You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform配置跨区域S3访问点对接SageMaker遇权限问题

SageMaker跨区域访问S3多区域访问点失败排查

问题场景

我有一个需要部署在不同AWS区域的SageMaker模型,模型文件存放在x区域的S3桶中。当模型部署在x区域时,终端节点正常工作;但部署在y区域时,出现以下错误:

Error: error creating SageMaker model: ValidationException: Could not access model data at s3://mmmm/. Please ensure that the role "arn:aws:iam::xxxx:role/dev-xxx-iam-role" exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com". Also ensure that the role has "s3:GetObject" permissions and that the object is located in region x.

当前IAM配置

权限策略附件

resource "aws_iam_policy_attachment" "sm_full_access_attach" {
  name       = "sm-full-access-attachment"
  roles      = [aws_iam_role.sagemaker_inferencer_iam_role.name]
  policy_arn = "arn:aws:iam::aws:policy/AmazonSageMakerFullAccess"
}

resource "aws_iam_policy_attachment" "s3_full_access_attach" {
  name       = "s3-full-access-attachment"
  roles      = [aws_iam_role.sagemaker_inferencer_iam_role.name]
  policy_arn = "arn:aws:iam::aws:policy/AmazonS3FullAccess"
}

信任关系策略

data "aws_iam_policy_document" "sm_assume_role_policy" {
  statement {
    actions = ["sts:AssumeRole"]

    principals {
      type        = "Service"
      identifiers = ["sagemaker.amazonaws.com"]
    }
  }
}

IAM角色定义

resource "aws_iam_role" "sagemaker_inferencer_iam_role" {
  name               = "${var.app_environment}-inferencer-sm-${var.aws_region}-iam-role"
  assume_role_policy = data.aws_iam_policy_document.sm_assume_role_policy.json
}

上述配置在访问同区域S3桶时完全正常。由于模型文件体积庞大,跨区域复制成本过高,我为原S3桶创建了多区域访问点,别名是zzz.mrap。尝试在SageMaker模型资源中使用该访问点时:

resource "aws_sagemaker_model" "sagemaker_multimodel" {
  name               = "${var.app_environment}-inferencer-sm-${var.aws_region}-model"
  execution_role_arn = aws_iam_role.sagemaker_inferencer_iam_role.arn

  primary_container {
    image          = local.multi_model_inferencer_container_name
    mode           = "MultiModel"
    model_data_url = "s3://zzz.mrap/"
  }
}

仍然出现类似错误:

Error: error creating SageMaker model: ValidationException: Could not access model data at s3://zzzz.mrap/. Please ensure that the role "arn:aws:iam::878435376106:role/dev-xxx-iam-role" exists and that its trust relationship policy allows the action "sts:AssumeRole" for the service principal "sagemaker.amazonaws.com". Also ensure that the role has "s3:GetObject" permissions and that the object is located in region x.

AWS文档说明只需将桶名替换为多区域访问点别名即可,且SageMaker支持该功能,但实际未生效。请问哪里配置出错了?


排查与解决建议

1. 多区域访问点URL格式错误

SageMaker中引用多区域访问点的正确格式应为s3://<访问点别名>.<12位AWS账号ID>.mrap/,你当前的配置缺少了账号ID部分。根据错误信息中的账号ID878435376106,修正后的配置应为:

model_data_url = "s3://zzz.mrap.878435376106/"

2. 多区域访问点资源策略未授权跨区域访问

即使IAM角色有S3全权限,多区域访问点自身的资源策略可能限制了来源区域。需要编辑访问点的资源策略,允许y区域的SageMaker服务访问:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "Service": "sagemaker.amazonaws.com"
      },
      "Action": ["s3:GetObject"],
      "Resource": "arn:aws:s3:::zzz.mrap.878435376106/*",
      "Condition": {
        "StringEquals": {
          "aws:SourceRegion": "y-region"
        }
      }
    }
  ]
}

3. 检查拼写与变量错误

错误信息中显示的访问点是zzzz.mrap,但你配置的是zzz.mrap,存在拼写不一致。同时确认Terraform中var.aws_region变量是否正确传递了y区域的值,避免角色或模型名称的区域匹配错误。

4. 验证多区域访问点状态

确保访问点已处于Active状态,可通过AWS CLI执行以下命令检查:

aws s3control list-multi-region-access-points --account-id 878435376106

内容的提问来源于stack exchange,提问作者toing_toing

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 09:10:28