You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Vertex Pipelines调度报Permission denied错误及PipelineJob调度方法咨询

Cloud Scheduler调度Vertex Pipeline权限错误排查
  • 首先确认Cloud Scheduler的内置服务账号(格式为service-<项目ID>@gcp-sa-cloudscheduler.iam.gserviceaccount.com)是否被授予roles/cloudfunctions.invoker权限:Cloud Scheduler触发HTTP端点时用的是自身的内置服务账号,而非你创建调度时使用的Owner账号,这是最高发的错误原因。
  • 检查Cloud Function运行时服务账号的权限:Cloud Function被触发后需要提交Vertex Pipeline作业,其运行账号需要持有roles/aiplatform.user权限,同时需要Pipeline spec所在GCS路径的读取权限。
  • 确认Vertex AI内置服务代理账号(格式为service-<项目ID>@gcp-sa-aiplatform.iam.gserviceaccount.com)拥有Pipeline运行所需的所有资源访问权限,包括GCS读写、BigQuery操作、相关服务的调用权限等。
  • 若Cloud Function配置了入站流量限制,需要放开Google内部服务的访问权限,或允许Cloud Scheduler的IP段访问。
新版google.cloud.aiplatform SDK PipelineJob调度方案

官方新版SDK没有单独的创建调度的客户端方法,直接使用Vertex AI原生Schedule资源即可实现Pipeline的定期调度,无需自行搭建Cloud Function中转,示例代码如下:

from google.cloud import aiplatform

# 初始化SDK
aiplatform.init(
    project="你的GCP项目ID",
    location="Vertex AI部署区域,比如us-central1"
)

# 构造PipelineJob对象,无需手动调用run()
pipeline_job = aiplatform.PipelineJob(
    display_name="你的pipeline任务名称",
    template_path="pipeline spec文件路径,支持本地路径或GCS路径",
    parameter_values={
        # 你的pipeline运行参数
        "input_path": "gs://xxx/input",
        "output_path": "gs://xxx/output"
    },
)

# 创建定时调度
schedule = aiplatform.Schedule.create(
    display_name="pipeline定时调度名称",
    cron="0 8 * * *", # cron表达式,此处为每天UTC时间8点运行
    max_concurrent_run_count=1, # 最大同时运行数,避免重复运行冲突
    pipeline_job=pipeline_job,
    service_account="用于运行Pipeline的服务账号邮箱"
)

如果需要自定义触发逻辑,仍可以搭配Cloud Scheduler + Cloud Function使用:在Cloud Function的业务代码中直接构造PipelineJob并调用run()方法即可,和本地单次运行逻辑一致,只需给Cloud Function的运行服务账号授予对应权限。

内容的提问来源于stack exchange,提问作者Martin Becuwe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 01:54:03