小编Ian*_*Ian的帖子

Composer 2/GKE Autopilot 集群 PodOperator 任务的工作负载身份和服务帐户

我正在尝试在 Composer 2 环境中运行 GKEStartPodOperator/KubernetesPodOperator 任务,该环境在自动驾驶模式下使用 GKE 集群。我们现有的 Composer 1 环境中的 GKE 集群不处于自动驾驶模式。我们使用 Google Cloud Platform 服务(BigQuery、GCS 等)进行身份验证的任务在 Composer 2 环境中失败并出现 401 未经授权,但在 Composer 1 环境中成功。

在日志文件中,我可以看出两个环境中的任务都是通过向元数据服务器发出请求来获取凭据的。主要区别是 Composer 1 中的任务请求分配给任务运行所在节点的服务帐户,但 Composer 2 中的任务请求似乎是工作负载身份池,例如[project-name].svc.id.goog.

Composer 1 的日志是:

[2021-10-22 12:38:01,349] {pod_launcher.py:148} INFO - DEBUG:google.auth._default:Checking None for explicit credentials as part of auth process...
[2021-10-22 12:38:01,351] {pod_launcher.py:148} INFO - DEBUG:google.auth._default:Checking Cloud SDK credentials as part of auth process...
[2021-10-22 12:38:01,352] {pod_launcher.py:148} INFO - DEBUG:google.auth._default:Cloud SDK credentials not found on disk; not …
Run Code Online (Sandbox Code Playgroud)

service-accounts google-kubernetes-engine airflow google-cloud-composer workload-identity

5
推荐指数
1
解决办法
2765
查看次数