Azure / Azure/MachineLearningNotebooks

Unable to pull custom docker image in Compute Cluster from Azure private registry

Aberta
#1,733 0 comentários 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
Jupyter Notebook
Estrelas
4.4k
Forks
2.6k
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

Hi,

I have created a new machine learning environment with a connected ACR (without admin keys enabled).
We also have created a User assigned managed identity to enable managed identity authentication for the compute clusters. This identity has the ACRPull role assigned on the connected ACR.

However, when we try the following Python code as seen in the [documentation](https://docs.microsoft.com/en-us/azure/machine-learning/how-to-use-managed-identities?tabs=python#pull-docker-base-image-to-machine-learning-compute-cluster-for-training-as-is), it does not work:
```
env = Environment(name="private-acr")
env.docker.base_image = "as01weuacrom4vosf3mpux7.azurecr.io/custom:v1"
env.python.user_managed_dependencies = True
```
```
We get the following error message:
AzureMLCompute job failed.
FailedPullingImage: Unable to pull docker image
imageName: as01weuacrom4vosf3mpux7.azurecr.io/custom:v1
error: Run docker command to pull public image failed with error: Error response from daemon: Head "https://as01weuacrom4vosf3mpux7.azurecr.io/v2/custom/manifests/v1": unauthorized: authentication required, visit https://aka.ms/acr/authorization for more information.
.
Reason: Error response from daemon: Head "https://as01weuacrom4vosf3mpux7.azurecr.io/v2/custom/manifests/v1": unauthorized: authentication required, visit https://aka.ms/acr/authorization for more information.

Info: Failed to setup runtime for job execution: Job environment preparation failed on 10.235.22.6 with err exit status 1.
```
We also tried to build the image in ACR, but it also does not authenticate automatically.
The only way we can get this to work is when we enable ACR access keys, but this obviously is not a preferred solution.

Please not that all resources are behind a vnet, including the compute cluster which has public ip disabled.

Can you please advice what to do next, or what we can try?

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Direção de pesquisa

Comece pela documentação vinculada de managed-identities e pela configuração de Environment mostrada na issue; em seguida, inspecione o erro do AzureMLCompute ao fazer pull da imagem e a configuração descrita do ACR e da managed identity. A tarefa estará concluída quando for identificada uma configuração ou correção documentada que permita fazer pull da imagem privada sem habilitar ACR access keys, incluindo as restrições indicadas de VNet e public-IP-disabled.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
azure, docker, python
Domínio
authentication, cloud, machine-learning
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
25/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.