You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法拉取Inferentia PyTorch SageMaker预构建镜像的权限问题

问题:无法拉取SageMaker Inferentia PyTorch预构建ECR镜像

尝试扩展SageMaker的Inferentia PyTorch预构建Docker容器,但执行拉取镜像操作时失败。

操作步骤

  1. 执行ECR登录命令(登录成功):
aws ecr get-login-password --region eu-west-2 | docker login --username AWS --password-stdin 205493899709.dkr.ecr.eu-west-2.amazonaws.com

输出:

Login Succeeded
  1. 执行镜像拉取命令:
docker pull 205493899709.dkr.ecr.eu-west-2.amazonaws.com/sagemaker-neo-pytorch:1.9-inf-py3

错误信息

Error response from daemon: pull access denied for 205493899709.dkr.ecr.eu-west-2.amazonaws.com/sagemaker-neo-pytorch, repository does not exist or may require 'docker login': denied: User: arn:aws:iam::[redacted]:user/[redacted] is not authorized to perform: ecr:BatchGetImage on resource: arn:aws:ecr:eu-west-2:205493899709:repository/sagemaker-neo-pytorch because no resource-based policy allows the ecr:BatchGetImage action

已知条件

  • AWS用户已附加AmazonEC2ContainerRegistryPowerUser权限,该权限允许执行ecr:BatchGetImage操作
  • 可正常拉取763104351884.dkr.ecr.eu-west-2.amazonaws.com/pytorch-inference:2.0.0-gpu-py310镜像

解决方案

1. 验证托管仓库的资源策略

目标ECR仓库属于AWS托管的SageMaker镜像仓库,需确认你的IAM用户被仓库的资源策略允许访问。通过AWS CLI查看策略:

aws ecr get-repository-policy --repository-name sagemaker-neo-pytorch --registry-id 205493899709 --region eu-west-2

若策略未允许你的IAM用户/角色执行ecr:BatchGetImage和ecr:GetDownloadUrlForLayer操作,需检查是否有组织级权限限制或联系AWS支持。

2. 检查IAM用户的权限边界

即使附加了AmazonEC2ContainerRegistryPowerUser权限,若用户设置了权限边界,可能会阻止访问该托管仓库。在IAM控制台查看用户的权限边界,确保它未显式拒绝相关操作,或允许对目标仓库资源的访问。

3. 确认镜像标签有效性

可能指定的镜像标签1.9-inf-py3不存在于目标仓库。通过以下命令列出仓库所有镜像标签:

aws ecr list-images --repository-name sagemaker-neo-pytorch --registry-id 205493899709 --region eu-west-2

若标签不存在,选择官方文档中列出的有效标签。

4. 切换至SageMaker环境拉取

若直接用IAM用户拉取失败,可尝试通过SageMaker Studio终端拉取镜像——Studio默认使用的执行角色通常具备访问托管SageMaker镜像的权限。


内容的提问来源于stack exchange,提问作者Hassan Ansari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 21:58:10