You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Airflow Dataproc Operator中ClusterGenerator的Shielded VM参数配置求助

在Airflow的DataprocCreateClusterOperator中配置Shielded VM

你之前的配置路径不对,Shielded VM的参数不能放在ClusterGenerator的properties里,也不能直接在cluster_config根节点传入,正确的位置是集群主节点(master_config)和工作节点(worker_config)的实例配置中——因为Shielded VM是针对虚拟机实例层面的安全配置。

正确配置示例

方式1:用ClusterGenerator构造配置

from airflow.providers.google.cloud.operators.dataproc import DataprocCreateClusterOperator
from airflow.providers.google.cloud.utils.dataproc import ClusterGenerator

cluster_config = ClusterGenerator(
    project_id="你的项目ID",
    zone="你的可用区",
    master_machine_type="n1-standard-4",
    master_disk_size=500,
    num_workers=2,
    worker_machine_type="n1-standard-4",
    worker_disk_size=500,
    # 为主节点配置Shielded VM
    master_config={
        "shielded_instance_config": {
            "enable_secure_boot": True,
            "enable_vtpm": True,
            "enable_integrity_monitoring": True
        }
    },
    # 为工作节点配置Shielded VM
    worker_config={
        "shielded_instance_config": {
            "enable_secure_boot": True,
            "enable_vtpm": True,
            "enable_integrity_monitoring": True
        }
    }
).make()

create_cluster = DataprocCreateClusterOperator(
    task_id="create_dataproc_cluster",
    cluster_name="你的集群名称",
    cluster_config=cluster_config,
    region="你的区域",
    project_id="你的项目ID"
)

方式2:直接构造cluster_config字典

如果不使用ClusterGenerator,可直接定义配置字典:

cluster_config = {
    "master_config": {
        "num_instances": 1,
        "machine_type_uri": "n1-standard-4",
        "disk_config": {"boot_disk_size_gb": 500},
        "shielded_instance_config": {
            "enable_secure_boot": True,
            "enable_vtpm": True,
            "enable_integrity_monitoring": True
        }
    },
    "worker_config": {
        "num_instances": 2,
        "machine_type_uri": "n1-standard-4",
        "disk_config": {"boot_disk_size_gb": 500},
        "shielded_instance_config": {
            "enable_secure_boot": True,
            "enable_vtpm": True,
            "enable_integrity_monitoring": True
        }
    }
    # 其他集群配置项可在此补充
}

关键注意点

  • Shielded VM是节点组级别配置,主、工作节点需分别设置(如果两者都要启用)
  • 参数名采用蛇形命名:enable_secure_boot、enable_vtpm、enable_integrity_monitoring,和你提到的驼峰命名有差异,这可能是之前配置不生效的原因之一
  • Airflow的DataprocCreateClusterOperator完全支持Shielded VM,因为它对接的是GCP Dataproc官方API,而GCP Dataproc本身原生支持该特性

内容的提问来源于stack exchange,提问作者italovinicius18

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 13:01:19