【发布时间】:2020-07-18 16:08:58
【问题描述】:
我正在尝试从在自定义容器中运行的 AI Platform Training 作业访问存储在 Google Secret Manager 中的机密。我正在使用以下 Python 代码来检索机密:
# Standard library imports
import os
# Import the Secret Manager client library.
from google.cloud import secretmanager
def access_secret_version(secret_id, version_id, project_id=os.environ.get("GCP_PROJECT")):
# Create the Secret Manager client.
client = secretmanager.SecretManagerServiceClient()
# Build the resource name of the secret version.
name = client.secret_version_path(project_id, secret_id, version_id)
# Access the secret version.
response = client.access_secret_version(name)
# Return the secret payload.
return response.payload.data.decode("UTF-8")
我已将Secret Manager Secret Accessor 角色添加到默认的 Cloud ML 服务帐户 (service-XXX@cloud-ml.google.com.iam.gserviceaccount.com),但访问仍然被拒绝:
google.api_core.exceptions.PermissionDenied: 403 Request had insufficient authentication scopes.
我是否将正确的角色授予了正确的服务帐户,或者我遗漏了其他内容?
【问题讨论】: