You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vertex AI自定义容器模型评估批量预测步骤权限报错排查

问题解决:Vertex AI评估流程中批量预测步骤权限报错

核心原因

Vertex AI评估流程里的model-batch-prediction步骤,会使用独立的内部服务账号custom-batch-prediction@[你的项目ID]-tp.iam.gserviceaccount.com执行,不会继承你创建评估任务时指定的Compute Engine默认服务账号权限。这就是为什么手动批量预测能成功,但评估流水线里的同一步骤会触发403权限错误。

解决方案

  1. 定位目标服务账号:从报错日志中复制完整的custom-batch-prediction@xxx.iam.gserviceaccount.com账号名称
  2. 配置GCS存储桶权限:
    • 打开GCP控制台的Cloud Storage页面,找到存储model.pkl的目标桶
    • 进入桶的「权限」标签页,点击「添加权限」
    • 在「新成员」中粘贴上述内部服务账号,选择「角色」为Storage Object Viewer(或直接授予storage.objects.get的细粒度权限)
    • 保存权限设置
  3. 重新触发评估任务:删除失败的评估流水线,重新创建并运行,验证model-batch-prediction步骤是否成功

补充说明

你手动执行批量预测时,使用的是Compute Engine默认服务账号(已配置足够权限),所以能正常读取GCS中的模型文件。但Vertex AI评估流水线的内部步骤有专属服务账号,必须单独为其配置模型文件所在存储桶的读取权限。

报错日志原文:

error: 403 GET
https://storage.googleapis.com/download/storage/v1/b/***/o/models%2F[folder name removed for confidentiality]%2F2024-01-28_040503%2Fmodel%2Fmodel.pkl?alt=media: 
custom-batch-prediction@[removed]-tp.iam.gserviceaccount.com does not have  storage.objects.get access to the Google Cloud Storage object.
Permission 'storage.objects.get' denied on resource (or it  may not exist).: 
('Request failed with status code', 403, 'Expected  one of', <HTTPStatus.OK: 200>, <HTTPStatus.PARTIAL_CONTENT: 206>),  type: <class 'google.api_core.exceptions.Forbidden'>  

手动批量预测的读取代码:

client = storage.Client(project=project_name)
bucket = client.bucket(bucket_name)
blob = bucket.blob(object_path)
model_bytes = blob.download_as_bytes()
model = pickle.loads(model_bytes)

内容的提问来源于stack exchange,提问作者Othmane El Omri

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 08:31:17