Google Cloud Auth Verification

作者 gemini-cli-extensions2df10e25bbf7Apache-2.0215 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Mandatory Step 0 pre-flight execution order and authentication verification for Google Cloud Platform (GCP), Application Default Credentials (ADC), gcloud CLI, Spark, Dataproc, BigQuery, GCS, and notebook runtimes. Use whenever interacting with GCP resources, running Spark/PySpark pipelines, BigQuery queries, GCS paths (gs://), or creating/running notebooks.

僅含說明

Google Cloud Authentication Guidelines

Mandatory Pre-Flight Execution & Auth Hierarchy

[!IMPORTANT] Pre-Flight Execution Priority Order: Before generating code, implementation plans, or executing tasks for any GCP or Notebook workload:

  1. Verify Shell, Script & Notebook Credentials: If shell-based commands, local Python scripts, or notebook kernels (gs://..., BigQuery, Dataproc) are required, verify credentials via bundled probe (gcloud auth list && gcloud config list) or Application Default Credentials (ADC).
  2. Distinguish Authentication vs. IAM Permissions:
    • If gcloud auth list returns No credentialed accounts, HARD STOP immediately and instruct the user to run gcloud auth login and gcloud auth application-default login.
    • If Python throws google.auth.exceptions.DefaultCredentialsError, explicitly direct the user to run gcloud auth application-default login.
    • If gcloud auth list shows an active credentialed account but a BigQuery/GCP call returns 403 Forbidden: Access Denied, DO NOT tell the user to log in again with gcloud auth login. Diagnose missing IAM roles (e.g., roles/bigquery.dataEditor) on the active account.
  3. HARD STOP if Unauthenticated: If no active GCP credentials or valid gcloud authentication are detected, STOP IMMEDIATELY. Prompt the user to run gcloud auth login and gcloud auth application-default login. Do NOT attempt local virtualenv creation, package installation, or local binary/JDK setup loops as workarounds.

Common Error Messages

  1. gcloud/bq CLI:
    • ERROR: (bq) You do not currently have an active account selected.
    • No credentialed accounts.
    • Configuration error: No account is currently active.
  2. Execution Failures (Python/Notebooks):
    • google.auth.exceptions.DefaultCredentialsError: Could not automatically determine credentials.
    • Forbidden: 403 Access Denied (when it's clearly an auth issue).

Verification Step

Before asking the user to log in, independently verify authentication status using a single bundled probe command:

bash
gcloud auth list --format="json" && gcloud config list --format="json"
  • If the output contains No credentialed accounts. or missing active account, proceed to Corrective Action.
  • If an account is listed but the user still receives a 403 Access Denied error, the issue is likely IAM permissions (e.g., missing BigQuery roles) on their active account, rather than missing authentication. In this case, investigate permissions rather than asking them to log in again.

Corrective Action

When missing credentials are confirmed, DO NOT attempt to fix credentials via code or local virtualenv workarounds. Credentials must be established by the user.

Stop and ask the user to run the following commands in their terminal:

  1. To authenticate the gcloud CLI: gcloud auth login
  2. To set up Application Default Credentials (ADC) (required for BQ CLI AND most libraries/notebooks): gcloud auth application-default login

Post-Login Verification

After the user confirms they have logged in, verify with: gcloud auth list Then proceed with the original task.

來源與署名

來源:gemini-cli-extensions/data-agent-kit-starter-pack位於skills/google-cloud-auth-verification提交2df10e2

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 gemini-cli-extensions/data-agent-kit-starter-pack 的技能

Schema Mapping

gemini-cli-extensions

為 ETL、ELT 或資料整合任務規劃來源到目標的結構描述對應,產出文件化的對應宣言。

Data & Analytics215今天更新

Resolving Mcp Region Configs

gemini-cli-extensions

修復區域性 Google Cloud MCP 伺服器設定中未取代的區域佔位符,讓缺少的 MCP 工具得以註冊。

DevOps & Cloud215今天更新

Notebook Guidance

gemini-cli-extensions

This skill guides the use of Jupyter notebooks for data analysis, exploration, and visualization, particularly with BigQuery. It outlines best practices for notebook execution and validation (supporting both cell-by-cell execution and full notebook generation depending on tool availability), library installation, and structuring notebooks for clarity. It also covers specific rules for data cleaning, plotting, and integrating with BigQuery SQL and machine learning workflows. Relevant when any of the following conditions are true: 1. The user request involves a data analysis, data exploration, data visualization, or data insights task that requires multiple steps, queries, or visualizations to answer. 2. The user explicitly requests a notebook (.ipynb). 3. You are creating, editing, or executing cells in a Jupyter notebook. 4. You need to query BigQuery from within a notebook. DO NOT use the Python BigQuery client library; instead, you MUST use the `%%bqsql` magics explained in this skill.

待分類215今天更新

Ml Best Practices

gemini-cli-extensions

為機器學習筆記本提供逐步方案,涵蓋分群、預測、分類、迴歸與模型比較。

Data & Analytics215今天更新

Managing Python Dependencies

gemini-cli-extensions

指導代理偵測 Python 專案的相依性管理器並正確安裝套件,而不是使用全域 pip。

Software Development215今天更新

Google Cloud Storage Fuse

gemini-cli-extensions

Mounts Cloud Storage buckets as a POSIX file system with Cloud Storage FUSE (gcsfuse). Use when you need to interact with gcsfuse — decide whether FUSE, native gs:// reads, or Filestore/Managed Lustre fits a workload, deploy tuned mounts on GKE, Compute Engine, or Cloud Run, enable and size the file, stat, and list caches, tune mount flags or config-file settings, apply workload profiles, keep ML checkpointing safe (rename atomicity, hierarchical namespace, close-time finalization, concurrent writers), or diagnose slow training, low throughput, or GCS bill spikes on existing mounts with gcsfuse metrics. Covers mount semantics, the gcsfuse CLI and config file, the GKE gcsfuse CSI driver (Workload Identity principal:// bindings, profile StorageClasses, sidecar sizing), and Cloud Run volume mounts. Don't use for bucket administration or data management without a mount (google-cloud-storage-basics) or for fully POSIX-compliant shared file systems (Filestore, Managed Lustre).

待分類215今天更新