Your code is looking for the Google metadata server, which only exists on Google Cloud VMs. You are running off-GCP, so supply credentials explicitly: `gcloud auth application-default login` for local dev, or `GOOGLE_APPLICATION_CREDENTIALS` pointing at a service-account key for servers.

```text
google.auth.exceptions.DefaultCredentialsError: Failed to retrieve http://YOUR-METADATA-HOST/computeMetadata/v1/instance/service-accounts/default/ from the Google Compute Engine metadata service. Compute Engine Metadata server unavailable
```

## Fix

1. For local development:
   ```bash
   gcloud auth application-default login
   ```
   Expected: ADC file written; the app stops probing the metadata server.

2. For servers, containers, CI:
   ```bash
   export GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account-key.json
   ```
   Expected: the library reads the key file first and never touches the metadata server.

3. Confirm which path your app takes by checking the env var is visible to the process:
   ```bash
   python3 -c "import os; print(os.environ.get('GOOGLE_APPLICATION_CREDENTIALS'))"
   ```
   Expected: the key path prints. If it prints None, the export did not reach the process.

## When this applies
- The error names the instance metadata server or the Compute Engine metadata service.
- Code runs on a laptop, on-prem server, non-GCP cloud, or a container without GCP credentials mounted.

## When it does NOT apply
- Running ON GCE/GKE/Cloud Run and still failing: the VM likely has no service account attached or scopes are `cloud-platform` disabled; check the instance config.
- `Could not automatically determine credentials` without metadata-server wording: same fix family, but check the env var path first.

## Compatibility
- google-auth libraries (Python, Node, Go, Java); Google Cloud SDK.

## Why it happens
ADC tries sources in order and the metadata server is the last resort. Code written and tested on GCP silently depends on it; moved off GCP, the HTTP probe to the metadata IP fails and the library reports this instead of a clearer 'no credentials configured'.

## Edge cases
- Some sandboxes block the metadata IP; the error then appears even on GCP. Allow traffic to the instance metadata endpoint or attach credentials explicitly.
- GKE Workload Identity: pods without the annotation fall back to the node metadata server and get the node's identity, which is usually wrong. Annotate the service account.
- Never copy a key file into a container image layer; mount it at runtime or use workload identity federation.