【发布时间】:2020-01-19 02:10:47
【问题描述】:
我有一个要自动扩展的 sagemaker 实例,目前它正在处理 4 个实例,但我想根据负载将其从 1 个自动扩展为 4 个。
这是我用来自动缩放的代码
resource_id = 'endpoint/[end-point-name]/variant/config1'
sc_client = boto3.client('application-autoscaling')
role = 'arn:aws:iam::[1234]:role/service-role/AmazonSageMaker-ExecutionRole-[1234]'
response = sc_client.register_scalable_target(
ServiceNamespace='sagemaker',
ResourceId=resource_id,
ScalableDimension='sagemaker:variant:DesiredInstanceCount',
MinCapacity=1,
MaxCapacity=4,
RoleARN= role,
SuspendedState={
'DynamicScalingInSuspended': True,
'DynamicScalingOutSuspended': True,
'ScheduledScalingSuspended': True
}
)
我已将所有资源的所有访问权限(sagemaker 和 cloudwatch)授予此角色:AmazonSageMaker-ExecutionRole-[1234]
现在每当我运行此代码时都会收到此错误
ClientError: An error occurred (AccessDeniedException) when calling the RegisterScalableTarget
operation: User: arn:aws:sts::[1234]:assumed-role/AmazonSageMaker-ExecutionRole-[1234]/SageMaker
is not authorized to perform: iam:PassRole on resource: arn:aws:iam::[1234]:role/service-role/AmazonSageMaker-ExecutionRole-[1234]
现在我不确定它是如何选择“假定角色”而不是“服务角色”以及如何解决问题,我正在使用具有所有访问权限的管理员帐户和上述“服务角色”拥有所有访问权限
【问题讨论】:
标签: amazon-web-services aws-sdk amazon-sagemaker