You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform创建AWS SageMaker多模型遇错误求助

AWS SageMaker多模型模式创建失败排查

问题描述

尝试使用Terraform在us-west-1区域以多模型模式创建AWS SageMaker模型,但遇到一系列异常,同款配置在eu-west-1区域可正常运行。已确认us-west-1区域的ECR仓库存在目标镜像、S3桶配置与eu-west-1一致、IAM角色权限及信任关系配置正确。

待创建资源定义

module.main.module.toing.aws_sagemaker_model.sagemaker_multimodel will be created
  + resource "aws_sagemaker_model" "sagemaker_multimodel" {
      + arn                = (known after apply)
      + execution_role_arn = "arn:aws:iam::XXXXX:role/us-west-1-toing_role"
      + id                 = (known after apply)
      + name               = "dev-us-west-test-model"
      + primary_container {
          + image          = "us-west-1-toing_image"
          + mode           = "MultiModel"
          + model_data_url = "s3://toing_bucket/"
        }
    }

报错历程

  • 首次执行Terraform apply失败

    Error: creating SageMaker model: ValidationException: The execution role ARN "arn:aws:iam::XXXXX:role/us-west-1-toing_role" is invalid. Please ensure that the role exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com".
    │       status code: 400, request id: XXX-XXX-XXX-XXX-XXX
    
  • 重试后异常
    Terraform进程挂起,查看CloudTrail发现CreateModel请求反复返回:

    ...
    "errorCode": "InternalFailure",
    "errorMessage": "An unknown error occurred",
    ...
    
  • GUI手动创建测试
    先出现ThrottlingException,等待一段时间后重试仍返回InternalFailure。

IAM角色配置确认

信任关系

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "Service": "sagemaker.amazonaws.com"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}

权限策略

  • AmazonS3FullAccess
  • AmazonSageMakerFullAccess

关联Terraform代码

# Defining the SageMaker "Assume Role" policy
data "aws_iam_policy_document" "sm_assume_role_policy" {
  statement {
    actions = ["sts:AssumeRole"]

    principals {
      type        = "Service"
      identifiers = ["sagemaker.amazonaws.com"]
    }
  }
}

resource "aws_iam_role" "sagemaker_inferencer_iam_role" {
  name               = "${var.app_environment}-inferencer-sm-${var.aws_region}-iam-role-${var.endpoint_postfix}"
  assume_role_policy = data.aws_iam_policy_document.sm_assume_role_policy.json
}

# Attaching the AWS default policy, "AmazonSageMakerFullAccess"
data "aws_iam_policy" "sm_required_policy" {
  name = "AmazonSageMakerFullAccess"
}

resource "aws_iam_role_policy_attachment" "sm_full_access_attach" {
  role       = aws_iam_role.sagemaker_inferencer_iam_role.name
  policy_arn = data.aws_iam_policy.sm_required_policy.arn
}

# Attaching the AWS default policy, "AmazonS3FullAccess"
data "aws_iam_policy" "s3_required_policy" {
  name = "AmazonS3FullAccess"
}

resource "aws_iam_role_policy_attachment" "s3_full_access_attach" {
  role       = aws_iam_role.sagemaker_inferencer_iam_role.name
  policy_arn = data.aws_iam_policy.s3_required_policy.arn
}

resource "aws_sagemaker_model" "sagemaker_multimodel" {
  name               = "${var.app_environment}-${var.endpoint_postfix}-model"
  execution_role_arn = aws_iam_role.sagemaker_inferencer_iam_role.arn

  primary_container {
    image          = local.multi_model_inferencer_container_name
    mode           = "MultiModel"
    model_data_url = "s3://${local.model_bucket_name}/"
  }

  tags = var.default_tags
}

提问

请问我哪里配置出错了?


内容的提问来源于stack exchange,提问作者toing_toing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 22:35:43