Permissions for SOCI indexing
Create SOCI indexes for your container images and store them in Amazon ECR before using SOCI indexing with Amazon SageMaker Studio or Amazon SageMaker Unified Studio.
Prerequisites
-
Amazon Web Services account with an Amazon Identity and Access Management (IAM) role with permissions to manage
-
Amazon ECR private repositories for storing your container images
-
Amazon CLI v2.0+ configured with appropriate credentials
-
The following container tools:
-
Required: soci-snapshotter
-
Options:
-
Required IAM permissions
Your IAM role needs permissions to:
-
Create and manage SageMaker AI resources (domains, images, app configs).
-
You may use the SageMakerFullAccess Amazon managed policy. For more permission details, see Amazon managed policy: AmazonSageMakerFullAccess.
-
-
IAM permissions for pushing an image to an Amazon ECR private repository.