You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Python中禁用google-cloud-aiplatform的SSL验证

解决Google Cloud AI Platform Python SDK SSL证书验证失败问题

问题描述

使用Python的google-cloud-aiplatform库时遭遇SSL握手失败错误,具体报错:

503 failed to connect to all addresses; last error: UNKNOWN: ipv4:{an ip address, hidden for security}:443: Ssl handshake failed: SSL_ERROR_SSL: error:1000007d:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED
src/core/tsi/ssl_transport_security.cc:1654] Handshake failed with
fatal error SSL_ERROR_SSL: error:1000007d:SSL
routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED

此前尝试的代码未解决问题:

channel = grpc.insecure_channel('us-central1-aiplatform.googleapis.com:443')

aiplatform.init(
    project=common.model_config['project_id'],
    staging_bucket=common.model_config['bucket_uri'],
    location =common.model_config['region'],
     credentials=channel)

正确解决方法

错误原因是把grpc通道直接传给了credentials参数,这是用法错误。要禁用SSL验证,需创建自定义grpc通道并正确配置到AI Platform客户端中,步骤如下:

  1. 创建禁用SSL验证的grpc通道
    使用grpc.ssl_channel_credentials生成忽略证书验证的凭据,再构建带配置的通道:

    import grpc
    from google.cloud import aiplatform
    
    # 创建忽略SSL验证的凭据
    ssl_credentials = grpc.ssl_channel_credentials(
        root_certificates=None,
        private_key=None,
        certificate_chain=None
    )
    # 配置通道选项,指定目标域名
    channel_options = [
        ("grpc.ssl_target_name_override", "us-central1-aiplatform.googleapis.com"),
        ("grpc.default_authority", "us-central1-aiplatform.googleapis.com")
    ]
    channel = grpc.secure_channel(
        target="us-central1-aiplatform.googleapis.com:443",
        credentials=ssl_credentials,
        options=channel_options
    )
    
  2. 将通道绑定到AI Platform客户端
    初始化aiplatform时,通过client_options传入自定义通道,而非credentials参数:

    aiplatform.init(
        project=common.model_config['project_id'],
        staging_bucket=common.model_config['bucket_uri'],
        location=common.model_config['region'],
        client_options={
            "api_endpoint": "us-central1-aiplatform.googleapis.com:443",
            "grpc_channel": channel
        }
    )
    
  3. 临时环境变量绕过验证(仅测试用)
    如果上述代码仍有问题,可通过环境变量临时绕过SSL验证(仅限测试环境):

    export GRPC_SSL_CIPHER_SUITES="HIGH+ECDSA"
    

    也可在Python代码中直接设置:

    import os
    os.environ['GRPC_SSL_CIPHER_SUITES'] = 'HIGH+ECDSA'
    

注意事项

  • 禁用SSL验证会降低通信安全性,仅建议在测试环境或内部可信网络中使用。
  • 生产环境请优先配置正确的CA证书,将根证书路径传入grpc.ssl_channel_credentials的root_certificates参数即可。

内容的提问来源于stack exchange,提问作者SaD

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 21:22:11