fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: ModelBuilder resolves private hub artifacts correctly - #5985

Merged
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution
Jul 8, 2026
Merged

fix: ModelBuilder resolves private hub artifacts correctly#5985
jam-jee merged 1 commit into
aws:masterfrom
lhnealreilly:fix/private-hub-artifact-resolution

Conversation

@lhnealreilly

Copy link
Copy Markdown
Contributor

Fix two defects causing ModelBuilder to ignore private hub when resolving model artifacts, forcing the execution role to access the public JumpStart S3 cache bucket.

Defect 1: from_jumpstart_config sets hub_name AFTER init has already called _initialize_jumpstart_config(), which takes the else branch and sets hub_arn = None. Fix: call _initialize_jumpstart_config() again after setting hub_name so hub_arn is correctly derived.

Defect 2: _build_for_jumpstart does not forward hub_arn to get_init_kwargs, causing model data to resolve from the public catalog. Fix: pass hub_arn=getattr(self, 'hub_arn', None) to all get_init_kwargs call sites in the build path (_build_for_jumpstart, _detect_jumpstart_image).

Impact: Customers deploying from private hubs via ModelBuilder no longer need to grant their execution role s3:GetObject on the public JumpStart cache bucket.

Testing:

  • 8 unit tests covering both defects and end-to-end flow
  • Integration test for private hub deployment (requires env config)

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 73c3510 to c85e4c4CompareJuly 2, 2026 02:36
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from c85e4c4 to f265dceCompareJuly 2, 2026 14:50
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from f265dce to 5cc330bCompareJuly 2, 2026 15:56
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 5cc330b to 93c38e7CompareJuly 2, 2026 17:59
Fix three defects causing ModelBuilder to ignore private hub when resolving
model artifacts, forcing the execution role to access the public JumpStart
S3 cache bucket.
Defect 1: from_jumpstart_config sets hub_name AFTER __init__ has already
called _initialize_jumpstart_config(), which takes the else branch and
sets hub_arn = None. Fix: derive hub_arn inline after setting hub_name.
Defect 2: _build_for_jumpstart does not forward hub_arn or sagemaker_session
to get_init_kwargs, causing model data to resolve from the public catalog.
Fix: pass hub_arn (when set) and sagemaker_session to all get_init_kwargs
call sites in the build path.
Defect 3: The v3 Session class (sagemaker.core.helper.session_helper.Session)
is missing hub API methods (describe_hub_content, list_hub_content_versions,
list_hub_contents) that the JumpStart cache calls during hub content
resolution. Fix: add these methods as thin wrappers around the boto3
sagemaker_client calls.
Impact: Customers deploying from private hubs via ModelBuilder no longer
need to grant their execution role s3:GetObject on the public JumpStart
cache bucket.
Testing:
- 8 new unit tests covering hub_arn derivation, forwarding, and e2e flow
- 2 existing unit tests updated to match new call signatures
@lhnealreilly
lhnealreillyforce-pushed the fix/private-hub-artifact-resolution branch from 93c38e7 to ae1f6cfCompareJuly 2, 2026 19:47
@jam-jee
jam-jee merged commit b27221b into aws:masterJul 8, 2026
15 of 24 checks passed
zhaoqizqwang pushed a commit that referenced this pull request Jul 17, 2026
…6039)
* fix(serve): support aliased hub content names in private hub deploys
CreateHubContentReference accepts a custom HubContentName, but the SDK
always looks up hub content by model_id, so a reference named
differently from the public model id fails with ResourceNotFound.
Add optional hub_content_name to JumpStartConfig and thread it through
from_jumpstart_config; when set, _build_for_jumpstart resolves hub
content by the reference's actual name.
Verified E2E against a live private hub with an execution role that has
zero S3 permissions: an aliased ModelReference now deploys successfully
with SageMaker brokering artifact access through the hub content
reference.
* test(serve): private hub regression coverage for HubAccessConfig and aliased names
Unit tests (extends the #5985 file, shared setup hoisted to a
module-level _build_jumpstart_builder helper per package convention):
- model_reference_arn propagation regression test guarding the #6036
fix (supersedes the subset assertions added there)
- CreateModel payload chain test: drives the real unmocked path
_build_for_jumpstart -> _prepare_container_def_base and asserts the
container definition carries S3DataSource.HubAccessConfig.HubContentArn
for hub builds and omits it for public builds -- the assertion that
would have caught the v3.15.1-v3.16.0 regression
- hub_content_name lookup and config threading tests
Integration tests (slow_test, self-provisioning with full teardown):
- test_deploy_with_no_s3_execution_role: zero-S3 execution role deploy,
asserts HubAccessConfig on the created Model (service-side contract)
- test_deploy_with_aliased_hub_content_name: aliased reference deploy
Verified red->green at every layer: 4 unit tests and both integ tests
fail on v3.16.0 baseline; all pass with the fixes (integ verified live
in us-east-1 with a real hub, zero-S3 role, 2 passed in 38s).
---------
Co-authored-by: Eli Davidson <elleedee@amazon.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@lhnealreilly@jam-jee@lnealrei