How to get GS_SECRET_ACCESS_KEY and GS_ACCESS_KEY_ID in google cloud storage

Viewed 2024

I try to read data from public google cloud storage (https://console.cloud.google.com/storage/browser/gcp-public-data-landsat) with Landsat images.

I use for it Python3 with GDAL. But I have an error

ERROR 15: GS_SECRET_ACCESS_KEY+GS_ACCESS_KEY_ID, GS_OAUTH2_REFRESH_TOKEN or GOOGLE_APPLICATION_CREDENTIALS or GS_OAUTH2_PRIVATE_KEY+GS_OAUTH2_CLIENT_EMAIL configuration options and /home/qwerty/.boto not defined

How can I get GS_SECRET_ACCESS_KEY and GS_ACCESS_KEY_ID ?

2 Answers

gs_access_key_id and gs_secret_access_key can be generated by

1.navigating to your Google Cloud Storage console and clicking on Settings.

2.on the Settings page, navigate to the Interoperability tab.

3.on this page you can now choose a service account and click Create a new key to generate an access key and a matching secret.

Output:

New service account HMAC key
service-account@project.iam.gserviceaccount.com
Access key  
xxxxxxxxxxxxxxxxxxx
Secret  
xxxxxxxxxxxxxxxxxxx
Copy this key's secret if you'll need it in the future. Once you close this dialog, the secret can't be recovered.

An alternative authentication approach to reading and optionally writing GeoTIF in GCS.

In CGP Console

  • Create a Service Account and download a JSON keyfile. Keep it safe.
  • On the Storage Bucket browser, Permission tab, give the new Service Account Roles for:
    • Storage Legacy Bucket Owner and
    • Storage Legacy Bucket Reader
    • path_to_credentials points to your key file
    GEOTIF_PATH = "/vsigs/<my-bucket>/<objectname>"

    with rasterio.Env(GOOGLE_APPLICATION_CREDENTIALS=path_to_credentials):
        with rasterio.open('{}'.format(GEOTIF_PATH)) as src:
            print(src.width, src.height)
            profile = src.profile
            print(profile)

However, sometimes I am unable to open a file that I think should be openable. Also, if the path is incorrect, like including "gs://" or missing the /vsigs, I get this error:

CPLE_NotSupportedError: CPLRSASHA256Sign() not implemented: GDAL must be built against libcrypto++ or libcrypto (openssl)

But that can't be right or it wouldn't work at all? However, restarting the jupyter notebook seemed to clear it up.

I am running GDAL 2.3.3, released 2018/12/14, Python 3.7.11 on Windows.

Related