Vertex AI自定义作业无法获取自定义服务账号身份令牌问题
问题背景
- 需求为在Vertex AI自定义作业中使用服务账号生成身份令牌,在作业执行完成后向Cloud Run API发送通知。
- 已为目标服务账号绑定
roles/run.invoker角色,本地验证确认该服务账号可正常访问Cloud Run API:使用服务账号凭据可生成audience设置为Cloud Run API URL的有效身份令牌。
故障现象
- 当通过
gcloud ai custom-jobs create命令或golang client library创建绑定自定义服务账号的Vertex AI自定义作业时,无法获取该自定义服务账号的身份令牌:- 执行
gcloud auth print-identity-token命令返回错误:(gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials.
- 直接调用metadata server接口请求身份令牌返回
Not Found响应,请求命令如下:curl \ -s \ --get \ --data-urlencode "audience=$CLOUD_RUN_API_URL" \ --data-urlencode "format=full" \ -H "Metadata-Flavor: Google" \ http://metadata/computeMetadata/v1/instance/service-accounts/default/identity - 响应结果:
Not Found
- 执行
- 现寻求可支持在自定义作业内正常获取服务账号身份令牌的作业配置方式或调用方案。
测试验证细节
- 为测试身份令牌生成能力,使用如下Dockerfile构建自定义测试容器:
FROM alpine:3.6 RUN apk add --update python curl which bash RUN curl -sSL https://sdk.cloud.google.com | bash -s -- --disable-prompts ENV PATH $PATH:/root/google-cloud-sdk/bin CMD ["gcloud", "auth", "print-identity-token", "--verbosity", "debug"]
- 以下场景可正常生成有效身份令牌:
- ✅ 本地运行该测试镜像
- ✅ 通过Vertex AI控制台界面的“创建”按钮运行该镜像,服务账号设置为本次场景使用的自定义服务账号
- ✅ 通过gcloud运行该镜像,不指定服务账号(使用项目默认Vertex AI服务账号)
- 以下场景触发错误(即本次问询的核心问题):
- ❌ 通过如下gcloud命令指定自定义服务账号运行镜像时返回错误(镜像名、服务账号信息已脱敏):
- 执行命令:
gcloud ai custom-jobs create \ --region=asia-northeast1 \ --display-name=cli_identity_test \ --worker-pool-spec=machine-type=n2-standard-4,replica-count=1,container-image-uri=<IMAGE NAME> \ --service-account=<SERVICE ACCOUNT EMAIL> - 错误日志:
DEBUG: (gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials. Traceback (most recent call last): File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/cli.py", line 987, in Execute resources = calliope_command.Run(cli=self, args=args) File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/backend.py", line 809, in Run resources = command_instance.Run(args) File "/root/google-cloud-sdk/lib/googlecloudsdk/calliope/exceptions.py", line 129, in TryFunc return func(*args, **kwargs) File "/root/google-cloud-sdk/lib/surface/auth/print_identity_token.py", line 130, in Run credential = _Run(args) File "/root/google-cloud-sdk/lib/surface/auth/print_identity_token.py", line 78, in _Run 'No identity token can be obtained from the current credentials.') InvalidIdentityTokenError: No identity token can be obtained from the current credentials. ERROR: (gcloud.auth.print-identity-token) No identity token can be obtained from the current credentials.
- 执行命令:
- ❌ 通过Vertex AI golang API客户端库启动绑定自定义服务账号的该镜像作业时,同样触发错误。
- ❌ 通过如下gcloud命令指定自定义服务账号运行镜像时返回错误(镜像名、服务账号信息已脱敏):
已尝试的排查操作
- 已尝试为自定义服务账号追加多种角色配置,均未解决问题,追加的角色包括:
- 与默认Vertex AI服务账号一致的
roles/aiplatform.customCodeServiceAgent角色 - Service Account Token Creator角色(
roles/iam.serviceAccountTokenCreator) - Service Account User角色(
roles/iam.serviceAccountUser)
- 与默认Vertex AI服务账号一致的
内容的提问来源于stack exchange,提问作者minikomi
相关产品推荐
相关产品推荐

