使用AtlasClient在Purview指定集合创建实体遇授权问题
问题描述
运行代码时遇到AtlasException:
{"requestId":"36fb4fc3-bc6b-4583-b6a1-faac6a5723b4","errorCode":"ATLAS-403-00-001","errorMessage":"5133fd99-b486-4723-ac91-c8acc375a4ed is not authorized to perform create entity: type=test file"}注意:仅拥有Purview中特定集合的访问权限,无法在根集合中创建实体。
运行的代码
from azure.identity import ClientSecretCredential from pyapacheatlas.auth import ServicePrincipalAuthentication from pyapacheatlas.core import AtlasClient, collections from pyapacheatlas.core import AtlasEntity, RelationshipTypeDef import requests import os import json import pandas as pd import pydicom # Azure AD credentials tenant_id = "xxxxxxxxxxxxxxxxxxxx" client_id = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" client_secret = "xxxxxxxxxxxxxxxxxxxxxxxxxxx" # Purview account details purview_account_name = "account-name" collection_name = "abcde" # Authenticate using AAD credential = ClientSecretCredential(tenant_id, client_id, client_secret) auth = ServicePrincipalAuthentication( tenant_id=tenant_id, client_id=client_id, client_secret=client_secret ) # Create an Atlas client client = AtlasClient( endpoint_url=f"https://{purview_account_name}.purview.azure.com/catalog/api/atlas/v2", authentication=auth ) entity_up = AtlasEntity( name="API_TEST_NEW", typeName='test file', qualified_name="TESTING_API_NEW", attributes={ "description": "A sample entity with custom attributes", "businessAttributes": { "businessAttribute1": "Business Value 1", "businessAttribute2": "Business Value 2" }, "customAttributes": { "customKey1": "Custom Value 1", "customKey2": "Custom Value 2" } }, collectionId = 'abcde', domainId = 'account-name', contacts = { "Expert": [ { "id": "xxxxxxxxxxxxxxxxx", "info": "Example Expert Info" } ], "Owner": [ { "id": "xxxxxxxxxxxxxxxxxxxxxxxxxx", "info": "Example Owner Info" } ] }, ) client.upload_entities(entity_up)
提问
如何使用AtlasClient在特定集合(而非根集合)中创建实体?已能通过PurviewClient实现,但使用AtlasClient时遇到问题。
解决方案
问题核心是未正确指定集合上下文,且AtlasEntity中误用了无效参数。按以下步骤修正:
- 获取目标集合的唯一ID
不能直接使用集合名称abcde,需先通过AtlasClient查询集合的实际ID:
# 获取指定集合的详细信息,提取唯一ID collection_details = client.get_collection(collection_name) target_collection_id = collection_details["collectionId"]
- 在上传时指定集合
AtlasEntity本身不支持直接设置collectionId属性,需通过upload_entities接口的collection参数显式指定,或在初始化AtlasClient时设置默认集合:
- 方式一:上传时指定集合
client.upload_entities(entity_up, collection=target_collection_id)
- 方式二:初始化客户端时设置默认集合
client = AtlasClient( endpoint_url=f"https://{purview_account_name}.purview.azure.com/catalog/api/atlas/v2", authentication=auth, default_collection=target_collection_id )
- 清理无效参数
删除AtlasEntity中的collectionId和domainId参数,这两个不属于AtlasEntity的合法属性,会被接口忽略。
修改后的完整代码示例
from azure.identity import ClientSecretCredential from pyapacheatlas.auth import ServicePrincipalAuthentication from pyapacheatlas.core import AtlasClient from pyapacheatlas.core import AtlasEntity import requests import os import json import pandas as pd import pydicom # Azure AD credentials tenant_id = "xxxxxxxxxxxxxxxxxxxx" client_id = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" client_secret = "xxxxxxxxxxxxxxxxxxxxxxxxxxx" # Purview account details purview_account_name = "account-name" collection_name = "abcde" # Authenticate using AAD auth = ServicePrincipalAuthentication( tenant_id=tenant_id, client_id=client_id, client_secret=client_secret ) # Create an Atlas client client = AtlasClient( endpoint_url=f"https://{purview_account_name}.purview.azure.com/catalog/api/atlas/v2", authentication=auth ) # 获取目标集合的唯一ID collection_details = client.get_collection(collection_name) target_collection_id = collection_details["collectionId"] entity_up = AtlasEntity( name="API_TEST_NEW", typeName='test file', qualified_name="TESTING_API_NEW", attributes={ "description": "A sample entity with custom attributes", "businessAttributes": { "businessAttribute1": "Business Value 1", "businessAttribute2": "Business Value 2" }, "customAttributes": { "customKey1": "Custom Value 1", "customKey2": "Custom Value 2" } }, contacts = { "Expert": [ { "id": "xxxxxxxxxxxxxxxxx", "info": "Example Expert Info" } ], "Owner": [ { "id": "xxxxxxxxxxxxxxxxxxxxxxxxxx", "info": "Example Owner Info" } ] }, ) # 上传实体时指定目标集合 client.upload_entities(entity_up, collection=target_collection_id)
关键说明
- 权限错误本质是上传时默认使用了根集合,而当前账号无此权限,指定正确的目标集合即可解决。
- 必须使用集合的唯一ID而非名称,避免因名称重复导致的错误。
AtlasEntity的属性需符合PyApacheAtlas的定义,自定义集合参数应通过客户端或上传接口传递。
内容的提问来源于stack exchange,提问作者Naveen Chandraiah
相关产品推荐
相关产品推荐

