Chapter 3.4 - Build and publish the model with BentoML and Docker in the CI/CD pipeline¶
Introduction¶
In this chapter, you will containerize and push the model to the container registry with the help of the CI/CD pipeline. You will use BentoML and Docker to containerize and publish the model and the pipeline to trigger the publishing.
The steps will be similar to the last chapter, but we will use the pipeline to automate the process.
In this chapter, you will learn how to:
- Grant access to the container registry on the cloud provider for the CI/CD pipeline
- Store the container registry credentials in the CI/CD configuration
- Create the CI/CD pipeline for publishing the model to the container registry
The following diagram illustrates the control flow of the experiment at the end of this chapter:
flowchart TB
dot_dvc[(.dvc)] <-->|dvc pull
dvc push| s3_storage[(S3 Storage)]
dot_git[(.git)] <-->|git pull
git push| repository[(Repository)]
workspaceGraph <-....-> dot_git
data[data/raw]
subgraph cacheGraph[CACHE]
dot_dvc
dot_git
end
subgraph workspaceGraph[WORKSPACE]
data --> code[*.py]
subgraph dvcGraph["dvc.yaml"]
code
end
params[params.yaml] -.- code
code <--> bento_model[classifier.bentomodel]
subgraph bentoGraph[bentofile.yaml]
bento_model
serve[serve.py] <--> bento_model
end
bento_model <-.-> dot_dvc
end
subgraph remoteGraph[REMOTE]
s3_storage
subgraph gitGraph[Git Remote]
repository <--> |...|action[Action]
end
registry[(Container
registry)]
action --> |bentoml build
bentoml containerize
docker push|registry
end
style workspaceGraph opacity:0.4,color:#7f7f7f80
style dvcGraph opacity:0.4,color:#7f7f7f80
style cacheGraph opacity:0.4,color:#7f7f7f80
style data opacity:0.4,color:#7f7f7f80
style dot_git opacity:0.4,color:#7f7f7f80
style dot_dvc opacity:0.4,color:#7f7f7f80
style code opacity:0.4,color:#7f7f7f80
style bentoGraph opacity:0.4,color:#7f7f7f80
style serve opacity:0.4,color:#7f7f7f80
style bento_model opacity:0.4,color:#7f7f7f80
style params opacity:0.4,color:#7f7f7f80
style s3_storage opacity:0.4,color:#7f7f7f80
style remoteGraph opacity:0.4,color:#7f7f7f80
style gitGraph opacity:0.4,color:#7f7f7f80
style repository opacity:0.4,color:#7f7f7f80
linkStyle 0 opacity:0.4,color:#7f7f7f80
linkStyle 1 opacity:0.4,color:#7f7f7f80
linkStyle 2 opacity:0.4,color:#7f7f7f80
linkStyle 3 opacity:0.4,color:#7f7f7f80
linkStyle 4 opacity:0.4,color:#7f7f7f80
linkStyle 5 opacity:0.4,color:#7f7f7f80
linkStyle 6 opacity:0.4,color:#7f7f7f80
linkStyle 7 opacity:0.4,color:#7f7f7f80
linkStyle 8 opacity:0.4,color:#7f7f7f80
Steps¶
Set up access to the container registry of the cloud provider¶
The container registry will need to be accessed inside the CI/CD pipeline to push the Docker image.
This is the same process you did for DVC as described in Chapter 2.3 - Reproduce the ML experiment in a CI/CD pipeline but this time for the container registry.
Update the Google Service Account and its associated Google Service Account Key to access Google Cloud from the CI/CD pipeline without your own credentials.
# Set the Cloud Storage permissions for the Google Service Account
gcloud projects add-iam-policy-binding $GCP_PROJECT_ID \
--member="serviceAccount:google-service-account@${GCP_PROJECT_ID}.iam.gserviceaccount.com" \
--role="roles/storage.objectAdmin"
# Set the Artifact Registry permissions for the Google Service Account
gcloud projects add-iam-policy-binding $GCP_PROJECT_ID \
--member="serviceAccount:google-service-account@${GCP_PROJECT_ID}.iam.gserviceaccount.com" \
--role="roles/artifactregistry.createOnPushWriter"
Tip
There is no need to update the value in the CI/CD pipeline configuration.
All changes are made at the Google Cloud level and the key file is not changed.
Add container registry CI/CD secrets¶
Add the container registry secret to access the container registry from the CI/CD pipeline. Depending on the CI/CD platform you are using, the process will be different:
Create the following new variables by going to the Settings section from the top header of your GitHub repository. Select Secrets and variables > Actions and select New repository secret:
GCP_CONTAINER_REGISTRY_HOST: The host of the container registry (ex:europe-west6-docker.pkg.dev/mlops-surname-project/mlops-surname-registry, from the variableGCP_CONTAINER_REGISTRY_HOSTin the previous chapter)
Save the variables by selecting Add secret.
Update the CI/CD pipeline configuration file¶
You will adjust the pipeline to build and push the Docker image to the container registry. The following steps will be performed:
- Detect a new commit on the
mainbranch - Authenticate to the cloud provider
- Build the Docker image
- Push the Docker image to the container registry
Update the .github/workflows/mlops.yaml file with the following content.
Take some time to understand the deploy job and its steps:
name: MLOps
on:
# Runs on pushes targeting main branch
push:
branches:
- main
# Runs on pull requests
pull_request:
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
jobs:
train-report-and-publish:
permissions: write-all
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Setup Python
uses: actions/setup-python@v6
with:
python-version: '3.13'
cache: pip
- name: Install dependencies
run: pip install -r requirements-freeze.txt
- name: Login to Google Cloud
uses: google-github-actions/auth@v3
with:
credentials_json: '${{ secrets.GOOGLE_SERVICE_ACCOUNT_KEY }}'
- name: Train model
run: dvc repro --pull
- name: Setup CML
if: github.event_name == 'pull_request'
uses: iterative/setup-cml@v2
with:
version: '0.20.6'
- name: Create CML report
if: github.event_name == 'pull_request'
env:
REPO_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
# Fetch all other Git branches
git fetch --depth=1 origin main:main
# Add title to the report
echo "# Experiment Report (${{ github.sha }})" >> report.md
# Compare parameters to main branch
echo "## Params workflow vs. main" >> report.md
dvc params diff main --md >> report.md
# Compare metrics to main branch
echo "## Metrics workflow vs. main" >> report.md
dvc metrics diff main --md >> report.md
# Compare plots (images) to main branch
dvc plots diff main
# Create plots
echo "## Plots" >> report.md
# Create training history plot
echo "### Training History" >> report.md
echo "#### main" >> report.md
echo '' >> report.md
echo "#### workspace" >> report.md
echo '' >> report.md
# Create predictions preview
echo "### Predictions Preview" >> report.md
echo "#### main" >> report.md
echo '' >> report.md
echo "#### workspace" >> report.md
echo '' >> report.md
# Create confusion matrix
echo "### Confusion Matrix" >> report.md
echo "#### main" >> report.md
echo '' >> report.md
echo "#### workspace" >> report.md
echo '' >> report.md
# Publish the CML report
cml comment update --target=pr --publish report.md
- name: Log in to the Container registry
uses: docker/login-action@v4
with:
registry: ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}
username: _json_key
password: ${{ secrets.GOOGLE_SERVICE_ACCOUNT_KEY }}
- name: Import the BentoML model
if: github.ref == 'refs/heads/main'
run: bentoml models import model/celestial_bodies_classifier_model.bentomodel
- name: Build the BentoML model artifact
if: github.ref == 'refs/heads/main'
run: bentoml build src
- name: Containerize and publish the BentoML model artifact Docker image
if: github.ref == 'refs/heads/main'
run: |
# Containerize the Bento
bentoml containerize celestial_bodies_classifier:latest \
--image-tag ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier:latest \
--image-tag ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier:${{ github.sha }}
# Push the container to the Container Registry
docker push --all-tags ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier
Check the differences with Git to validate the changes.
# Show the differences with Git
git diff .github/workflows/mlops.yaml
The output should be similar to this:
diff --git a/.github/workflows/mlops.yaml b/.github/workflows/mlops.yaml
index 1fa989b..6d479ef 100644
--- a/.github/workflows/mlops.yaml
+++ b/.github/workflows/mlops.yaml
@@ -13,7 +13,7 @@ on:
workflow_dispatch:
jobs:
- train-and-report:
+ train-report-and-publish:
permissions: write-all
runs-on: ubuntu-latest
steps:
@@ -85,3 +85,43 @@ jobs:
# Publish the CML report
cml comment update --target=pr --publish report.md
+ - name: Log in to the Container registry
+ uses: docker/login-action@v4
+ with:
+ registry: ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}
+ username: _json_key
+ password: ${{ secrets.GOOGLE_SERVICE_ACCOUNT_KEY }}
+ - name: Import the BentoML model
+ if: github.ref == 'refs/heads/main'
+ run: bentoml models import model/celestial_bodies_classifier_model.bentomodel
+ - name: Build the BentoML model artifact
+ if: github.ref == 'refs/heads/main'
+ run: bentoml build src
+ - name: Containerize and publish the BentoML model artifact Docker image
+ if: github.ref == 'refs/heads/main'
+ run: |
+ # Containerize the Bento
+ bentoml containerize celestial_bodies_classifier:latest \
+ --image-tag ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier:latest \
+ --image-tag ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier:${{ github.sha }}
+ # Push the container to the Container Registry
+ docker push --all-tags ${{ secrets.GCP_CONTAINER_REGISTRY_HOST }}/celestial-bodies-classifier
Check the changes¶
Check the changes with Git to ensure that all the necessary files are tracked:
# Add all the files
git add .
# Check the changes
git status
The output should look similar to this:
On branch main
Your branch is up to date with 'origin/main'.
Changes to be committed:
(use "git restore --staged <file>..." to unstage)
modified: .github/workflows/mlops.yaml
Commit the changes to Git¶
Commit the changes to Git.
# Commit the changes
git commit -m "Use the pipeline to containerize and publish the model artifact to the model registry"
# Push the changes
git push
Check the published image in the container registry¶
Once the CI/CD pipeline has completed successfully, open the
Artifact Registry on the Google
Cloud interface and click on your registry to access the details. The new
celestial-bodies-classifier image should appear with both the latest and
commit SHA tags.
Summary¶
Congratulations! You have successfully prepared the model for automated deployment in a production environment with the CI/CD pipeline!
In this chapter, you have successfully:
- Automated the containerization and publication of the BentoML model artifact to the container registry
You fixed some of the previous issues:
- Model publication to the artifact registry is automated
Take away
- Automation prevents deployment drift: By building and publishing models automatically in the CI/CD pipeline, you ensure that every model version that reaches production follows the exact same build process, eliminating manual steps that can introduce errors.
- Service accounts enable secure automation: Using cloud service accounts with minimal required permissions (rather than personal credentials) follows the principle of least privilege and allows CI/CD pipelines to authenticate securely without exposing sensitive credentials.
- Secrets management is critical for cloud integration: Properly storing credentials as CI/CD secrets (masked, encrypted, and access-controlled) prevents accidental exposure while allowing automated workflows to interact with cloud resources like container registries.
- Automated publication shortens the deployment cycle: Automatically publishing new model versions to the container registry on every merge to main enables rapid iteration and reduces the time from model improvement to production deployment.
State of the MLOps process¶
- Model can be saved and loaded with all required artifacts for future usage
- Model can be easily used outside of the experiment context
- Model publication to the artifact registry is automated
- Model is not accessible on the Internet and cannot be used anywhere
- Model requires manual deployment on the cluster
- Model cannot be trained on hardware other than the local machine
- Model cannot be trained on custom hardware for specific use-cases
Continue to the next chapters to address the remaining items.
Sources¶
Highly inspired by: