I am running a Firebase Gen 2 (Node.js) Cloud Function and attempting to access a secret from Secret Manager. Despite confirming all recommended IAM roles, the function execution fails with a PERMISSION_DENIED error when trying to access the value.
1. The Error Log (In-Function Execution)
When the function is triggered, it fails with this error, indicating the Service Account cannot access the secret's version:
Error: 7 PERMISSION_DENIED: Permission 'secretmanager.versions.access' denied for resource 'projects/PROJECT_NUMBER/secrets/SECRET_NAME/versions/4' (or it may not exist).
2. IAM Permissions (Confirmed Correct)
I have explicitly verified and confirmed the following roles are granted:
Role on Service Account (Project Level): The SA
has the@appspot.gserviceaccount.com Secret Manager Secret Accessorrole granted at the project level.Role on Secret Resource: The SA
has the@appspot.gserviceaccount.com Secret Manager Secret Accessorrole granted directly on theSECRET_NAMEsecret resource itself.API Status: The Secret Manager API is Enabled in the project.
3. The Code (Using @google-cloud/secret-manager client)
Note: This is the code that resulted in the PERMISSION_DENIED error during execution, indicating a potential context/credential issue with the client library in this environment.
// index.js snippet
import { SecretManagerServiceClient } from '@google-cloud/secret-manager';
// ... initialization ...
const PROJECT_NUMBER = 'PROJECT_NUMBER';
const SECRET_NAME_RESOURCE = `projects/${PROJECT_NUMBER}/secrets/SECRET_NAME/versions/4`;
const client = new SecretManagerServiceClient();
async function getOpenaiApiKey() {
// Fails here with PERMISSION_DENIED
const [version] = await client.accessSecretVersion({ name: SECRET_NAME_RESOURCE });
// ...
}
Given that all IAM roles are explicitly granted on the Service Account for the correct secret resource in the same project, and the Secret Manager API is enabled, what highly specific environmental or deployment-context issue could still cause a persistent PERMISSION_DENIED error during the function's execution?