guillaumeblaquiere
According with my comment [here](https://dev.to/gblaquiere/comment/gfm1), the security proposed by this packaging is too weak (or even dangerous! -> There is a plain text service-account key file with owner role!) 1. The role are too wide: As described in this [page](https://firebase.google.com/docs/firestore/manage-data/export-import?utm_source=notify_mailer&utm_medium=email&utm_campaign=new_reply_email#before_you_begin) (in reply to my post), the list of role are separated by an **OR**. That's why, I only recommend to use the role `Cloud Datastore Import Export Admin` for accessing to the export feature of Firestore. (the storage admin role is to keep). The aim here is to apply the "least privilege" principle. 2. Set the JSON key file in clear in environment variable (Base64 = clear plain text, no ciphering, no security) is not recommended. Using ciphering system like [Berglas](https://github.com/GoogleCloudPlatform/berglas) (better solution), or simply using the Cloud Run identity (the best solution) are recommended