Amazon SageMaker创建EndpointConfig时AccessDeniedException权限问题求助
在AWS Cloud Quest「机器学习>基于大语言模型(LLM)的聊天机器人」实验第二步(通过Amazon SageMaker实时推理端点部署模型)中,调用CreateEndpointConfig操作时反复触发AccessDeniedException错误。所用IAM角色已配置sagemaker:CreateEndpointConfig、sagemaker:CreateEndpoint等权限,但因是AWS提供的实验环境,无权限修改IAM角色及服务控制策略(SCP)。
部分IAM权限
{ "Version": "2012-10-17", "Statement": [ { "Action": [ "iam:GetRole", "iam:PassRole" ], "Resource": "arn:aws:iam::*:role/sagemaker_studio_role", "Effect": "Allow", "Sid": "IAM1" }, { "Action": "iam:ListRoles", "Resource": "*", "Effect": "Allow", "Sid": "IAM2" }, { "Action": [ "ecr:*", "sagemaker:CreateEndpoint", "sagemaker:CreateEndpointConfig", ], "Resource": "*", "Effect": "Allow", "Sid": "Sagemaker1" } ] }
错误信息(ClientError)
ClientError: An error occurred (AccessDeniedException) when calling the CreateEndpointConfig operation: User: arn:aws:sts::920******910:assumed-role/sagemaker_studio_role/SageMaker is not authorized to perform: sagemaker:CreateEndpointConfig on resource: arn:aws:sagemaker:us-east-1:920******910:endpoint-config/jumpstart-example-huggingface-text2text-2024-09-02-23-45-22-813 with an explicit deny in a service control policy
示例代码(Jupyter Notebook)
# Deploy the Model. Note that we need to pass Predictor class when we deploy model through the Model class # defined above, so we can run inference through the sagemaker API. model_predictor = model.deploy( initial_instance_count=1, instance_type='ml.g5.xlarge', predictor_cls=sagemaker.predictor.Predictor, endpoint_name='jumpstart-example-huggingface-text2text-2024-09-03-03-36-14-616', )
内容的提问来源于stack exchange,提问作者nwpie

