googleapis / googleapis/python-aiplatform

[Reasoning Engine] Support for custom Cloud Build worker pools in `agent_engines.create()

Aperta
#5,552 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
api: vertex-ai
Lingua principale
Python
Stelle
905
Fork
465
Merge medio
1g 13h
PR unite (30g)
44

Descrizione

### Feature Request: Support for custom Cloud Build worker pools in `agent_engines.create()`

The `vertexai.agent_engines.create()` method provides a streamlined way to deploy an agent, but it lacks the ability to specify a custom **Cloud Build worker pool** for the underlying build process.

This is a critical feature for organizations that use **VPC Service Controls (VPC-SC)**. In a VPC-SC environment, network policies often prohibit builds from running in the default Google-managed pool, requiring them to execute within a private worker pool inside the service perimeter.

Currently, attempting to use `agent_engines.create()` from within a secured environment fails with a `PermissionDenied` error because the build is initiated outside the perimeter. The alternative of building a container manually with `gcloud builds submit --worker-pool` is not a viable workaround, as there is no corresponding Agent Engine method to deploy a pre-built container image.

We request the addition of a parameter to `agent_engines.create()` (e.g., `build_config`) that allows users to specify a private worker pool, enabling Agent Engine deployments in VPC-SC-protected environments.

---

#### Environment details

- **OS type and version**: Linux (Vertex AI Workbench)
- **Python version**: `Python 3.11.5`
- **pip version**: `pip 23.2.1`
- **`google-cloud-aiplatform` version**: `1.58.0`

---

#### Steps to reproduce

1. Configure a Google Cloud project with a VPC Service Controls perimeter that includes the Cloud Build API (`cloudbuild.googleapis.com`) and Vertex AI API (`aiplatform.googleapis.com`).
2. Create a private Cloud Build worker pool within the project's VPC network.
3. From an environment within the perimeter (like a Vertex AI Workbench notebook), attempt to deploy an agent using the code example below.
4. The operation fails with a VPC-SC `PermissionDenied` error because the build cannot be configured to use the private worker pool.

---

#### Code example

```python
import vertexai
from vertexai.preview import agent_engines

PROJECT_ID = "your-vpc-sc-project"
LOCATION = "us-central1"

vertexai.init(project=PROJECT_ID, location=LOCATION)

# A placeholder agent for demonstration
class MyAgent:
def query(self, query: str) -> str:
return f"Query received: {query}"

try:
# This call fails because it cannot be directed to a private worker pool
# inside the VPC-SC perimeter.
remote_app = agent_engines.create(
display_name="my-secure-agent",
agent_engine=MyAgent(),
)
print(f"Successfully deployed agent: {remote_app.resource_name}")

# --- DESIRED FUNCTIONALITY ---
# A new parameter is needed to specify build configurations:
# remote_app = agent_engines.create(
# ...,
# build_config={
# "worker_pool": "projects/PROJECT_ID/locations/REGION/workerPools/MY_POOL"
# }
# )

except Exception as e:
print(f"Deployment failed: {e}")

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.