使用Terraform创建Vertex AI托管Notebook失败:插入GCE VM错误
问题:Terraform创建GCP Vertex AI托管Notebook失败(插入GCE VM报错)
我尝试在GCP中创建多台Vertex AI托管Notebook(非用户托管Notebook),但每次都失败,报错显示插入GCE VM失败。已排查以下点:
- 部署用服务账号已配置项目OWNER权限
- 项目所需API均已启用,且通过Vertex AI控制台可手动创建相同配置的托管Notebook
- 共享VPC的网络和子网无异常
谷歌支持判断是Terraform配置问题,以下是我的模块代码、调用代码,已参考官方示例配置。
错误日志
2023-07-10T02:36:05.3813609Z e[31m│e[0m e[0me[1me[31mError: e[0me[0me[1mError waiting to create Runtime: Error waiting for Creating Runtime: Error code 3, message: operation “projects//locations/australia-southeast1/operations/create-d73db12f-8b7e-48eb-af84-7aadae580bd1” completed with error: %!w(*status.Status=&{{{} } 3 Http(400) Bad Request; [ExecuteComputeApi] failed.; [VM][:vm-d73db12f-8b7e-48eb-af84-7aadae580bd1] ; Failed to insert a GCE VM 131})e[0m 2023-07-10T02:36:05.3814103Z e[31m│e[0m e[0m 2023-07-10T02:36:05.3814380Z e[31m│e[0m e[0me[0m with module.user2notebook.google_notebooks_runtime.runtime, 2023-07-10T02:36:05.3814746Z e[31m│e[0m e[0m on notebook_module/notebook_module.tf line 16, in resource “google_notebooks_runtime” “runtime”: 2023-07-10T02:36:05.3815095Z e[31m│e[0m e[0m 16: resource “google_notebooks_runtime” “runtime” e[4m{e[0me[0m 2023-07-10T02:36:05.3815319Z e[31m│e[0m e[0m
模块代码(notebook_module.tf)
variable “user_name” { description = “Name of the user” type = string } variable “user_email” { description = “Email of the user” type = string } variable “machine_type” { description = “Machine type for the notebook instance” type = string } resource “google_notebooks_runtime” “runtime” { name = “${lower(replace(replace(var.user_email, “@”, “-”), “.”, “-”))}-notebook-instance” location = “australia-southeast1” access_config { access_type = “SINGLE_USER” runtime_owner = var.user_email } virtual_machine { virtual_machine_config { machine_type = var.machine_type internal_ip_only = true network = var.NETWORK subnet = var.SUBNET data_disk { initialize_params { disk_size_gb = “100” disk_type = “PD_STANDARD” } } metadata = { app = "inventory-mlops" bu = var.BU owner = var.OWNER costcentre = var.COSTCENTRE email = var.user_email } labels = { app = "inventory-mlops" bu = var.BU owner = var.OWNER costcentre = var.COSTCENTRE email = var.user_email } } } timeouts { create = “30m” delete = “30m” } }
调用代码(main.tf)
module "user21notebook" { source = "./notebook_module" user_name = "James Matson" user_email = "james.matson@api.net.au" machine_type = "n1-standard-1" }
问题分析与解决方案
核心问题
模块代码中使用了var.NETWORK、var.SUBNET、var.BU、var.OWNER、var.COSTCENTRE这些变量,但未在模块中声明,也未在调用时传入值,导致Terraform创建资源时缺少关键的网络配置和标签信息,触发GCE VM插入的400 Bad Request错误。
修复步骤
- 补充模块变量声明
在notebook_module.tf中添加缺失的变量定义:
variable "NETWORK" { description = "VPC网络名称或自链接" type = string } variable "SUBNET" { description = "子网名称或自链接" type = string } variable "BU" { description = "业务单元标签" type = string } variable "OWNER" { description = "所有者标签" type = string } variable "COSTCENTRE" { description = "成本中心标签" type = string }
- 在调用时传入变量值
修改main.tf的模块调用,补充传入所有变量:
module "user21notebook" { source = "./notebook_module" user_name = "James Matson" user_email = "james.matson@api.net.au" machine_type = "n1-standard-1" # 补充网络和标签变量 NETWORK = "projects/你的项目ID/global/networks/你的VPC名称" # 或直接用VPC名称(同项目下) SUBNET = "projects/你的项目ID/regions/australia-southeast1/subnetworks/你的子网名称" BU = "你的业务单元值" OWNER = "你的所有者值" COSTCENTRE = "你的成本中心值" }
- 可选优化
将变量名改为Terraform规范的小写蛇形命名(如network代替NETWORK),提升代码可读性和一致性。
内容的提问来源于stack exchange,提问作者JamesMatson
相关产品推荐
相关产品推荐

