fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(train): correct Networking field names in ModelTrainer intelligent defaults - #5866

Open
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation
Open

fix(train): correct Networking field names in ModelTrainer intelligent defaults#5866
mandipat wants to merge 2 commits into
aws:masterfrom
mandipat:fix/networking-default-enable-network-isolation

Conversation

@mandipat

Copy link
Copy Markdown

Summary

Fixes two bugs in _populate_intelligent_defaults_from_training_job_space() in model_trainer.py that prevent ModelTrainer from working when sagemaker_config has a VpcConfig set. This makes SageMaker distribution 4.0 unusable out of the box.

Bug 1 — Wrong field name passed to Networking constructor

default_enable_network_isolation does not exist as a field in sagemaker-core 2.x. The correct field name is enable_network_isolation. This caused a Pydantic ValidationError on every model_trainer.train() call when VPC config was present in sagemaker_config.

# BEFORE (broken)self.networking=Networking(
default_enable_network_isolation=default_enable_network_isolation, # field does not exist
...
)
# AFTER (fixed)self.networking=Networking(
enable_network_isolation=default_enable_network_isolation,
...
)

Bug 2 — security_group_ids silently assigned wrong value

When updating an existing Networking object, security_group_ids was mistakenly assigned the value from TRAINING_JOB_SUBNETS_PATH instead of TRAINING_JOB_SECURITY_GROUP_IDS_PATH.

# BEFORE (broken)ifself.networking.security_group_idsisNone:
self.networking.subnets=self.config_mgr.resolve_value_from_config( # wrong attribute + wrong pathconfig_path=TRAINING_JOB_SUBNETS_PATH
)
# AFTER (fixed)ifself.networking.security_group_idsisNone:
self.networking.security_group_ids=self.config_mgr.resolve_value_from_config(
config_path=TRAINING_JOB_SECURITY_GROUP_IDS_PATH
)

Testing

Reproduced and verified the fix using a clean venv with sagemaker-core==2.10.0 and sagemaker-train==1.10.0 (exact versions shipped in SageMaker distribution 4.0).

fromsagemaker.core.training.configsimportNetworking# Bug 1 confirmedtry:
Networking(default_enable_network_isolation=None) # ValidationErrorexceptExceptionase:
print(f"BUG: {e}")
# Fix confirmedNetworking(enable_network_isolation=False) # Works

Closes#5766

…t defaults
Two bugs in _populate_intelligent_defaults_from_training_job_space():
1. Networking constructor was passed `default_enable_network_isolation`
which does not exist in sagemaker-core 2.x. The correct field name
is `enable_network_isolation`. This caused a Pydantic ValidationError
when sagemaker_config had a VpcConfig value set, making ModelTrainer
unusable in SageMaker distribution 4.0 out of the box.
2. When updating an existing Networking object, `security_group_ids` was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH
instead of the correct value from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Fixesaws#5766
@jam-jee
jam-jeeforce-pushed the fix/networking-default-enable-network-isolation branch from 3e79bac to 203ddf3CompareJuly 8, 2026 03:58
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@jam-jee
jam-jeetemporarily deployed to manual-approval July 8, 2026 03:58 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@mandipat
mandipattemporarily deployed to manual-approval July 8, 2026 14:40 — with GitHub Actions Inactive
@jam-jee

Copy link
Copy Markdown
Collaborator

Failed integ tests are not related to the changes made in this PR.

jam-jee
jam-jee previously approved these changes Jul 10, 2026
@jam-jee
jam-jee self-requested a review July 10, 2026 05:35

@jam-jeejam-jee left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add/update relevant unit tests for this change.

@jam-jee
jam-jee self-requested a review July 13, 2026 21:19
@jam-jee
jam-jee dismissed their stale reviewJuly 14, 2026 05:10

added comments to add relevant tests

@admivsn

Copy link
Copy Markdown
Contributor

Hey, please let me know how we can get this or the original PR (#5767) merged to fix this issue. Happy to support

mohamedzeidan2021 added a commit that referenced this pull request Jul 21, 2026
…t defaults (#6064)
Fixes two bugs in _populate_intelligent_defaults_from_training_job_space()
in model_trainer.py that prevent ModelTrainer from working when
sagemaker_config has a VpcConfig set.
Bug 1: Networking() was passed default_enable_network_isolation, which is
not a field in sagemaker-core 2.x. The correct field is
enable_network_isolation. This raised a pydantic ValidationError on every
train() call when VPC config was present.
Bug 2: When updating an existing Networking object, security_group_ids was
mistakenly assigned the subnets value from TRAINING_JOB_SUBNETS_PATH instead
of security_group_ids from TRAINING_JOB_SECURITY_GROUP_IDS_PATH.
Adds unit tests covering both bug paths (fresh Networking construction and
updating an existing Networking object).
Fix originally from #5866; unit tests added here.
Co-authored-by: Mohamed Zeidan <zeidmo@amazon.com>
@mohamedzeidan2021

Copy link
Copy Markdown
Collaborator

merged in your PR with unit tests here: #6064

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sagemaker_config related Networking bugs in ModelTrainer

4 participants

@mandipat@jam-jee@admivsn@mohamedzeidan2021