【问题标题】:Accessing Google Secret Manager from AI Platform training job with custom container使用自定义容器从 AI Platform 训练作业访问 Google Secret Manager
【发布时间】:2020-07-18 16:08:58
【问题描述】:

我正在尝试从在自定义容器中运行的 AI Platform Training 作业访问存储在 Google Secret Manager 中的机密。我正在使用以下 Python 代码来检索机密:

# Standard library imports
import os

# Import the Secret Manager client library.
from google.cloud import secretmanager


def access_secret_version(secret_id, version_id, project_id=os.environ.get("GCP_PROJECT")):
     # Create the Secret Manager client.
    client = secretmanager.SecretManagerServiceClient()

    # Build the resource name of the secret version.
    name = client.secret_version_path(project_id, secret_id, version_id)

    # Access the secret version.
    response = client.access_secret_version(name)

    # Return the secret payload.
    return response.payload.data.decode("UTF-8")

我已将Secret Manager Secret Accessor 角色添加到默认的 Cloud ML 服务帐户 (service-XXX@cloud-ml.google.com.iam.gserviceaccount.com),但访问仍然被拒绝:

google.api_core.exceptions.PermissionDenied: 403 Request had insufficient authentication scopes.

我是否将正确的角色授予了正确的服务帐户,或者我遗漏了其他内容?

【问题讨论】:

    标签: python google-cloud-ml


    【解决方案1】:

    我们有一个 alpha 功能来启用您的用例。请给我们发送电子邮件至 cloudml-feedback@google.com 好吗?

    【讨论】:

    • 该功能目前处于测试阶段。 cloud.google.com/ai-platform/training/docs/…
    • 您的评论是否暗示通过 ML Engine 访问 Secret Manager 的唯一方法是通过指定另一个服务帐户来运行训练作业(根据您的链接)?并且将角色Secret Manager Secret Accessor 分配给...@cloud-ml.google.com.iam.gserviceaccount.com 服务帐户永远不会起作用?
    • 我们正在通过 Google Composer DAG 运行培训作业,并且在 Composer 中使用自动身份验证时,似乎无法通过 MLEngine 运算符使用 delegate_to 进行服务帐户模拟,根据 github.com/apache/airflow/issues/8163
    • 在通过 Google Composer 提交作业时,我们如何从 ML 引擎/AI Platform 训练作业访问 Secret Manager?
    • 在发送到 ML Engine 的作业创建请求中,您可以指定要使用的服务帐户。请注意,此服务需要有权访问 Secret Manager。
    猜你喜欢
    • 2019-10-11
    • 2021-02-24
    • 2021-08-27
    • 2021-08-08
    • 2022-10-15
    • 1970-01-01
    • 1970-01-01
    • 2021-12-24
    • 2019-10-22
    相关资源
    最近更新 更多