【发布时间】:2020-12-20 04:05:41
【问题描述】:
我想在一个新建项目中创建 Bigquery 和 Cloud SQL(MySQL 5.7) 之间的连接! (不在现有项目中,我可以在现有项目中创建连接没有问题)
这是我使用的命令
bq mk --connection --connection_type='CLOUD_SQL' --properties='{"instanceId":"<PROJECT ID>:<REGION>:<MYSQL INSTANCE>","database":"<MY DATABASE>","type":"MYSQL"}' --connection_credential='{"username":"root", "password":"<PASSWORD>"}' --project_id=<PROJECT ID> --location=<REGION> <MYSQL INSTANCE>
但我收到如下错误
BigQuery error in mk operation: Access Denied: URI: services/bigqueryconnection.googleapis.com/projects/<PROJECT ID>:
APPLICATION_ERROR;google.api.serviceconsumermanagement.v1beta1/ServiceConsumerManagerV1Beta1.GenerateServiceIdentity;Permission denied to generate service identity for service
[bigqueryconnection.googleapis.com]
Details: [{
IAM{policy: 'serviceconsumermanagement_consumers-/000000555846b828/bigqueryconnection.googleapis.com/000000b742218216' resource: 'services/bigqueryconnection.googleapis.com/consumers/<PROJECT ID>'
permission: 'serviceconsumermanagement.consumers.generateServiceAccount'}
allowed: false auditlog: false cloudaudit: false
}]
...
...
经过大量研究,我认为问题可能是我没有这样的服务帐户,其角色名为BigQuery Connection Service agent。因为我在另一个项目中有这种服务帐号。
service-<project id>@gcp-sa-bigqueryconnection.iam.gserviceaccount.com
我真的不知道这个服务帐户是如何创建的,也许通过启用 Bigquery Connection API 服务,我将创建一个像上面这样的服务帐户。
虽然 bigquery Connection API 已经启用,但我禁用了它然后再次启用它。但仍未创建服务帐号。
有人知道这个问题吗?非常感谢。
更新:
对不起,我忘了说我已经拥有 bigquery Admin/bigquery 连接 admin/cloud sql admin 权限
【问题讨论】:
标签: google-cloud-platform google-bigquery google-cloud-sql