您建立並擁有這個專案。根據預設,Cloud Data Fusion 會在這個專案中建立臨時 Dataproc 叢集,以便執行管道。
下圖顯示在租用戶專案中執行的 Cloud Data Fusion 執行個體,以及在客戶專案的 Dataproc 叢集中執行的管道。
Cloud Data Fusion 中的服務帳戶
服務帳戶會為 Cloud Data Fusion 提供身分,讓 Cloud Data Fusion 存取您的資源。
啟用 Cloud Data Fusion API 並建立 Cloud Data Fusion 執行個體後,系統會在專案中新增服務帳戶,以便存取 Service Networking、Dataproc、Cloud Storage、BigQuery、Spanner 和 Bigtable 等資源。這個服務帳戶稱為「Cloud Data Fusion API 服務代理人」。系統會自動將角色授予這個服務代理。
服務代理人 (稱為 Cloud Data Fusion API 服務代理人) 是 Cloud Data Fusion 建立的服務,可取得客戶資源的存取權,以便代表客戶採取行動。用於用戶群專案,存取客戶專案資源。例如,預覽會在記憶體中執行,而不是在 Dataproc 叢集中執行。
預設指派給 Cloud Data Fusion 服務帳戶的 Cloud Data Fusion API 服務代理人 (roles/datafusion.serviceAgent) 身分與存取權管理角色,包含額外權限,可確保最佳使用者體驗。為提升安全性,您可以建立自訂角色,並為該角色指派一組任務的最低權限,然後指派給 Cloud Data Fusion 服務帳戶。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-06-16 (世界標準時間)。"],[[["Cloud Data Fusion uses service accounts to access resources in both tenant and customer projects, enabling it to manage pipelines on the user's behalf."],["The Cloud Data Fusion API Service Agent is a service account created automatically when enabling the Cloud Data Fusion API, granting it access to resources like Service Networking, Dataproc, Cloud Storage, and others."],["A default Compute Engine service account is also created to deploy jobs that access other Google Cloud resources, which can attach to a Dataproc cluster VM to enable Cloud Data Fusion to access Dataproc resources during pipeline runs."],["In Cloud Data Fusion Enterprise edition, pipelines can run from a user-managed service account by creating a profile in the Cloud Data Fusion console, enhancing control and customization."],["Customer project is owned by the customer and is the location where the ephemeral Dataproc cluster is located in order to run the user's pipelines."]]],[]]