Compute Engine Metadata server unavailable (gcloud ADC off GCP)
Fixes ADC failures on machines outside Google Cloud where code expects the GCE metadata server. Use when the error mentions the metadata server being unavailable or failing to retrieve credentials from it. The fix is providing real credentials via GOOGLE_APPLICATION_CREDENTIALS or gcloud auth application-default login. Not for on-GCP metadata issues.
Your code is looking for the Google metadata server, which only exists on Google Cloud VMs. You are running off-GCP, so supply credentials explicitly: gcloud auth application-default login for local dev, or GOOGLE_APPLICATION_CREDENTIALS pointing at a service-account key for servers.
google.auth.exceptions.DefaultCredentialsError: Failed to retrieve http://YOUR-METADATA-HOST/computeMetadata/v1/instance/service-accounts/default/ from the Google Compute Engine metadata service. Compute Engine Metadata server unavailableFix
- For local development:
gcloud auth application-default loginExpected: ADC file written; the app stops probing the metadata server.
- For servers, containers, CI:
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account-key.jsonExpected: the library reads the key file first and never touches the metadata server.
- Confirm which path your app takes by checking the env var is visible to the process:
python3 -c "import os; print(os.environ.get('GOOGLE_APPLICATION_CREDENTIALS'))"Expected: the key path prints. If it prints None, the export did not reach the process.
When this applies
- The error names the instance metadata server or the Compute Engine metadata service.
- Code runs on a laptop, on-prem server, non-GCP cloud, or a container without GCP credentials mounted.
When it does NOT apply
- Running ON GCE/GKE/Cloud Run and still failing: the VM likely has no service account attached or scopes are
cloud-platformdisabled; check the instance config. Could not automatically determine credentialswithout metadata-server wording: same fix family, but check the env var path first.
Compatibility
- google-auth libraries (Python, Node, Go, Java); Google Cloud SDK.
Why it happens
ADC tries sources in order and the metadata server is the last resort. Code written and tested on GCP silently depends on it; moved off GCP, the HTTP probe to the metadata IP fails and the library reports this instead of a clearer 'no credentials configured'.
Edge cases
- Some sandboxes block the metadata IP; the error then appears even on GCP. Allow traffic to the instance metadata endpoint or attach credentials explicitly.
- GKE Workload Identity: pods without the annotation fall back to the node metadata server and get the node's identity, which is usually wrong. Annotate the service account.
- Never copy a key file into a container image layer; mount it at runtime or use workload identity federation.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.