Add a Git repository to your Amazon SageMaker AI account
Important
Custom IAM policies that allow Amazon SageMaker Studio or Amazon SageMaker Studio Classic to create Amazon SageMaker resources must also grant permissions to add tags to those resources. The permission to add tags to resources is required because Studio and Studio Classic automatically tag any resources they create. If an IAM policy allows Studio and Studio Classic to create resources but does not allow tagging, "AccessDenied" errors can occur when trying to create resources. For more information, see Provide permissions for tagging SageMaker AI resources.
AWS managed policies for Amazon SageMaker AI that give permissions to create SageMaker resources already include permissions to add tags while creating those resources.
To manage your GitHub repositories, easily associate them with your notebook instances, and associate credentials for repositories that require authentication, add the repositories as resources in your Amazon SageMaker AI account. You can view a list of repositories that are stored in your account and details about each repository in the SageMaker AI console and by using the API.
You can add Git repositories to your SageMaker AI account in the SageMaker AI console or by using the AWS CLI.
Note
You can use the SageMaker AI API
CreateCodeRepository
to add Git repositories to
your SageMaker AI account, but step-by-step instructions are not provided here.
Add a Git repository to your SageMaker AI account (Console)
To add a Git repository as a resource in your SageMaker AI account
-
Open the SageMaker AI console at https://console.aws.amazon.com/sagemaker/
. -
Under Notebook, choose Git repositories, then choose Add repository.
-
To add an CodeCommit repository, choose AWS CodeCommit. To add a GitHub or other Git-based repository, choose GitHub/Other Git-based repo.
To add an existing CodeCommit repository
-
Choose Use existing repository.
-
For Repository, choose a repository from the list.
-
Enter a name to use for the repository in SageMaker AI. The name must be 1 to 63 characters. Valid characters are a-z, A-Z, 0-9, and - (hyphen).
-
Choose Add repository.
To create a new CodeCommit repository
-
Choose Create new repository.
-
Enter a name for the repository that you can use in both CodeCommit and SageMaker AI. The name must be 1 to 63 characters. Valid characters are a-z, A-Z, 0-9, and - (hyphen).
-
Choose Create repository.
To add a Git repository hosted somewhere other than CodeCommit
-
Choose GitHub/Other Git-based repo.
-
Enter a name of up to 63 characters. Valid characters include alpha-numeric characters, a hyphen (-), and 0-9.
-
Enter the URL for the repository. Do not provide a username in the URL. Add the sign-in credentials in AWS Secrets Manager as described in the next step.
-
For Git credentials, choose the credentials to use to authenticate to the repository. This is necessary only if the Git repository is private.
Note
If you have two-factor authentication enabled for your Git repository, enter a personal access token generated by your Git service provider in the
password
field.-
To use an existing AWS Secrets Manager secret, choose Use existing secret, and then choose a secret from the list. For information about creating and storing a secret, see Creating a Basic Secret in the AWS Secrets Manager User Guide. The name of the secret you use must contain the string
sagemaker
.Note
The secret must have a staging label of
AWSCURRENT
and must be in the following format:{"username":
UserName
, "password":Password
}For GitHub repositories, we recommend using a personal access token in the
password
field. For information, see https://help.github.com/articles/creating-a-personal-access-token-for-the-command-line/. -
To create a new AWS Secrets Manager secret, choose Create secret, enter a name for the secret, and then enter the sign-in credentials to use to authenticate to the repository. The name for the secret must contain the string
sagemaker
.Note
The IAM role you use to create the secret must have the
secretsmanager:GetSecretValue
permission in its IAM policy.The secret must have a staging label of
AWSCURRENT
and must be in the following format:{"username":
UserName
, "password":Password
}For GitHub repositories, we recommend using a personal access token.
-
To not use any credentials, choose No secret.
-
-
Choose Create secret.