Composer2环境服务账号无法访问Google Drive及API范围添加求助
解决Composer 2访问Google Drive/BigQuery时的权限凭证错误问题
针对你遇到的Composer 2环境报错:
Access Denied: BigQuery BigQuery: Permission denied while getting Drive credentials
且已确认缺失https://www.googleapis.com/auth/cloud-platform、https://www.googleapis.com/auth/spreadsheets、https://www.googleapis.com/auth/drive这三个API范围的情况,可按以下步骤操作:
一、添加缺失的OAuth范围
1. 创建新Composer 2环境时添加范围
使用gcloud命令创建环境时,通过--oauth-scopes参数指定所需范围:
gcloud composer environments create <你的环境名> \ --location <你的区域> \ --oauth-scopes=https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/spreadsheets,https://www.googleapis.com/auth/drive
2. 修改现有Composer 2环境添加范围
对已存在的环境,执行更新命令添加范围(操作会触发环境重启,需等待数分钟):
gcloud composer environments update <你的环境名> \ --location <你的区域> \ --update-oauth-scopes=https://www.googleapis.com/auth/cloud-platform,https://www.googleapis.com/auth/spreadsheets,https://www.googleapis.com/auth/drive
二、额外排查点
- 确认Composer 2使用的服务账号是否与Composer 1一致:若为不同账号,需把该服务账号邮箱添加到目标Drive文件的共享列表,赋予至少「查看者」权限
- 检查BigQuery外部表配置:若通过BigQuery访问Drive文件,确保外部表的数据源配置使用的服务账号拥有Drive访问权限,且BigQuery API已在GCP项目中启用
- 验证Airflow连接:进入Airflow UI的「Admin -> Connections」,查看
google_cloud_default连接的Extra字段,确认scopes已包含上述三个范围 - 确认服务账号权限:即使已赋予权限,检查是否存在权限继承问题,或需重新授权(可尝试移除再重新添加权限)
内容的提问来源于stack exchange,提问作者jptr
相关产品推荐
相关产品推荐

