Skip to content

Commit 890b7dc

Browse files
authored
fix: use aiplatform.user role for agent identity IAM permissions (#727)
Update agent identity setup to grant roles/aiplatform.user instead of roles/aiplatform.expressUser. The user role provides broader access to Vertex AI services including model prediction capabilities, while expressUser is limited to simplified Express Mode features with API keys.
1 parent 2fb9794 commit 890b7dc

File tree

1 file changed

+1
-1
lines changed
  • agent_starter_pack/deployment_targets/agent_engine/python/{{cookiecutter.agent_directory}}/app_utils

1 file changed

+1
-1
lines changed

agent_starter_pack/deployment_targets/agent_engine/python/{{cookiecutter.agent_directory}}/app_utils/deploy.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,7 @@ def setup_agent_identity(client: Any, project: str, display_name: str) -> Any:
148148
)
149149

150150
roles = [
151-
"roles/aiplatform.expressUser",
151+
"roles/aiplatform.user",
152152
"roles/serviceusage.serviceUsageConsumer",
153153
"roles/browser",
154154
"roles/cloudapiregistry.viewer",

0 commit comments

Comments
 (0)