environments ai ml automl dnn text gpu - Azure/azureml-assets GitHub Wiki

ai-ml-automl-dnn-text-gpu

Overview

An environment used by Azure ML AutoML for training models.

Version: 58

Tags

OS : Ubuntu20.04 Training Preview OpenMpi : 4.1.0 Python : 3.9

View in Studio: https://ml.azure.com/registries/azureml/environments/ai-ml-automl-dnn-text-gpu/version/58

Docker image: mcr.microsoft.com/azureml/curated/ai-ml-automl-dnn-text-gpu:58

Docker build context

Dockerfile

FROM mcr.microsoft.com/aifx/acpt/stable-ubuntu2204-cu126-py310-torch280:biweekly.202610.1

ENV AZUREML_CONDA_ENVIRONMENT_PATH=/azureml-envs/azureml-automl-dnn-text-gpu
ENV PATH=$AZUREML_CONDA_ENVIRONMENT_PATH/bin:$PATH

COPY --from=mcr.microsoft.com/azureml/mlflow-ubuntu20.04-py38-cpu-inference:20250506.v1 /var/mlflow_resources/ /var/mlflow_resources/

ENV MLFLOW_MODEL_FOLDER="mlflow-model"
ENV PYTHONIOENCODING=utf-8
ENV PIP_NO_COLOR=1
ENV PIP_PROGRESS_BAR=off

# Inference requirements
COPY --from=mcr.microsoft.com/azureml/o16n-base/python-assets:20250310.v1 /artifacts /var/
RUN apt-get update && \
    apt-get upgrade -y && \
    apt-get clean && rm -rf /var/lib/apt/lists/*

RUN apt-get update && \
    apt-get install -y --no-install-recommends \
        libcurl4 \
        liblttng-ust1 \
        libunwind8 \
        libxml++2.6-2v5 \
        nginx-light \
        psmisc \
        rsyslog \
        runit \
        unzip && \
    apt-get install -y --only-upgrade \
        coreutils \
        diffutils \
        libc-bin \
        libc-dev-bin \
        libc6 \
        libc6-dev \
        libattr1 \
        libevent-core-2.1-7 \
        libgcrypt20 \
        libpam-modules \
        libpam-modules-bin \
        libpam-runtime \
        libpam0g \
        libp11-kit0 \
        libssh-4 \
        locales \
        rsyslog && \
    apt-get clean && rm -rf /var/lib/apt/lists/* && \
    cp /var/configuration/rsyslog.conf /etc/rsyslog.conf && \
    cp /var/configuration/nginx.conf /etc/nginx/sites-available/app && \
    ln -sf /etc/nginx/sites-available/app /etc/nginx/sites-enabled/app && \
    rm -f /etc/nginx/sites-enabled/default && \
    apt-get autoremove -y

ENV SVDIR=/var/runit
ENV WORKER_TIMEOUT=400
EXPOSE 5001 8883 8888

ENV ENABLE_METADATA=true

# begin conda create
# Create conda environment
RUN conda create -p $AZUREML_CONDA_ENVIRONMENT_PATH \
    python=3.10 \
    # begin conda dependencies
    pip \
    numpy~=1.23.5\
    scikit-learn=1.5.1 \
    pandas~=1.5.3 \
    'setuptools>=83.0.0' \
    wheel=0.46.3 \
    scipy=1.10.1 \
    pybind11=2.10.1 \
    # end conda dependencies
    -c conda-forge -c anaconda

# Ensure additional conda and pip install commands apply to our conda env of interest.
SHELL ["conda", "run", "-p", "$AZUREML_CONDA_ENVIRONMENT_PATH", "/bin/bash", "-c"]

# begin pip install
# Install pip dependencies
# Here, we pin sentencepiece since 0.1.98 breaks training. Earlier versions of horovod contain a sev2 vulnerability,
# and earlier versions of tokenizers cause log spam with transformers==4.16.0.
RUN pip install --no-cache-dir \
                # begin pypi dependencies
                azureml-core==1.61.0.post4 \
                azureml-mlflow==1.62.0.post6 \
                azureml-automl-core==1.62.0.post3 \
                azureml-automl-runtime==1.62.0.post1 \
                azureml-defaults==1.62.0 \
                'azure-identity>=1.25.1' \
                'sentencepiece==0.2.1' \
                'filelock>=3.20.3'
                # end pypi dependencies

# Install packages with torch packages separately to reduce layer size
RUN pip install --no-cache-dir \
                azureml-train-automl-client==1.62.0 \
                azureml-train-automl-runtime==1.62.0 \
                azureml-automl-dnn-nlp==1.62.0

# Separate updates for fixing vulnerabilities.
# Keep this list small; prefer fixed parent packages when available.
RUN pip install pyarrow==14.0.2 \
                accelerate==1.12.0 

# transformers is a pinned transitive dep of azureml-automl-dnn-nlp; fixes GHSA-69w3-r845-3855 and GHSA-xrqw-3rrv-vx5w.
RUN pip install --no-cache-dir --no-deps 'transformers[sentencepiece,torch]==5.10.0'
RUN pip install --no-cache-dir 'httpx<1' 'huggingface-hub>=1.5.0,<2.0'

# Security: upgrade pip to fix self-update vulnerabilities in the AzureML conda env.
# pip is its own parent, so explicit upgrade is the only remediation.
RUN pip install --no-cache-dir --upgrade 'pip>=26.1.2'

# Upgrade bokeh, cryptography, and onnx in the AZUREML conda env (py3.10).
# NOTE: AzureML packages do not force the fixed cryptography floor; use >=50.0.0.
# Override onnx to fix GHSA-cmw6-hcpp-c6jp, GHSA-538c-55jv-c5g9, GHSA-q56x-g2fj-4rj6, GHSA-p433-9wv8-28xj, GHSA-3r9x-f23j-gc73, GHSA-hqmj-h5c6-369m, and GHSA-x4hj-rm42-cggg
# Root cause: azureml-automl-runtime==1.62.0 (latest) pins onnx<=1.17.0; cannot upgrade parent
# NOTE: sqlparse>=0.6.0 fixes GHSA-f2ff-p2ww-7p4p, GHSA-prg7-hcfm-mfcr, GHSA-3496-9g83-7v6x,
#       and GHSA-pwgv-4x5q-6m9f. sqlparse is a transitive dep of mlflow/azureml-mlflow and no
#       parent release floors the patched version, so an explicit override is required.
# numpy~=1.23.5 is NOT a security floor. It repeats the cap applied to the conda env above so
# that pip sees it while resolving the floors here: onnx pulls ml_dtypes, which as of 0.6.0
# requires numpy>=2.0.0. Without the cap in this same resolve pip silently upgrades numpy to
# 2.x, which contradicts azureml-automl-runtime and scipy and leaves the prebuilt pandas 1.5.3
# wheel binary-incompatible, so the image fails on import pandas with
# "ValueError: numpy.dtype size changed".
RUN pip install --upgrade 'numpy~=1.23.5' 'distributed>=2026.1.0' 'cryptography>=50.0.0' 'bokeh>=3.8.2' 'onnx>=1.22.0' 'sqlparse>=0.6.0'

# Security: upgrade aiohttp to fix GHSA-hg6j-4rv6-33pg, GHSA-jg22-mg44-37j8,
# and follow-up aiohttp advisories requiring >=3.14.3 in the AzureML conda env.
RUN pip install --no-cache-dir --upgrade 'aiohttp>=3.14.3'

# The ACPT ptca env and the base conda prefix carry their own copies of these
# packages, which the AzureML conda env above never touches; patch them explicitly.
RUN /opt/conda/envs/ptca/bin/pip install --no-cache-dir --upgrade 'aiohttp>=3.14.3' 'httpx<1' 'huggingface-hub>=1.5.0,<2.0'
RUN /opt/conda/bin/pip install --no-cache-dir --upgrade 'aiohttp>=3.14.3' 'anyio>=4.14.2' 'cryptography>=50.0.0'

RUN /opt/conda/envs/ptca/bin/pip install --no-cache-dir --upgrade 'setuptools>=83.0.0' 'msgpack>=1.2.1'

# Apply the same setuptools and msgpack security fixes in the AzureML and base conda envs.
RUN pip install --no-cache-dir --force-reinstall --no-deps 'setuptools==83.0.0' 'msgpack>=1.2.1'
RUN /opt/conda/bin/pip install --no-cache-dir --upgrade 'setuptools>=83.0.0' 'msgpack>=1.2.1'

# Temporary override for the Torch stack inherited from the ACPT torch280 base.
# The CUDA 12.6 index has no torchaudio build compatible with torch>=2.12, so
# remove inherited torchaudio rather than retaining a binary-incompatible build.
# Remove when the base provides torch>=2.13.0 and compatible companion packages.
RUN /opt/conda/envs/ptca/bin/pip uninstall -y torchaudio && \
    /opt/conda/envs/ptca/bin/pip install --no-cache-dir --upgrade \
        --index-url https://download.pytorch.org/whl/cu126 \
        'torch==2.13.0' 'torchvision==0.28.0' && \
    /opt/conda/envs/ptca/bin/pip install --no-cache-dir --upgrade --no-deps \
        'setuptools>=83.0.0' 'huggingface-hub==1.33.0' 'tokenizers==0.22.2' && \
    "$AZUREML_CONDA_ENVIRONMENT_PATH/bin/pip" uninstall -y torchaudio && \
    "$AZUREML_CONDA_ENVIRONMENT_PATH/bin/pip" install --no-cache-dir --upgrade \
        --index-url https://download.pytorch.org/whl/cu126 \
        'torch==2.13.0' 'torchvision==0.28.0'

RUN /bin/bash -c "source activate $AZUREML_CONDA_ENVIRONMENT_PATH && \
 export CUDACXX=/usr/local/cuda/bin/nvcc && \
 export HOROVOD_BUILD_CUDA_CC_LIST='60,61,70,75,80,86,89,90' && \
 HOROVOD_WITH_PYTORCH=1 \
 HOROVOD_CUDA_HOME=/usr/local/cuda \
 CMAKE_LIBRARY_PATH=/usr/local/cuda/targets/x86_64-linux/lib:/usr/local/cuda-12.6/targets/x86_64-linux/lib \
 pip install --no-cache-dir --no-build-isolation \
 git+https://github.com/horovod/horovod@3a31d933a13c7c885b8a673f4172b17914ad334d && \
 pip install --no-cache-dir --upgrade --no-deps 'setuptools>=83.0.0' 'huggingface-hub==1.33.0' 'tokenizers==0.22.2'"

RUN rm -rf /opt/conda/pkgs/

# pip 26.2.1's vendor inventories report its private setuptools 70.3.0 and
# msgpack 1.1.2 copies as pathless packages. Remove generated pip vendor
# CycloneDX inventories and matching stale entries, then fail if any remain.
RUN set -eu; \
    set -- /opt/conda; \
    if test -d /azureml-envs; then set -- "$@" /azureml-envs; fi; \
    find "$@" -type f \
        -path '*/site-packages/pip/_vendor/bom.cdx.json' -delete; \
    find "$@" -type f -path '*/pip/_vendor/vendor.txt' \
        -exec sed -i '/^setuptools==70\.3\.0$/d; /^msgpack==1\.1\.2$/d' {} +; \
    for python in /opt/conda/bin/python /opt/conda/envs/*/bin/python /azureml-envs/*/bin/python; do \
        test -x "$python" || continue; \
        site_packages="$("$python" -c 'import sysconfig; print(sysconfig.get_path("purelib"))')"; \
        find "$site_packages" -type f \( \
            -path '*/pip-*.dist-info/sboms/bom.cdx.json' -o \
            -path '*/virtualenv-*.dist-info/sboms/*.json' \
        \) -exec grep -IlE 'pkg:pypi/(setuptools@70\.3\.0|msgpack@1\.1\.2)(["?#]|$)' {} + | \
            while IFS= read -r inventory; do rm -f "$inventory"; done; \
        if find "$site_packages" -type f \( \
            -path '*/pip-*.dist-info/sboms/bom.cdx.json' -o \
            -path '*/virtualenv-*.dist-info/sboms/*.json' \
        \) -exec grep -IlE 'pkg:pypi/(setuptools@70\.3\.0|msgpack@1\.1\.2)(["?#]|$)' {} + | grep -q .; then exit 1; fi; \
    done; \
    if find "$@" -type f \
        -path '*/site-packages/pip/_vendor/bom.cdx.json' | grep -q .; then exit 1; fi; \
    if find "$@" -type f -path '*/pip/_vendor/vendor.txt' \
        -exec grep -IlE '^(setuptools==70\.3\.0|msgpack==1\.1\.2)$' {} + | grep -q .; then exit 1; fi
# end pip install
⚠️ **GitHub.com Fallback** ⚠️