> ## Documentation Index
> Fetch the complete documentation index at: https://anaconda.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Train and deploy models with Amazon SageMaker

export const Comments = ({children}) => {
  return <div class="my-4 px-5 py-4 overflow-hidden rounded-2xl flex gap-3 border border-zinc-500/20 bg-zinc-50/50 dark:border-zinc-500/30 dark:bg-zinc-500/10" data-callout-type="comments">
      <div class="w-4">
        <svg width="14" height="14" viewBox="0 0 640 640" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="w-5 h-5" aria-label="Comments">
            <path d="M320 112C434.9 112 528 205.1 528 320C528 434.9 434.9 528 320 528C205.1 528 112 434.9 112 320C112 205.1 205.1 112 320 112zM320 576C461.4 576 576 461.4 576 320C576 178.6 461.4 64 320 64C178.6 64 64 178.6 64 320C64 461.4 178.6 576 320 576zM280 400C266.7 400 256 410.7 256 424C256 437.3 266.7 448 280 448L360 448C373.3 448 384 437.3 384 424C384 410.7 373.3 400 360 400L352 400L352 312C352 298.7 341.3 288 328 288L280 288C266.7 288 256 298.7 256 312C256 325.3 266.7 336 280 336L304 336L304 400L280 400zM320 256C337.7 256 352 241.7 352 224C352 206.3 337.7 192 320 192C302.3 192 288 206.3 288 224C288 241.7 302.3 256 320 256z" />
        </svg>
      </div>
      <div class="text-sm prose min-w-0 w-full">
        {children}
      </div>
    </div>;
};

This tutorial walks you through connecting Anaconda Platform to Amazon SageMaker so you can launch training jobs and deploy model endpoints from your workstations and Metaflow flows.

<Note>
  Creating a resource integration requires an administrator role. If you do not have administrator access, ask your administrator to create the integration before you begin.
</Note>

By the end of this tutorial, you will have:

* An IAM role with SageMaker execution permissions, chained to the platform
* An S3 bucket for training artifacts
* A workstation notebook that trains and deploys a model on SageMaker
* A Metaflow flow that automates the training and deployment pipeline

## Create SageMaker resources

Open both the Anaconda Platform UI and the AWS console for the account you want to use with SageMaker.

### Set up a SageMaker execution role

Create an IAM role for SageMaker.

1. In the AWS console, select the **SageMaker - Execution** use case when creating the role.

The role requires three properties:

1. **Permissions policies**: Attach the `AmazonSageMakerFullAccess` policy, or your organization's modified SageMaker execution role policy. This allows the role to perform actions on SageMaker resources.

2. **Trust relationship**: The role must trust the Anaconda Platform task role as a principal. The trust policy should look like this:

   ```json expandable IAM trust policy template theme={null}
   {
       "Version": "2012-10-17",
       "Statement": [
           {
               "Effect": "Allow",
               "Principal": {
                   "Service": "sagemaker.amazonaws.com"
               },
               "Action": [
                   "sts:AssumeRole",
                   "sts:SetSourceIdentity"
               ]
           },
           {
               "Effect": "Allow",
               "Principal": {
                   "AWS": "arn:aws:iam::<AWS_ACCOUNT_ID_OUTERBOUNDS_DATAPLANE>:role/obp-<UNIQUE_CODE>-task"
               },
               "Action": [
                   "sts:AssumeRole",
                   "sts:SetSourceIdentity"
               ]
           }
       ]
   }
   ```

   <Comments>
     Replace \<AWS\_ACCOUNT\_ID\_OUTERBOUNDS\_DATAPLANE> with your platform's AWS account ID.<br />
     Replace \<UNIQUE\_CODE> with your deployment's unique code.<br />
     You can find both values in the Anaconda Platform UI: select **Integrations** in the left-hand navigation, click **AWS** in the **Add an Integration** section, and expand the **Getting your IAM role ARN** section.
   </Comments>

3. **Tag**: Tag the role with the key `outerbounds.com/accessible-by-deployment` and the value from your Anaconda Platform deployment. The same Integrations panel section shows the value to use.

### Set up a SageMaker bucket

Create an S3 bucket for SageMaker to store training artifacts. Any bucket works, including an existing one. The default name used in this tutorial is `sagemaker-outerbounds-demo`. You will need to choose a different name because S3 bucket names are globally unique.

After creating the bucket, attach a bucket policy that allows your SageMaker execution role to operate on it:

```json expandable S3 bucket policy template theme={null}
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::<AWS_ACCOUNT_ID_SAGEMAKER>:role/<SAGEMAKER_EXECUTION_ROLE>"
            },
            "Action": [
                "s3:PutObject",
                "s3:GetObject"
            ],
            "Resource": "arn:aws:s3:::<S3_SAGEMAKER_BUCKET_NAME>/*"
        },
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::<AWS_ACCOUNT_ID_SAGEMAKER>:role/<SAGEMAKER_EXECUTION_ROLE>"
            },
            "Action": "s3:ListBucket",
            "Resource": "arn:aws:s3:::<S3_SAGEMAKER_BUCKET_NAME>"
        }
    ]
}
```

<Comments>
  Replace \<AWS\_ACCOUNT\_ID\_SAGEMAKER> with your AWS account ID.<br />
  Replace \<SAGEMAKER\_EXECUTION\_ROLE> with the name of the SageMaker execution role you created.<br />
  Replace \<S3\_SAGEMAKER\_BUCKET\_NAME> with your bucket name.
</Comments>

### Register the role as an integration

1. Select **Integrations** in the left-hand navigation.
2. Click **AWS** in the **Add an Integration** section.
3. Enter a name for the integration.
4. Enter a description for the integration.
5. Enter the Amazon Resource Name (ARN) of the SageMaker execution role.
6. Click **Add**.

After the integration is created, the **How to use** tab in the integration panel shows a code snippet with the exact `role_arn` value for your flows.

## Download the tutorial content

Download the tutorial content to your workstation:

```bash theme={null}
outerbounds tutorials pull --url https://outerbounds-journeys-content.s3.us-west-2.amazonaws.com/main/journeys.tar.gz --destination-dir ~/learn
```

<Tip>
  This command downloads all tutorial content as a single bundle. If you've already worked through other tutorials, you likely already have this and do not need to run the command again.
</Tip>

The SageMaker tutorial content is in `~/learn/sagemaker`. If you prefer a different location, replace `~/learn` with a directory of your choice.

## Validate the role

Open the notebook in `00-assume-role-nb` from the `~/learn/sagemaker` directory. This notebook validates that your IAM role chaining works correctly and explains how IAM roles interact with the platform.

## Train and deploy from a notebook

Open the notebook in `01-train-deploy-nb` from the `~/learn/sagemaker` directory. Before running it, update the role ARN and bucket name variables with the values you created earlier. This notebook walks you through training a model and deploying it as a SageMaker endpoint.

## Train and deploy from a flow

Open the `02-train-deploy-flow` directory from the `~/learn/sagemaker` directory. This directory contains a Metaflow flow that automates training and deployment. Before running it, update the `sagemaker_execution_role_arn` and `bucket_name` variables in `flow.py` with the same values you used in the notebooks.

Run the flow:

```bash theme={null}
python flow.py --environment=fast-bakery run --with kubernetes
```

## Test the endpoint

Open the notebook in `03-test-endpoint-nb` from the `~/learn/sagemaker` directory. This notebook walks through testing the SageMaker endpoint you deployed.

## Clean up

Open the notebook in `04-cleanup-nb` from the `~/learn/sagemaker` directory. This notebook walks through deleting the resources you created in this tutorial.
