TL;DR: No application default credentials exist where your code runs. For local dev, run gcloud auth application-default login. On servers or CI, set GOOGLE_APPLICATION_CREDENTIALS to a service account key file. On GCP compute, use the attached service account.

```text
google.auth.exceptions.DefaultCredentialsError: Could not automatically determine credentials. Please set GOOGLE_APPLICATION_CREDENTIALS or explicitly create credentials and re-run the application.
```

## Fix it

1. Local dev: gcloud auth application-default login. Expected: a credentials file lands in your config dir and the error goes away.
2. Servers/CI: create a service account with the needed roles, download its JSON key, and set GOOGLE_APPLICATION_CREDENTIALS to the file path. Expected: the client authenticates on next run.
3. On GCE/GKE/Cloud Run: attach a service account to the resource instead of shipping key files. Expected: the metadata server supplies credentials automatically.
4. Verify with a trivial call, e.g. list buckets: python -c "from google.cloud import storage; print(list(storage.Client().list_buckets()))". Expected: a list, not an exception.

## When this applies
- The error is exactly DefaultCredentialsError: Could not automatically determine credentials.

## When it doesn't
- The error is 403 Forbidden: credentials work but the identity lacks IAM permission.
- The error names a missing key file: the env var points at a wrong path; fix the path.

## Compatibility
- google-auth and any google-cloud-* client; gcloud CLI for the login path.

## Why it happens
Google clients search a fixed order: explicit credentials, the env var, the well-known file from gcloud auth application-default login, then the metadata server. This error means all four came up empty.

## Edge cases
- Key files are secrets: never commit them; prefer workload identity on GCP.
- In Docker, the env var path must exist inside the container, not just on the host.
