Tooling blueprints in Amazon SageMaker Unified Studio
Every Amazon SageMaker Unified Studio project deploys a Tooling environment first. Tooling provisions the project's Amazon S3 storage, the IAM role for project execution, and a collection of default Amazon DataZone connections. Tooling also provisions AWS resources commonly used within projects, such as Amazon Athena workgroups and AWS Lake Formation permissions.
All blueprints in Amazon SageMaker Unified Studio provision an AWS CloudFormation template using an IAM role designated as the provisioning role. After a project becomes active, you need an IAM role designated as the project user role to run the project. The following table gives the name of each role in an IAM-based domain and in an Identity Center-based domain.
| IAM role | IAM-based domain | Identity Center-based domain |
|---|---|---|
| Provisioning | AmazonSageMakerAdminIAMExecutionRole |
AmazonSageMakerProvisioning- |
| Project user | AmazonSageMakerUserIAMExecutionRole |
datazone_usr_role_ |
Depending on the type of domain, Amazon SageMaker Unified Studio provides AWS managed policies that can be attached to the provisioning or project user roles to grant full permissions. The following table gives the managed policy for each role in an IAM-based domain and in an Identity Center-based domain.
| IAM role | IAM-based domain | Identity Center-based domain |
|---|---|---|
| Provisioning | AWS policy: SageMakerStudioAdminIAMPermissiveExecutionPolicy | AWS policy: SageMakerStudioProjectProvisioningRolePolicy |
| Project user | AWS policy: SageMakerStudioUserIAMPermissiveExecutionPolicy | AWS policy: SageMakerStudioProjectUserRolePolicy |
Tooling provisions the default connections that every project requires. The set of connections differs between an IAM-based domain and an Identity Center-based domain. The name of each connection differs too.
| Default connection | IAM-based domain | Identity Center-based domain |
|---|---|---|
| Amazon Athena (Spark) | serverless.spark |
serverless.spark |
| Amazon Athena (SQL) | default.sql |
project.athena |
| Amazon S3, default folder | default.s3_project |
project.s3_default_folder |
| Amazon S3, root | default.s3 |
— |
| Amazon S3, shared folder | default.s3_shared |
default.s3_shared |
| AWS Glue (Spark) | default.spark |
project.spark.compatibility,
project.spark.fineGrained |
| AWS IAM | default.iam |
project.iam |
| Data catalog | default.catalog |
project.default_lakehouse |
| Workflows | default.workflow_serverless |
default.workflow_serverless |
Enable the managed Tooling blueprint for your domain on the Blueprints page. Tooling has parameters you can set, and a permissions boundary you can apply to the roles it creates. For both, see Manage Tooling blueprint parameters.