aws / aws/sagemaker-python-sdk

Sagemaker Local-Mode permission errors

Offen
#4,764 2 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @pintaoz-aws Auf GitHub ansehen
type: bug
Vorherrschende Sprache
Python
Sterne
2.3k
Forks
1.3k
Ø Merge
1 T. 22 Std.
Gemergte PRs (30 T.)
35

Beschreibung

**Describe the bug**
I keep running into issues trying to run bring your own container (BYOC) images, they either work in local model, or they work in "cloud mode" but not both. The issue is almost certainly docker permission problems but I cannot see a way of resolving.

**To reproduce**
I have a docker image

```
FROM continuumio/miniconda3

WORKDIR /opt/ml/code/
COPY src/ /opt/ml/code/

ENTRYPOINT ["bash", "/opt/ml/code/processor.sh"]
```

The `processor.sh` creates a conda venv, installs packages into it then runs `conda pack` with the output set to `/opt/ml/processing/output/pyenv.tar.gz`

In `local` mode this step fails on this line

https://github.com/aws/sagemaker-python-sdk/blob/0e3769ea70a9b4c471a2bfb3a0f6116b9958361e/src/sagemaker/local/utils.py#L84

Because the container user (root) writes the file with permissions that are too restrictive. Note there's a "fix" on line 99 for a similar issue but it doesn't help.

I tried to work around this by adding a non-root (gid/pid 1000) user to the container. This "fixed" the local issue - but now the contain fails when I run it normally. It appears to be the opposite issue, the container user doesn't have access to the volume ` /opt/ml/processing/output/` so the script fails.

**Expected behavior**
Need to be able to run pipelines in local and sagemaker mode without permission errors. It seems that in local mode, scripts need to run with the same pid as the host user, but in sagemaker mode they need to run as root? Is there some way they can work in both?

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.