts.google.com/", error=invalid_token', 'content-type': 'text/html; charset=UTF-8', date: 'Wed, 02 Sep 2015 17:50:38 GMT', expires: 'Wed, 02 Sep 2015 17:50:38 GMT', 'cache-control': 'private, max-age=0', 'x-content-type-options': 'nosniff', 'x-frame-options': 'SAMEORIGIN', 'x-xss-protection': '1; mode=block', server: 'GSE', 'alternate-protocol': '443:quic,p=1', 'alt-svc': 'quic=":443"; p="1"; ma=604800', 'accept-ranges': 'none', connection: 'close' }// @jgeewax not sure where to go from here.
From @jonparrott (thanks!):
cloud-platformdoesn't includeuserinfo.email.userinfo.emailwas just recently added to the default scopes for [managed VMs] but it will be a few weeks before it hits prod. In the meantime, add the scopes to your app.yaml like this: https://github.com/GoogleCloudPlatform/nodejs-getting-started/blob/2-structured-data/app.yamlShould be in production now, verified last week. :)
Actually, this only applies for MVMs. GCE instances will still need to explicitly request userinfo.email until datastore v1beta3. example
Sweet, thanks for the info!
4 remaining items
- added 6 commits that reference this issue
on Jan 27, 2026 - added 2 commits that reference this issue
on Feb 24, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 11, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on May 5, 2026
From an internal bug report:
--- SNIP ---
I tried to use gcloud-node from a Node application running inside of a docker container on a GCE container-optimized VM instance. I expected authentication to work automatically given the README (https://github.com/GoogleCloudPlatform/gcloud-node#on-google-compute-engine) but it didn't work.
What did you expect to happen?
gcloud-node should work inside docker containers on GCE container-optimized VM instances (or the README should be updated to specify cases in which authentication doesn't work automatically on GCE)
--- SNIP ---