Recover package and cloud access
Diagnose the specific denied operation under the intended machine identity. Do not broaden permissions or copy Mac credentials as a shortcut.
Diagnose
Section titled “Diagnose”For Google, inspect the active account name and configured project only; avoid printing access tokens or credential JSON. Confirm the configured ADC path exists and uses the worker key. File presence does not prove permissions. Identify the service, resource, method and redacted denial message.
For npm registry failures, check the expected @spotai registry and token expiry. registry-auth.sh is a reference helper preserved from setup outputs, not part of the active deployment allowlist; review it and its environment prerequisite before use. For GitHub, distinguish authentication failures from Git author/signature configuration.
Repair
Section titled “Repair”An expired registry token can be refreshed through the existing worker identity. An expired native agent session requires its own interactive sign-in, not credential copying. Do not invoke a paid agent prompt merely to test authentication.
A missing Google permission is handled by the existing Terraform/RBAC owner: identify the exact workflow, prefer a narrowly scoped standard role, review/apply the change and rerun the same operation. Usually no new key is needed. Build monitoring and Kubernetes debugging have deliberate limits; do not substitute project-wide Viewer/Admin grants.
Verify and escalate
Section titled “Verify and escalate”Retry the failed non-destructive operation. Avoid consuming shared production subscriptions, changing production data or testing destructive denial paths. Direct restrictions do not eliminate indirect capabilities inside an authorized pod exec session. Browser consent uses the browser workflow; it is not a Google service-account issue.