Allow for model registration to use KMS auth from different workspace#20156
Allow for model registration to use KMS auth from different workspace#20156BenWilson2 merged 3 commits intomlflow:masterfrom
Conversation
Signed-off-by: Ben Wilson <benjamin.wilson@databricks.com>
🛠 DevTools 🛠
Install mlflow from this PRFor Databricks, use the following command: |
There was a problem hiding this comment.
Pull request overview
This PR fixes a regression introduced in MLflow 2.14.3 where KMS key authentication for Unity Catalog model registration was broken for cross-account encryption scenarios. The fix restores the original behavior by using the full KMS key ARN instead of parsing out just the key ID.
Changes:
- Modified
_parse_aws_sse_credentialto pass the full KMS ARN to AWS S3'sSSEKMSKeyIdparameter instead of extracting only the key ID - Updated test expectations to reflect that the full ARN is now used
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| mlflow/utils/_unity_catalog_utils.py | Removed the key ID parsing logic and now passes the full aws_kms_key_arn directly to the SSEKMSKeyId parameter |
| tests/utils/test_unity_catalog_utils.py | Updated test data to use a realistic full KMS ARN format and verify the expected output includes the full ARN |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Documentation preview for fc71a05 is available at: More info
|
|
Test failure https://github.com/mlflow/mlflow/actions/runs/21230883374/job/61088897239?pr=20156 is present in master and is unrelated (sqlalchemy issue with latest released version on PyPI) |
…mlflow#20156) Signed-off-by: Ben Wilson <benjamin.wilson@databricks.com>
…mlflow#20156) Signed-off-by: Ben Wilson <benjamin.wilson@databricks.com>
…#20156) Signed-off-by: Ben Wilson <benjamin.wilson@databricks.com>
Related Issues/PRs
#xxxWhat changes are proposed in this pull request?
In MLflow 2.14.3, a function was added (_parse_aws_sse_credential) that extracted the KMS key for acquiring write credentials for registration to UC. Prior to this release, the KMS authentication relied on the default account that was being used, meaning that the bucket defaults would be used, allowing for cross-account encryption capabilities.
To restore the original behavior, this PR pulls the full ARN for authentication instead of parsing out the key / value pair, which breaks the multi-tenant workflow.
How is this PR tested?
Does this PR require documentation update?
Release Notes
Is this a user-facing change?
What component(s), interfaces, languages, and integrations does this PR affect?
Components
area/tracking: Tracking Service, tracking client APIs, autologgingarea/models: MLmodel format, model serialization/deserialization, flavorsarea/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registryarea/scoring: MLflow Model server, model deployment tools, Spark UDFsarea/evaluation: MLflow model evaluation features, evaluation metrics, and evaluation workflowsarea/gateway: MLflow AI Gateway client APIs, server, and third-party integrationsarea/prompts: MLflow prompt engineering features, prompt templates, and prompt managementarea/tracing: MLflow Tracing features, tracing APIs, and LLM tracing functionalityarea/projects: MLproject format, project running backendsarea/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev serverarea/build: Build and test infrastructure for MLflowarea/docs: MLflow documentation pagesHow should the PR be classified in the release notes? Choose one:
rn/none- No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" sectionrn/breaking-change- The PR will be mentioned in the "Breaking Changes" sectionrn/feature- A new user-facing feature worth mentioning in the release notesrn/bug-fix- A user-facing bug fix worth mentioning in the release notesrn/documentation- A user-facing documentation change worth mentioning in the release notesShould this PR be included in the next patch release?
Yesshould be selected for bug fixes, documentation updates, and other small changes.Noshould be selected for new features and larger changes. If you're unsure about the release classification of this PR, leave this unchecked to let the maintainers decide.What is a minor/patch release?
Bug fixes, doc updates and new features usually go into minor releases.
Bug fixes and doc updates usually go into patch releases.