使用Terraform配置跨区域S3访问点对接SageMaker遇权限问题
问题场景
我有一个需要部署在不同AWS区域的SageMaker模型,模型文件存放在x区域的S3桶中。当模型部署在x区域时,终端节点正常工作;但部署在y区域时,出现以下错误:
Error: error creating SageMaker model: ValidationException: Could not access model data at s3://mmmm/. Please ensure that the role "arn:aws:iam::xxxx:role/dev-xxx-iam-role" exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com". Also ensure that the role has "s3:GetObject" permissions and that the object is located in region x.
当前IAM配置
权限策略附件
resource "aws_iam_policy_attachment" "sm_full_access_attach" { name = "sm-full-access-attachment" roles = [aws_iam_role.sagemaker_inferencer_iam_role.name] policy_arn = "arn:aws:iam::aws:policy/AmazonSageMakerFullAccess" } resource "aws_iam_policy_attachment" "s3_full_access_attach" { name = "s3-full-access-attachment" roles = [aws_iam_role.sagemaker_inferencer_iam_role.name] policy_arn = "arn:aws:iam::aws:policy/AmazonS3FullAccess" }
信任关系策略
data "aws_iam_policy_document" "sm_assume_role_policy" { statement { actions = ["sts:AssumeRole"] principals { type = "Service" identifiers = ["sagemaker.amazonaws.com"] } } }
IAM角色定义
resource "aws_iam_role" "sagemaker_inferencer_iam_role" { name = "${var.app_environment}-inferencer-sm-${var.aws_region}-iam-role" assume_role_policy = data.aws_iam_policy_document.sm_assume_role_policy.json }
上述配置在访问同区域S3桶时完全正常。由于模型文件体积庞大,跨区域复制成本过高,我为原S3桶创建了多区域访问点,别名是zzz.mrap。尝试在SageMaker模型资源中使用该访问点时:
resource "aws_sagemaker_model" "sagemaker_multimodel" { name = "${var.app_environment}-inferencer-sm-${var.aws_region}-model" execution_role_arn = aws_iam_role.sagemaker_inferencer_iam_role.arn primary_container { image = local.multi_model_inferencer_container_name mode = "MultiModel" model_data_url = "s3://zzz.mrap/" } }
仍然出现类似错误:
Error: error creating SageMaker model: ValidationException: Could not access model data at s3://zzzz.mrap/. Please ensure that the role "arn:aws:iam::878435376106:role/dev-xxx-iam-role" exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com". Also ensure that the role has "s3:GetObject" permissions and that the object is located in region x.
AWS文档说明只需将桶名替换为多区域访问点别名即可,且SageMaker支持该功能,但实际未生效。请问哪里配置出错了?
排查与解决建议
1. 多区域访问点URL格式错误
SageMaker中引用多区域访问点的正确格式应为s3://<访问点别名>.<12位AWS账号ID>.mrap/,你当前的配置缺少了账号ID部分。根据错误信息中的账号ID878435376106,修正后的配置应为:
model_data_url = "s3://zzz.mrap.878435376106/"
2. 多区域访问点资源策略未授权跨区域访问
即使IAM角色有S3全权限,多区域访问点自身的资源策略可能限制了来源区域。需要编辑访问点的资源策略,允许y区域的SageMaker服务访问:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "sagemaker.amazonaws.com" }, "Action": ["s3:GetObject"], "Resource": "arn:aws:s3:::zzz.mrap.878435376106/*", "Condition": { "StringEquals": { "aws:SourceRegion": "y-region" } } } ] }
3. 检查拼写与变量错误
错误信息中显示的访问点是zzzz.mrap,但你配置的是zzz.mrap,存在拼写不一致。同时确认Terraform中var.aws_region变量是否正确传递了y区域的值,避免角色或模型名称的区域匹配错误。
4. 验证多区域访问点状态
确保访问点已处于Active状态,可通过AWS CLI执行以下命令检查:
aws s3control list-multi-region-access-points --account-id 878435376106
内容的提问来源于stack exchange,提问作者toing_toing

