Creating a resource integration requires an administrator role. If you do not have administrator access, ask your administrator to create the integration before you begin.
- An IAM role with SageMaker execution permissions, chained to the platform
- An S3 bucket for training artifacts
- A workstation notebook that trains and deploys a model on SageMaker
- A Metaflow flow that automates the training and deployment pipeline
Create SageMaker resources
Open both the Anaconda Platform UI and the AWS console for the account you want to use with SageMaker.Set up a SageMaker execution role
Create an IAM role for SageMaker.- In the AWS console, select the SageMaker - Execution use case when creating the role.
-
Permissions policies: Attach the
AmazonSageMakerFullAccesspolicy, or your organization’s modified SageMaker execution role policy. This allows the role to perform actions on SageMaker resources. -
Trust relationship: The role must trust the Anaconda Platform task role as a principal. The trust policy should look like this:
IAM trust policy template
-
Tag: Tag the role with the key
outerbounds.com/accessible-by-deploymentand the value from your Anaconda Platform deployment. The same Integrations panel section shows the value to use.
Set up a SageMaker bucket
Create an S3 bucket for SageMaker to store training artifacts. Any bucket works, including an existing one. The default name used in this tutorial issagemaker-outerbounds-demo. You will need to choose a different name because S3 bucket names are globally unique.
After creating the bucket, attach a bucket policy that allows your SageMaker execution role to operate on it:
S3 bucket policy template
Register the role as an integration
- Select Integrations in the left-hand navigation.
- Click AWS in the Add an Integration section.
- Enter a name for the integration.
- Enter a description for the integration.
- Enter the Amazon Resource Name (ARN) of the SageMaker execution role.
- Click Add.
role_arn value for your flows.
Download the tutorial content
Download the tutorial content to your workstation:~/learn/sagemaker. If you prefer a different location, replace ~/learn with a directory of your choice.
Validate the role
Open the notebook in00-assume-role-nb from the ~/learn/sagemaker directory. This notebook validates that your IAM role chaining works correctly and explains how IAM roles interact with the platform.
Train and deploy from a notebook
Open the notebook in01-train-deploy-nb from the ~/learn/sagemaker directory. Before running it, update the role ARN and bucket name variables with the values you created earlier. This notebook walks you through training a model and deploying it as a SageMaker endpoint.
Train and deploy from a flow
Open the02-train-deploy-flow directory from the ~/learn/sagemaker directory. This directory contains a Metaflow flow that automates training and deployment. Before running it, update the sagemaker_execution_role_arn and bucket_name variables in flow.py with the same values you used in the notebooks.
Run the flow:
Test the endpoint
Open the notebook in03-test-endpoint-nb from the ~/learn/sagemaker directory. This notebook walks through testing the SageMaker endpoint you deployed.
Clean up
Open the notebook in04-cleanup-nb from the ~/learn/sagemaker directory. This notebook walks through deleting the resources you created in this tutorial.