You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为VPC内运行的SageMaker服务配置boto3 IAM连接代理

VPC环境下SageMaker Estimator IAM请求代理配置方案

核心逻辑

SageMaker Python SDK发起的所有AWS API请求(含IAM签名请求)完全依赖传入的boto3 Session实现,代理配置只需在boto3 Session层完成,再绑定到SageMaker Session即可生效,无需在Estimator或fit方法中单独配置。

具体配置步骤

  1. 初始化带代理配置的boto3 Session
import boto3
from botocore.config import Config
from sagemaker.session import Session
from sagemaker.estimator import Estimator

# 定义代理规则
proxy_config = Config(
    proxies={
        "http": "http://<代理地址>:<代理端口>",
        "https": "http://<代理地址>:<代理端口>"
    },
    # 代理使用自签名证书时添加该参数,无需可删除
    verify="/path/to/custom/ca.crt"
)

# 初始化boto3 Session,可按需指定区域、身份凭证等参数
boto3_session = boto3.Session(region_name="<AWS区域代码>")
# 绑定代理配置到boto3 Session全局配置
boto3_session._session.set_config_variable("proxies", proxy_config.proxies)
  1. 生成绑定了代理配置的SageMaker Session
sagemaker_session = Session(boto_session=boto3_session)
  1. 初始化Estimator并调用fit方法
estimator = Estimator(
    image_uri="<训练镜像URI>",
    role="<IAM训练角色ARN>",
    instance_count=1,
    instance_type="ml.m5.xlarge",
    sagemaker_session=sagemaker_session,
    # 其他Estimator自定义参数
)

# 此时fit方法发起的所有IAM签名请求都会自动走配置的代理
estimator.fit()

注意事项

  • 需提前确认VPC安全组、路由规则允许当前环境访问代理地址,且代理已放通AWS服务端点的访问权限
  • 若代理需要身份认证,代理地址格式调整为http://<用户名>:<密码>@<代理地址>:<代理端口>即可
  • 上述配置仅作用于本地发起的SageMaker API请求,若训练作业内部的代码也需要走代理,需额外在Estimator的environment参数中传入HTTP_PROXY、HTTPS_PROXY环境变量,两类配置互相独立不通用

内容的提问来源于stack exchange,提问作者ptwats

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.29 01:42:00