Firebase Gen 2 Cloud Function (Node.js) Fails with PERMISSION_DENIED on Secret Manager Access despite Correct IAM
06:00 28 Nov 2025

I am running a Firebase Gen 2 (Node.js) Cloud Function and attempting to access a secret from Secret Manager. Despite confirming all recommended IAM roles, the function execution fails with a PERMISSION_DENIED error when trying to access the value.

1. The Error Log (In-Function Execution)

When the function is triggered, it fails with this error, indicating the Service Account cannot access the secret's version:

Error: 7 PERMISSION_DENIED: Permission 'secretmanager.versions.access' denied for resource 'projects/PROJECT_NUMBER/secrets/SECRET_NAME/versions/4' (or it may not exist).

2. IAM Permissions (Confirmed Correct)

I have explicitly verified and confirmed the following roles are granted:

  • Role on Service Account (Project Level): The SA @appspot.gserviceaccount.com has the Secret Manager Secret Accessor role granted at the project level.

  • Role on Secret Resource: The SA @appspot.gserviceaccount.com has the Secret Manager Secret Accessor role granted directly on the SECRET_NAME secret resource itself.

  • API Status: The Secret Manager API is Enabled in the project.

3. The Code (Using @google-cloud/secret-manager client)

Note: This is the code that resulted in the PERMISSION_DENIED error during execution, indicating a potential context/credential issue with the client library in this environment.

// index.js snippet
import { SecretManagerServiceClient } from '@google-cloud/secret-manager';
// ... initialization ...

const PROJECT_NUMBER = 'PROJECT_NUMBER';
const SECRET_NAME_RESOURCE = `projects/${PROJECT_NUMBER}/secrets/SECRET_NAME/versions/4`;
const client = new SecretManagerServiceClient();

async function getOpenaiApiKey() {
    // Fails here with PERMISSION_DENIED
    const [version] = await client.accessSecretVersion({ name: SECRET_NAME_RESOURCE });
    // ...
}

Given that all IAM roles are explicitly granted on the Service Account for the correct secret resource in the same project, and the Secret Manager API is enabled, what highly specific environmental or deployment-context issue could still cause a persistent PERMISSION_DENIED error during the function's execution?

node.js google-cloud-platform google-cloud-run google-secret-manager google-cloud-scheduler