Written from an actual first-time setup on a second machine, in order,
including every wall that was hit and the exact click-path past it: the
two authentication methods, the two separate (legacy + managed)
organization policies that can block service account key creation, the
Vertex AI User role requirement, and a troubleshooting table mapping each
literal error message we saw to its real cause.
Leads with the one fact that caused most of the confusion: none of this
setup travels with git pull. Every machine running MaskanX needs it done
locally, once, even with identical code.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>