SageMakerClient ignores the passed boto3 session for the "sagemaker" client since 2.13.0 — all resource API calls sign with default-chain credentials
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 58/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 静か
- 技術スタック
- aws, python
調査の方向性
sagemaker-core/src/sagemaker/core/utils/utils.py の SageMakerClient.init から開始し、次に Base.get_sagemaker_client(session=...) と get_client("sagemaker") を追跡します。AWS リソースを作成せずに、提供された認証情報比較の再現を実行します。明示的に渡されたセッションの認証情報で sagemaker クライアントが署名し、カスタムサービスモデルの動作が維持されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
TL;DR — Since sagemaker-core 2.13.0, SageMakerClient ignores the session= the caller passed and builds its main sagemaker client from a fresh default-chain session. Every V3 resource API call (FeatureGroup.create, Model.create, describe/delete/list, …) is silently signed with ambient credentials instead of the caller's.
Besides breaking explicit-session workflows, this is a quiet identity mix-up with a security edge: code written to run under a scoped or assumed role can instead execute under a less-privileged (or worse a more-privileged) ambient identity, with no error or warning. Last good version: 2.12.0. Workaround: pin sagemaker-core>=2.12,<2.13.
PySDK Version
- PySDK V2 (2.x)
- PySDK V3 (3.x)
Describe the bug
SageMakerClient.__init__ (sagemaker-core/src/sagemaker/core/utils/utils.py) contains a block introduced by #5919 (merged 2026-06-03, released as sagemaker-core 2.13.0) that loads a custom service model for pre-GA Job APIs through a brand-new botocore session:
# TODO: Remove post-launch. This loads a custom botocore service model
# (from the 'sample/' directory) that includes pre-GA Job APIs ...
bc_session = bc_session_mod.get_session()
...
custom_session = Session(botocore_session=bc_session, region_name=env_region)
self.sagemaker_client = custom_session.client("sagemaker", ...) # <-- passed `session` ignored
custom_session resolves credentials from the default provider chain (env vars / AWS_PROFILE / IMDS), discarding the passed session's credentials. The other clients built in the same constructor (sagemaker-runtime, sagemaker-featurestore-runtime, sagemaker-metrics) still correctly use the passed session.
Since every resource class routes through Base.get_sagemaker_client(session=...) → SageMakerClient(...).get_client("sagemaker"), all V3 resource API calls are affected.
To reproduce
Minimal proof, no AWS resources created — the returned client does not hold the passed session's credentials:
import boto3
from sagemaker.core.utils.utils import SageMakerClient
# Any session whose credentials differ from the default provider chain,
# e.g. an assumed role:
sts = boto3.client("sts")
creds = sts.assume_role(
RoleArn="arn:aws:iam::<ACCOUNT_ID>:role/<SomeRole>",
RoleSessionName="repro",
)["Credentials"]
session = boto3.Session(
aws_access_key_id=creds["AccessKeyId"],
aws_secret_access_key=creds["SecretAccessKey"],
aws_session_token=creds["SessionToken"],
region_name="us-west-2",
)
client = SageMakerClient(session=session, region_name="us-west-2").get_client("sagemaker")
client_key = client._request_signer._credentials.get_frozen_credentials().access_key
print("passed session key:", session.get_credentials().access_key)
print("client signs with :", client_key)
assert client_key == session.get_credentials().access_key, "client ignored the passed session"
The assert passes on 2.12.0 and fails on 2.13.0–2.15.0.
The same code with sagemaker-core 2.12.0 (identical credentials, identical account) succeeds.
Expected behavior
When a session is passed to SageMakerClient (directly or via any resource method's session= parameter), every client it constructs — including sagemaker — signs requests with that session's credentials. If the custom service-model loader is still needed, attach it to the passed session's botocore session rather than creating a new default-chain session.
System information
- SageMaker Python SDK version: sagemaker 3.13.1 / sagemaker-core 2.13.1 (broken); still present in sagemaker-core 2.15.0; last good 2.12.0
- Framework name / algorithm: n/a (Feature Store / core resource classes)
- Python version: 3.13
- CPU or GPU: CPU
- Custom Docker image (Y/N): N (bare venv on macOS)
Additional context
- The bug is easy to miss on EC2/ECS/Batch/SageMaker jobs because the default chain resolves to the attached role — the wrong session happens to be the right identity. It bites exactly when an explicit session matters: assumed roles, cross-account work, multi-profile laptops.
- Two smaller quirks in the same block, worth fixing together:
SageMakerClientis a singleton (SingletonMeta), so even the correctly-handled clients only honor whichever session arrives first in the process.logger.info(f"Runs on sagemaker {env_stage}, region:{env_region}")logs on every construction and reads like leftover debug output.
- Introduced by #5919
- 主要言語
- Python
- スター
- 2.3k
- フォーク
- 1.3k
- 平均マージ
- 3日 2時間
- マージ済み PR(30日)
- 70
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
aws/sagemaker-python-sdk のほかの issue
-
Cannot use spark_event_logs_s3_uri in PySparkProcessor job対応中かも @rsareddy0329 が 5 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
aws/sagemaker-python-sdk#6253 ·
メンテナーはふだん 2 日以内に返信
-
[Bug] V3 Hyperparameter Tuning Pipeline page labelled "Download Data" in navigation due to missing title cell対応中かも @admivsn が 33 日前に担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 93/100
aws/sagemaker-python-sdk#6232 ·
メンテナーはふだん 2 日以内に返信
-
[Bug] ModelTrainer with no input channels emits InputDataConfig: [], which CreatePipeline rejects (min=1) — v2 omitted the key対応中かも @sagemaker-bot が 5 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
aws/sagemaker-python-sdk#6156 · コメント 2 件 ·
メンテナーはふだん 2 日以内に返信
-
sagemaker-train should depend on mlflow-skinny, following sagemaker-mlflow 0.5.0対応中かも @mohamedzeidan2021 が 6 日前に担当しました。 オープン
難易度 2/5 半日 初心者へのやさしさ 72/100
aws/sagemaker-python-sdk#6152 ·
メンテナーはふだん 2 日以内に返信
-
ModelTrainer generates sm_train.sh with CRLF line endings on Windows causing training job failure対応中かも @MohammedAlkindi が 24 日前に担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
aws/sagemaker-python-sdk#5904 · リアクション 1 件 ·
メンテナーはふだん 2 日以内に返信
aws/sagemaker-python-sdk の issue をすべて見る
似ている issue
-
json_params_matcher fails on falsy top-level JSON primitives (0, False, "")対応中かも @mayureshsonawane17 が今日担当しました。 オープンWaiting for: Product Owner
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 5 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
bojieli/ai-agent-book#1169 ·
メンテナーはふだん 1 日以内に返信
-
priority:low ready-for-dev
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
OpenHands/extensions#738 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
micronaut-projects/micronaut-core#13677 ·
メンテナーはふだん 1 日以内に返信