如何通过Python SDK将Azure ML计算实例分配给指定用户
解决Azure ML计算实例分配给指定用户的问题
当使用服务主体创建Azure ML计算实例时,实例的默认权限归属服务主体,导致你的用户账号无法访问。可以通过RBAC角色分配的方式,将计算实例的访问权限授予指定用户,具体步骤如下:
1. 确认服务主体权限
确保用于认证的服务主体拥有以下任一权限:
- 工作区或计算实例资源的Owner角色
- 工作区或计算实例资源的User Access Administrator角色
无上述权限将无法为用户分配角色。
2. 获取计算实例的资源ID
通过Azure ML SDK获取目标计算实例的资源ID:
from azureml.core.compute import ComputeInstance compute_name = "light-medium-gabriel-2nd" instance = ComputeInstance(workspace=ws, name=compute_name) compute_resource_id = instance.id
3. 安装所需依赖包
执行以下命令安装Azure权限管理相关SDK:
pip install azure-mgmt-authorization uuid
4. 为指定用户分配计算实例访问角色
通过Azure权限管理SDK,将Azure ML Compute Instance User角色(或更高权限角色)分配给目标用户:
from azure.mgmt.authorization import AuthorizationManagementClient from azure.mgmt.authorization.models import RoleAssignmentCreateParameters import uuid # 初始化权限管理客户端 auth_client = AuthorizationManagementClient( credential=svc_pr, subscription_id=ws.subscription_id ) # 替换为目标用户的Azure AD Object ID(从Azure门户用户配置文件中获取) target_user_object_id = "your_user_object_id" # 获取"Azure ML Compute Instance User"角色的定义ID role_definition = auth_client.role_definitions.get( scope=f"/subscriptions/{ws.subscription_id}", role_definition_name="Azure ML Compute Instance User" ) role_definition_id = role_definition.id # 创建角色分配 role_assignment = auth_client.role_assignments.create( scope=compute_resource_id, role_assignment_name=str(uuid.uuid4()), # 生成唯一分配ID parameters=RoleAssignmentCreateParameters( role_definition_id=role_definition_id, principal_id=target_user_object_id, principal_type="User" ) ) print(f"角色分配成功,分配ID:{role_assignment.id}")
可选:分配更高权限角色
如果需要用户拥有更多工作区权限(如管理计算实例、运行实验等),可将Azure ML Data Scientist角色分配给用户,只需将上述代码中的role_definition_name替换为"Azure ML Data Scientist"即可。
验证权限
完成角色分配后,刷新Azure ML工作室页面,即可访问目标计算实例。
内容的提问来源于stack exchange,提问作者Gabriel Padilha
相关产品推荐
相关产品推荐

