aws / aws/sagemaker-python-sdk

ModelTrainer (V3) does not support output_kms_key for source code uploads

未关闭
#5,956 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
2.3k
派生
1.3k
平均合并
1 天 22 小时
30 天内合并 PR
35

描述

## Describe the bug

In SageMaker SDK V2, the `Estimator` uses the `output_kms_key` when uploading user training scripts to S3 (see `_stage_user_code_in_s3`):
https://github.com/aws/sagemaker-python-sdk/blob/5b3b127a2d3d12a6ff0d877ddfd9ddf13527c27f/src/sagemaker/estimator.py#L1044-L1108

In SageMaker SDK V3, the new `ModelTrainer` does not apply any KMS key when uploading source code while creating the input data channel:
https://github.com/aws/sagemaker-python-sdk/blob/9101cef1a589cf2b44e73c5456dfa46c10e32691/sagemaker-train/src/sagemaker/train/model_trainer.py#L834-L953

Additionally, even when providing an S3 URI in the `SourceCode` object (instead of a local path), the `ModelTrainer` still uploads additional driver files whenever source code is specified:
https://github.com/aws/sagemaker-python-sdk/blob/9101cef1a589cf2b44e73c5456dfa46c10e32691/sagemaker-train/src/sagemaker/train/model_trainer.py#L684-L689

These uploads do not use a KMS key.

## Expected behavior

`ModelTrainer` should:
- either respect a user-provided KMS key (similar to `output_kms_key` in V2), OR
- allow configuration of a KMS key for all S3 uploads related to source code.

## Actual behavior

- Source code and driver files are uploaded to S3 without KMS encryption.
- There is no apparent way to configure a KMS key for these uploads.

## Impact

In restricted environments (like ours), S3 policies enforce server-side encryption with KMS.
As a result, `ModelTrainer` cannot be used with custom training scripts.

This blocks use cases that rely on custom code, such as MLflow serverless integration.

## Steps to reproduce

1. Create a `ModelTrainer` with a `SourceCode` object
2. Provide either:
- a local path, or
- an S3 URI
3. Observe that S3 uploads occur without KMS encryption

## Possible solution

Expose a parameter similar to `output_kms_key` in V2, or reuse existing encryption configuration mechanisms.

## Additional context

This is a regression compared to V2 `Estimator` behavior and impacts secure environments with strict S3 encryption policies.

贡献指南

打开贡献指南

调研方向

从 sagemaker-train/src/sagemaker/train/model_trainer.py 中 issue 所引用的 input-channel 和 driver-file 上传路径附近开始,然后将其与 src/sagemaker/estimator.py 中的 _stage_user_code_in_s3 进行比较。跟踪现有的加密配置,并为本地和 S3 SourceCode 上传添加有针对性的覆盖。完成标准是所有与源代码相关的上传都可以使用已配置的 KMS key。

由索引模型根据 Issue 内容生成。

评估

技术栈
aws, python
领域
cloud, machine-learning
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
68/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。