Give service account user permissions  |  Cloud Data Fusion Documentation  |  Google Cloud (2024)

Stay organized with collections Save and categorize content based on your preferences.

This page describes how to grant the Dataproc Service AccountUser role to Cloud Data Fusion toallow it to provision and run pipelines on Dataproc clusters.

For service accounts that are used by Dataproc, you also need togrant datafusion.instances.runtime permission to accessCloud Data Fusion runtime resources.

Whether you use a user-managed service account, or the default Compute Engineservice account on the virtual machines in a cluster, you must grant theService Account User role to Cloud Data Fusion. Otherwise,Cloud Data Fusion cannot provision a Dataproc clusterand the following error appears when you execute a data pipeline:

PROVISION task failed in REQUESTING_CREATE state for program run [pipeline-name] due to Dataproc operation failure: INVALID_ARGUMENT: User not authorized to act as service account '[service-account-name]'

Get the service account name

  1. In the Google Cloud console, go to the Identity and Access Management page.
    Go to the IAM page
  2. From the project selector at the top of the page, choose the project, folder, or organization to which the Cloud Data Fusion instancebelongs.
  3. Find and copy the Cloud Data Fusion service account name. Use the following format:service-[project-number]@gcp-sa-datafusion.iam.gserviceaccount.com.

Give service account user permission

  1. In the Google Cloud console, go to the Service Accounts page.
    Go to the Service Accounts page
  2. Click Select a project, choose a project where the service account youwant to use for the Dataproc cluster is located, and then click Open.
  3. Click the email address of the Dataproc service account.

  4. Click the Permissions tab. The page displays a list of principals thathave been granted roles on the service account.

  5. Click person_add Grant access.

  6. In the New principals field, paste the Cloud Data Fusion service account name that you previously copied.

  7. Select the Service Account User role.

    Give service account user permissions | Cloud Data Fusion Documentation | Google Cloud (1)

  8. Click Save.

Grant roles to Dataproc service accounts

Grant runner role permission

Grant the Cloud Data Fusion runner role(roles/datafusion.runner) to service accounts that are used byDataproc. This authorizes the Dataproc service account to run Cloud Data Fusion pipelines in your project.For more information, see Requiring permission to attach service accounts to resources.

Grant Cloud Storage admin permission

In Cloud Data Fusion versions 6.2.0 and above, grant the Cloud Storage admin role(roles/storage.admin) to service accounts that are used byDataproc in your project.

What's next

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2024-09-10 UTC.

Give service account user permissions  |  Cloud Data Fusion Documentation  |  Google Cloud (2024)
Top Articles
Everything You Need to Know About Hiking from Valbona to Theth in the Albanian Alps - Passports and Preemies
What Is the Balance Sheet Classification of Trading Securities? | The Motley Fool
Davita Internet
Mate Me If You May Sapir Englard Pdf
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Flixtor The Meg
Jennette Mccurdy And Joe Tmz Photos
Arrests reported by Yuba County Sheriff
Kent And Pelczar Obituaries
10000 Divided By 5
ATV Blue Book - Values & Used Prices
Brutál jó vegán torta! – Kókusz-málna-csoki trió
Yakimacraigslist
Free Online Games on CrazyGames | Play Now!
Roof Top Snipers Unblocked
Pay Boot Barn Credit Card
91 East Freeway Accident Today 2022
Craigslist Southern Oregon Coast
Nhl Tankathon Mock Draft
Traveling Merchants Tack Diablo 4
Miltank Gamepress
New Stores Coming To Canton Ohio 2022
Horses For Sale In Tn Craigslist
Danielle Moodie-Mills Net Worth
Jesus Calling Feb 13
Joann Fabrics Lexington Sc
Orange Park Dog Racing Results
Superhot Free Online Game Unblocked
Ryujinx Firmware 15
Shauna's Art Studio Laurel Mississippi
Average weekly earnings in Great Britain
Dreammarriage.com Login
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
The Complete Guide To The Infamous "imskirby Incident"
About :: Town Of Saugerties
The Minneapolis Journal from Minneapolis, Minnesota
Busch Gardens Wait Times
Wlds Obits
Flags Half Staff Today Wisconsin
Indiana Jones 5 Showtimes Near Cinemark Stroud Mall And Xd
11526 Lake Ave Cleveland Oh 44102
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Levi Ackerman Tattoo Ideas
Scythe Banned Combos
A rough Sunday for some of the NFL's best teams in 2023 led to the three biggest upsets: Analysis
Rick And Morty Soap2Day
Julies Freebies Instant Win
Hsi Delphi Forum
Pilot Travel Center Portersville Photos
Hampton Inn Corbin Ky Bed Bugs
Salem witch trials - Hysteria, Accusations, Executions
Latest Posts
Article information

Author: Prof. An Powlowski

Last Updated:

Views: 6700

Rating: 4.3 / 5 (64 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Prof. An Powlowski

Birthday: 1992-09-29

Address: Apt. 994 8891 Orval Hill, Brittnyburgh, AZ 41023-0398

Phone: +26417467956738

Job: District Marketing Strategist

Hobby: Embroidery, Bodybuilding, Motor sports, Amateur radio, Wood carving, Whittling, Air sports

Introduction: My name is Prof. An Powlowski, I am a charming, helpful, attractive, good, graceful, thoughtful, vast person who loves writing and wants to share my knowledge and understanding with you.