使用Terraform创建AWS SageMaker多模型遇错误求助
AWS SageMaker多模型模式创建失败排查
问题描述
尝试使用Terraform在us-west-1区域以多模型模式创建AWS SageMaker模型,但遇到一系列异常,同款配置在eu-west-1区域可正常运行。已确认us-west-1区域的ECR仓库存在目标镜像、S3桶配置与eu-west-1一致、IAM角色权限及信任关系配置正确。
待创建资源定义
module.main.module.toing.aws_sagemaker_model.sagemaker_multimodel will be created + resource "aws_sagemaker_model" "sagemaker_multimodel" { + arn = (known after apply) + execution_role_arn = "arn:aws:iam::XXXXX:role/us-west-1-toing_role" + id = (known after apply) + name = "dev-us-west-test-model" + primary_container { + image = "us-west-1-toing_image" + mode = "MultiModel" + model_data_url = "s3://toing_bucket/" } }
报错历程
首次执行Terraform apply失败
Error: creating SageMaker model: ValidationException: The execution role ARN "arn:aws:iam::XXXXX:role/us-west-1-toing_role" is invalid. Please ensure that the role exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com". │ status code: 400, request id: XXX-XXX-XXX-XXX-XXX重试后异常
Terraform进程挂起,查看CloudTrail发现CreateModel请求反复返回:... "errorCode": "InternalFailure", "errorMessage": "An unknown error occurred", ...GUI手动创建测试
先出现ThrottlingException,等待一段时间后重试仍返回InternalFailure。
IAM角色配置确认
信任关系
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "sagemaker.amazonaws.com" }, "Action": "sts:AssumeRole" } ] }
权限策略
- AmazonS3FullAccess
- AmazonSageMakerFullAccess
关联Terraform代码
# Defining the SageMaker "Assume Role" policy data "aws_iam_policy_document" "sm_assume_role_policy" { statement { actions = ["sts:AssumeRole"] principals { type = "Service" identifiers = ["sagemaker.amazonaws.com"] } } } resource "aws_iam_role" "sagemaker_inferencer_iam_role" { name = "${var.app_environment}-inferencer-sm-${var.aws_region}-iam-role-${var.endpoint_postfix}" assume_role_policy = data.aws_iam_policy_document.sm_assume_role_policy.json } # Attaching the AWS default policy, "AmazonSageMakerFullAccess" data "aws_iam_policy" "sm_required_policy" { name = "AmazonSageMakerFullAccess" } resource "aws_iam_role_policy_attachment" "sm_full_access_attach" { role = aws_iam_role.sagemaker_inferencer_iam_role.name policy_arn = data.aws_iam_policy.sm_required_policy.arn } # Attaching the AWS default policy, "AmazonS3FullAccess" data "aws_iam_policy" "s3_required_policy" { name = "AmazonS3FullAccess" } resource "aws_iam_role_policy_attachment" "s3_full_access_attach" { role = aws_iam_role.sagemaker_inferencer_iam_role.name policy_arn = data.aws_iam_policy.s3_required_policy.arn } resource "aws_sagemaker_model" "sagemaker_multimodel" { name = "${var.app_environment}-${var.endpoint_postfix}-model" execution_role_arn = aws_iam_role.sagemaker_inferencer_iam_role.arn primary_container { image = local.multi_model_inferencer_container_name mode = "MultiModel" model_data_url = "s3://${local.model_bucket_name}/" } tags = var.default_tags }
提问
请问我哪里配置出错了?
内容的提问来源于stack exchange,提问作者toing_toing
相关产品推荐
相关产品推荐

