You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vertex AI自定义作业无法获取自定义服务账号身份令牌问题

问题背景
  • 需求为在Vertex AI自定义作业中使用服务账号生成身份令牌,在作业执行完成后向Cloud Run API发送通知。
  • 已为目标服务账号绑定roles/run.invoker角色,本地验证确认该服务账号可正常访问Cloud Run API:使用服务账号凭据可生成audience设置为Cloud Run API URL的有效身份令牌。
故障现象
  • 当通过gcloud ai custom-jobs create命令或golang client library创建绑定自定义服务账号的Vertex AI自定义作业时,无法获取该自定义服务账号的身份令牌:
    • 执行gcloud auth print-identity-token命令返回错误:
      • (gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials.
    • 直接调用metadata server接口请求身份令牌返回Not Found响应,请求命令如下:
      curl \
        -s \
        --get \
        --data-urlencode "audience=$CLOUD_RUN_API_URL" \
        --data-urlencode "format=full" \
        -H "Metadata-Flavor: Google" \
        http://metadata/computeMetadata/v1/instance/service-accounts/default/identity
      
    • 响应结果:Not Found
  • 现寻求可支持在自定义作业内正常获取服务账号身份令牌的作业配置方式或调用方案。

测试验证细节
  • 为测试身份令牌生成能力,使用如下Dockerfile构建自定义测试容器:
FROM alpine:3.6

RUN apk add --update python curl which bash
RUN curl -sSL https://sdk.cloud.google.com | bash -s -- --disable-prompts
ENV PATH $PATH:/root/google-cloud-sdk/bin

CMD ["gcloud", "auth", "print-identity-token", "--verbosity", "debug"]
  • 以下场景可正常生成有效身份令牌:
    • ✅ 本地运行该测试镜像
    • ✅ 通过Vertex AI控制台界面的“创建”按钮运行该镜像,服务账号设置为本次场景使用的自定义服务账号
    • ✅ 通过gcloud运行该镜像,不指定服务账号(使用项目默认Vertex AI服务账号)
  • 以下场景触发错误(即本次问询的核心问题):
    • ❌ 通过如下gcloud命令指定自定义服务账号运行镜像时返回错误(镜像名、服务账号信息已脱敏):
      • 执行命令:
        gcloud ai custom-jobs create \
          --region=asia-northeast1 \
          --display-name=cli_identity_test \
          --worker-pool-spec=machine-type=n2-standard-4,replica-count=1,container-image-uri=<IMAGE NAME> \
          --service-account=<SERVICE ACCOUNT EMAIL>
        
      • 错误日志:
        DEBUG: (gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials.                                                                
        Traceback (most recent call last):                                                                                                                                       
          File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/cli.py", line 987, in Execute                                                                                 
            resources = calliope_command.Run(cli=self, args=args)                                                                                                                
          File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/backend.py", line 809, in Run                                                                                 
            resources = command_instance.Run(args)                                                                                                                               
          File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/exceptions.py", line 129, in TryFunc                                                                          
            return func(*args, **kwargs)                                                                                                                                         
          File "/root/google-cloud-sdk/lib/surface/auth/print_identity_token.py", line 130, in Run                                                                               
            credential = _Run(args)                                                                                                                                              
          File "/root/google-cloud-sdk/lib/surface/auth/print_identity_token.py", line 78, in _Run                                                                               
            'No identity token can be obtained from the current credentials.')                                                                                                   
        InvalidIdentityTokenError: No identity token can be obtained from the current credentials.                                                                               
        ERROR: (gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials.
        
    • ❌ 通过Vertex AI golang API客户端库启动绑定自定义服务账号的该镜像作业时,同样触发错误。

已尝试的排查操作
  • 已尝试为自定义服务账号追加多种角色配置,均未解决问题,追加的角色包括:
    • 与默认Vertex AI服务账号一致的roles/aiplatform.customCodeServiceAgent角色
    • Service Account Token Creator角色(roles/iam.serviceAccountTokenCreator)
    • Service Account User角色(roles/iam.serviceAccountUser)

内容的提问来源于stack exchange,提问作者minikomi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 06:54:31