Azure ML SDK v2上传组件遇认证错误及模型导入咨询
问题描述
使用Azure ML SDK v2向工作区注册组件时遇到认证错误,已确认存储账户防火墙允许所有网络访问,但问题仍存在。期望组件能成功注册到Azure ML工作区,同时咨询如何将Azure Model Registry中的模型导入Azure ML Pipelines。
代码与错误信息
认证与MLClient初始化代码
subscription_id = "XXXX" resource_group = "XXXX" workspace_name = "XXXX" credential = InteractiveBrowserCredential() ml_client = MLClient(credential, subscription_id, resource_group, workspace_name) workspace = ml_client.workspaces.get(name=ml_client.workspace_name)
组件注册代码
from components import optimizer ml_client.components.create_or_update(optimizer)
错误回溯
ClientAuthenticationError Traceback (most recent call last) ~\AppData\Local\Temp\ipykernel_21948\2530497008.py in <module> 1 from components import optimizer ----> 2 ml_client.components.create_or_update(optimizer) c:\Users\Alan\miniconda3\envs\azureml\lib\site-packages\azure\ai\ml\operations\_component_operations.py in create_or_update(self, component, version, skip_validation, **kwargs) 294 295 # Create all dependent resources ---> 296 self._resolve_arm_id_or_upload_dependencies(component) 297 298 component._update_anonymous_hash() c:\Users\Alan\miniconda3\envs\azureml\lib\site-packages\azure\ai\ml\operations\_component_operations.py in _resolve_arm_id_or_upload_dependencies(self, component) 439 440 # resolve component's code ---> 441 _try_resolve_code_for_component(component=component, get_arm_id_and_fill_back=get_arm_id_and_fill_back) 442 # resolve component's environment 443 if hasattr(component, "environment"): c:\Users\Alan\miniconda3\envs\azureml\lib\site-packages\azure\ai\ml\operations\_component_operations.py in _try_resolve_code_for_component(component, get_arm_id_and_fill_back) 603 with component._resolve_local_code() as code_path: 604 component.code = get_arm_id_and_fill_back( ---> 605 Code(base_path=component._base_path, path=code_path), azureml_type=AzureMLResourceType.CODE 606 ) ... c:\Users\Alan\miniconda3\envs\azureml\lib\site-packages\azure\storage\blob\_shared\response_handlers.py in <module> ClientAuthenticationError: Operation returned an invalid status 'Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature.' ErrorCode:AuthenticationFailed
组件注册认证错误的解决方案
- 检查账户权限:确保用于认证的账户拥有Azure ML工作区关联存储账户的存储Blob数据贡献者角色,SDK v2上传组件代码时需要直接操作存储Blob,仅ML工作区权限不足以完成该操作。
- 替换认证方式:尝试使用
DefaultAzureCredential替代InteractiveBrowserCredential,它会自动尝试环境变量、Azure CLI、托管标识等多种认证途径,避免单一认证方式的问题:
from azure.ai.ml import MLClient from azure.identity import DefaultAzureCredential ml_client = MLClient(DefaultAzureCredential(), subscription_id, resource_group, workspace_name)
- 更新依赖包:旧版本的
azure-ai-ml或azure-storage-blob可能存在签名认证bug,执行以下命令更新到最新版本:
pip install --upgrade azure-ai-ml azure-storage-blob
- 验证系统时间:本地机器时间与Azure服务器时间偏差过大时,会导致签名验证失败,确保本地系统时间正确同步。
从Azure Model Registry导入模型到Azure ML Pipelines
在SDK v2中可通过以下步骤实现:
- 从Model Registry获取模型:使用MLClient查询目标模型,支持按名称+版本或名称+标签查询:
model = ml_client.models.get(name="your-model-name", version="1") # 或按标签查询:model = ml_client.models.get(name="your-model-name", label="production")
- 在Pipeline组件中引用模型:将模型作为组件的输入,指定类型为
mlflow_model(或对应模型类型),示例如下:
from azure.ai.ml import Input, Output, command from azure.ai.ml.constants import AssetTypes from azure.ai.ml.dsl import pipeline # 定义使用模型的推理组件 score_component = command( name="model_scoring", inputs={ "trained_model": Input(type=AssetTypes.MLFLOW_MODEL, path=model.id), "test_data": Input(type=AssetTypes.URI_FILE, path="./data/test.csv") }, outputs={"scored_results": Output(type=AssetTypes.URI_FILE)}, code="./scoring_code", command="python score.py --model ${{inputs.trained_model}} --data ${{inputs.test_data}} --output ${{outputs.scored_results}}" ) # 定义并运行Pipeline @pipeline() def scoring_pipeline(): score_step = score_component() pipeline_job = scoring_pipeline() ml_client.jobs.create_or_update(pipeline_job, experiment_name="model-scoring-experiment")
内容的提问来源于stack exchange,提问作者WeMoveOn
相关产品推荐
相关产品推荐

