Usage
Deployed Resources
Once deployed, you should see the following in your AWS account:
Naming convention: <org>-<env>-<domain>-<module>-<resource>
SSM parameters: /<org>/<domain>/<module>/<resource-type>/<resource-name>/<attribute>
| Resource | Deployed Name / SSM Path | Config Reference |
|---|---|---|
| Audit S3 Bucket | <org>-dev-shared-audit-audit/<org>/shared/audit/bucket/name |
deployed by shared/audit.yaml |
| Audit KMS Key | <org>-dev-shared-audit-audit/<org>/shared/audit/kms/arn |
deployed by shared/audit.yaml |
| CloudTrail Trail | <org>-dev-shared-audit-trail-s3-audit |
trails.s3-audit in shared/audit-trail.yaml |
| SMUS Domain | <org>-dev-sagemaker-domain-domain1/<org>/sagemaker/domain/domain/domain1/name |
domains.domain1 in sagemaker/domain.yaml |
| SMUS Project Profile | <org>-dev-sagemaker-projects/<org>/sagemaker/projects/project/name |
configured in sagemaker/projects.yaml |
| IAM Role | <org>-dev-shared-roles-data-admin/<org>/shared/generated-role/data-admin/id |
generateRoles.data-admin in shared/roles.yaml |
| Glue Catalog Encryption | Account-level setting | deployed by glue-catalog module(not configurable) |
| LakeFormation Data Lake Settings | Account-level setting | deployed by shared/lakeformation-settings.yaml(not configurable) |
Post-Deployment Steps
1. Access the SMUS Portal
- Assume the
<org>-dev-shared-roles-data-adminrole in your deployment account. - Navigate to SageMaker Unified Studio in the AWS Console.
- Select the deployed domain (
<org>-dev-sagemaker-domain-domain1). - Click Open portal.
2. Verify SSO Access
- SSO users in the
team1andteam2groups should be able to log into the portal. - If users cannot access the portal, verify their SSO group IDs match the values configured in
mdaa.yamlcontext (team1-group-sso-id,team2-group-sso-id).
3. Create a Project
- In the SMUS portal, navigate to Projects.
- Select a project profile to create a new team workspace.
- Team members in the assigned SSO group will have access to the project's notebooks, SQL queries, and data catalog.
4. Start Working
Available capabilities in the portal: - JupyterLab notebooks — ML experimentation and data analysis - SQL queries — Query data in Glue databases via Athena - Data catalog — Discover and subscribe to data assets - MLflow — Track experiments and model versions
Scaling Up
For more complex organizations with teams operating across multiple accounts, see the SMUS Data Mesh starter kit.