Google Cloud Auth Verification

作者 gemini-cli-extensions2df10e25bbf7Apache-2.0215 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Mandatory Step 0 pre-flight execution order and authentication verification for Google Cloud Platform (GCP), Application Default Credentials (ADC), gcloud CLI, Spark, Dataproc, BigQuery, GCS, and notebook runtimes. Use whenever interacting with GCP resources, running Spark/PySpark pipelines, BigQuery queries, GCS paths (gs://), or creating/running notebooks.

仅含说明

Google Cloud Authentication Guidelines

Mandatory Pre-Flight Execution & Auth Hierarchy

[!IMPORTANT] Pre-Flight Execution Priority Order: Before generating code, implementation plans, or executing tasks for any GCP or Notebook workload:

  1. Verify Shell, Script & Notebook Credentials: If shell-based commands, local Python scripts, or notebook kernels (gs://..., BigQuery, Dataproc) are required, verify credentials via bundled probe (gcloud auth list && gcloud config list) or Application Default Credentials (ADC).
  2. Distinguish Authentication vs. IAM Permissions:
    • If gcloud auth list returns No credentialed accounts, HARD STOP immediately and instruct the user to run gcloud auth login and gcloud auth application-default login.
    • If Python throws google.auth.exceptions.DefaultCredentialsError, explicitly direct the user to run gcloud auth application-default login.
    • If gcloud auth list shows an active credentialed account but a BigQuery/GCP call returns 403 Forbidden: Access Denied, DO NOT tell the user to log in again with gcloud auth login. Diagnose missing IAM roles (e.g., roles/bigquery.dataEditor) on the active account.
  3. HARD STOP if Unauthenticated: If no active GCP credentials or valid gcloud authentication are detected, STOP IMMEDIATELY. Prompt the user to run gcloud auth login and gcloud auth application-default login. Do NOT attempt local virtualenv creation, package installation, or local binary/JDK setup loops as workarounds.

Common Error Messages

  1. gcloud/bq CLI:
    • ERROR: (bq) You do not currently have an active account selected.
    • No credentialed accounts.
    • Configuration error: No account is currently active.
  2. Execution Failures (Python/Notebooks):
    • google.auth.exceptions.DefaultCredentialsError: Could not automatically determine credentials.
    • Forbidden: 403 Access Denied (when it's clearly an auth issue).

Verification Step

Before asking the user to log in, independently verify authentication status using a single bundled probe command:

bash
gcloud auth list --format="json" && gcloud config list --format="json"
  • If the output contains No credentialed accounts. or missing active account, proceed to Corrective Action.
  • If an account is listed but the user still receives a 403 Access Denied error, the issue is likely IAM permissions (e.g., missing BigQuery roles) on their active account, rather than missing authentication. In this case, investigate permissions rather than asking them to log in again.

Corrective Action

When missing credentials are confirmed, DO NOT attempt to fix credentials via code or local virtualenv workarounds. Credentials must be established by the user.

Stop and ask the user to run the following commands in their terminal:

  1. To authenticate the gcloud CLI: gcloud auth login
  2. To set up Application Default Credentials (ADC) (required for BQ CLI AND most libraries/notebooks): gcloud auth application-default login

Post-Login Verification

After the user confirms they have logged in, verify with: gcloud auth list Then proceed with the original task.

来源与署名

来源:gemini-cli-extensions/data-agent-kit-starter-pack位于skills/google-cloud-auth-verification提交2df10e2

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 gemini-cli-extensions/data-agent-kit-starter-pack 的技能

Schema Mapping

gemini-cli-extensions

为 ETL、ELT 或数据集成任务规划源到目标的模式映射,产出文档化的映射宣言。

Data & Analytics215今天更新

Resolving Mcp Region Configs

gemini-cli-extensions

修复区域级 Google Cloud MCP 服务器配置中未替换的区域占位符,使缺失的 MCP 工具得以注册。

DevOps & Cloud215今天更新

Notebook Guidance

gemini-cli-extensions

This skill guides the use of Jupyter notebooks for data analysis, exploration, and visualization, particularly with BigQuery. It outlines best practices for notebook execution and validation (supporting both cell-by-cell execution and full notebook generation depending on tool availability), library installation, and structuring notebooks for clarity. It also covers specific rules for data cleaning, plotting, and integrating with BigQuery SQL and machine learning workflows. Relevant when any of the following conditions are true: 1. The user request involves a data analysis, data exploration, data visualization, or data insights task that requires multiple steps, queries, or visualizations to answer. 2. The user explicitly requests a notebook (.ipynb). 3. You are creating, editing, or executing cells in a Jupyter notebook. 4. You need to query BigQuery from within a notebook. DO NOT use the Python BigQuery client library; instead, you MUST use the `%%bqsql` magics explained in this skill.

待分类215今天更新

Ml Best Practices

gemini-cli-extensions

为机器学习笔记本提供分步方案,涵盖聚类、预测、分类、回归和模型比较。

Data & Analytics215今天更新

Managing Python Dependencies

gemini-cli-extensions

指导代理检测 Python 项目的依赖管理器并正确安装依赖,而不是使用全局 pip。

Software Development215今天更新

Google Cloud Storage Fuse

gemini-cli-extensions

Mounts Cloud Storage buckets as a POSIX file system with Cloud Storage FUSE (gcsfuse). Use when you need to interact with gcsfuse — decide whether FUSE, native gs:// reads, or Filestore/Managed Lustre fits a workload, deploy tuned mounts on GKE, Compute Engine, or Cloud Run, enable and size the file, stat, and list caches, tune mount flags or config-file settings, apply workload profiles, keep ML checkpointing safe (rename atomicity, hierarchical namespace, close-time finalization, concurrent writers), or diagnose slow training, low throughput, or GCS bill spikes on existing mounts with gcsfuse metrics. Covers mount semantics, the gcsfuse CLI and config file, the GKE gcsfuse CSI driver (Workload Identity principal:// bindings, profile StorageClasses, sidecar sizing), and Cloud Run volume mounts. Don't use for bucket administration or data management without a mount (google-cloud-storage-basics) or for fully POSIX-compliant shared file systems (Filestore, Managed Lustre).

待分类215今天更新