SageMakerClient ignores the passed boto3 session for the "sagemaker" client since 2.13.0 — all resource API calls sign with default-chain credentials
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 58/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- aws, python
- Lĩnh vực
- backend-api-design, cloud, security
Hướng nghiên cứu
Bắt đầu tại sagemaker-core/src/sagemaker/core/utils/utils.py ở SageMakerClient.init, sau đó lần theo Base.get_sagemaker_client(session=...) và get_client("sagemaker"). Chạy bản tái hiện so sánh thông tin xác thực được cung cấp mà không tạo tài nguyên AWS. Hoàn tất khi client sagemaker ký bằng thông tin xác thực của session được truyền rõ ràng, đồng thời vẫn giữ nguyên hành vi service-model tùy chỉnh.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
TL;DR — Since sagemaker-core 2.13.0, SageMakerClient ignores the session= the caller passed and builds its main sagemaker client from a fresh default-chain session. Every V3 resource API call (FeatureGroup.create, Model.create, describe/delete/list, …) is silently signed with ambient credentials instead of the caller's.
Besides breaking explicit-session workflows, this is a quiet identity mix-up with a security edge: code written to run under a scoped or assumed role can instead execute under a less-privileged (or worse a more-privileged) ambient identity, with no error or warning. Last good version: 2.12.0. Workaround: pin sagemaker-core>=2.12,<2.13.
PySDK Version
- PySDK V2 (2.x)
- PySDK V3 (3.x)
Describe the bug
SageMakerClient.__init__ (sagemaker-core/src/sagemaker/core/utils/utils.py) contains a block introduced by #5919 (merged 2026-06-03, released as sagemaker-core 2.13.0) that loads a custom service model for pre-GA Job APIs through a brand-new botocore session:
# TODO: Remove post-launch. This loads a custom botocore service model
# (from the 'sample/' directory) that includes pre-GA Job APIs ...
bc_session = bc_session_mod.get_session()
...
custom_session = Session(botocore_session=bc_session, region_name=env_region)
self.sagemaker_client = custom_session.client("sagemaker", ...) # <-- passed `session` ignored
custom_session resolves credentials from the default provider chain (env vars / AWS_PROFILE / IMDS), discarding the passed session's credentials. The other clients built in the same constructor (sagemaker-runtime, sagemaker-featurestore-runtime, sagemaker-metrics) still correctly use the passed session.
Since every resource class routes through Base.get_sagemaker_client(session=...) → SageMakerClient(...).get_client("sagemaker"), all V3 resource API calls are affected.
To reproduce
Minimal proof, no AWS resources created — the returned client does not hold the passed session's credentials:
import boto3
from sagemaker.core.utils.utils import SageMakerClient
# Any session whose credentials differ from the default provider chain,
# e.g. an assumed role:
sts = boto3.client("sts")
creds = sts.assume_role(
RoleArn="arn:aws:iam::<ACCOUNT_ID>:role/<SomeRole>",
RoleSessionName="repro",
)["Credentials"]
session = boto3.Session(
aws_access_key_id=creds["AccessKeyId"],
aws_secret_access_key=creds["SecretAccessKey"],
aws_session_token=creds["SessionToken"],
region_name="us-west-2",
)
client = SageMakerClient(session=session, region_name="us-west-2").get_client("sagemaker")
client_key = client._request_signer._credentials.get_frozen_credentials().access_key
print("passed session key:", session.get_credentials().access_key)
print("client signs with :", client_key)
assert client_key == session.get_credentials().access_key, "client ignored the passed session"
The assert passes on 2.12.0 and fails on 2.13.0–2.15.0.
The same code with sagemaker-core 2.12.0 (identical credentials, identical account) succeeds.
Expected behavior
When a session is passed to SageMakerClient (directly or via any resource method's session= parameter), every client it constructs — including sagemaker — signs requests with that session's credentials. If the custom service-model loader is still needed, attach it to the passed session's botocore session rather than creating a new default-chain session.
System information
- SageMaker Python SDK version: sagemaker 3.13.1 / sagemaker-core 2.13.1 (broken); still present in sagemaker-core 2.15.0; last good 2.12.0
- Framework name / algorithm: n/a (Feature Store / core resource classes)
- Python version: 3.13
- CPU or GPU: CPU
- Custom Docker image (Y/N): N (bare venv on macOS)
Additional context
- The bug is easy to miss on EC2/ECS/Batch/SageMaker jobs because the default chain resolves to the attached role — the wrong session happens to be the right identity. It bites exactly when an explicit session matters: assumed roles, cross-account work, multi-profile laptops.
- Two smaller quirks in the same block, worth fixing together:
SageMakerClientis a singleton (SingletonMeta), so even the correctly-handled clients only honor whichever session arrives first in the process.logger.info(f"Runs on sagemaker {env_stage}, region:{env_region}")logs on every construction and reads like leftover debug output.
- Introduced by #5919
- Ngôn ngữ chính
- Python
- Star
- 2.3k
- Fork
- 1.3k
- Merge trung bình
- 3 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 70
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của aws/sagemaker-python-sdk
-
Cannot use spark_event_logs_s3_uri in PySparkProcessor jobCó thể đã có người làm @rsareddy0329 đã nhận 5 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
aws/sagemaker-python-sdk#6253 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
[Bug] V3 Hyperparameter Tuning Pipeline page labelled "Download Data" in navigation due to missing title cellCó thể đã có người làm @admivsn đã nhận 34 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 93/100
aws/sagemaker-python-sdk#6232 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
[Bug] ModelTrainer with no input channels emits InputDataConfig: [], which CreatePipeline rejects (min=1) — v2 omitted the keyCó thể đã có người làm @sagemaker-bot đã nhận 5 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
aws/sagemaker-python-sdk#6156 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
sagemaker-train should depend on mlflow-skinny, following sagemaker-mlflow 0.5.0Có thể đã có người làm @mohamedzeidan2021 đã nhận 6 ngày trước. Đang mở
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 72/100
aws/sagemaker-python-sdk#6152 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
ModelTrainer generates sm_train.sh with CRLF line endings on Windows causing training job failureCó thể đã có người làm @MohammedAlkindi đã nhận 25 ngày trước. Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
aws/sagemaker-python-sdk#5904 · 1 reaction ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của aws/sagemaker-python-sdk
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Qiskit/qiskit-ibm-runtime#3431 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Lesson] A compatibility-gate rejection is a verdict, not something to overwrite with --accept-riskĐang mởlesson-submission needs-ac pending-review
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
Ikalus1988/MisakaNet#2870 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature:LinkChecker
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
digitalfabrik/integreat-cms#4594 ·
Maintainer thường phản hồi trong vòng 5 ngày