You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Databricks配置或PySpark会话中设置additionallyAllowedTenants?

在Databricks中配置多租户Azure应用的additionallyAllowedTenants参数

下面是几种实用的实现思路,按需选择:

1. 集群全局配置(一次性生效)

编辑Databricks集群时,找到Spark配置区域,添加以下配置项:

  • 允许所有租户:
    spark.databricks.azuread.tokenProviderClassName com.microsoft.azure.synapse.tokenlibrary.MultiTenantAzureADTokenProvider
    spark.databricks.azuread.additionallyAllowedTenants *
    
  • 只允许特定租户:
    spark.databricks.azuread.tokenProviderClassName com.microsoft.azure.synapse.tokenlibrary.MultiTenantAzureADTokenProvider
    spark.databricks.azuread.additionallyAllowedTenants <你的租户ID>
    

配置完成后重启集群,整个集群上所有使用Azure AD凭据访问ADLS的操作都会自动应用这个租户规则。

2. PySpark会话级别配置(仅当前会话有效)

如果不想影响整个集群,就在代码里给当前Spark会话单独设置:

# 允许所有租户
spark.conf.set("spark.databricks.azuread.additionallyAllowedTenants", "*")

# 或者指定单个租户
# spark.conf.set("spark.databricks.azuread.additionallyAllowedTenants", "<你的租户ID>")

这个设置只在当前Notebook或作业的会话周期内生效,重启会话后需要重新设置。

3. 代码显式构建凭据(精细化控制)

要是需要针对某一次ADLS读取任务单独配置,直接在代码里手动初始化带参数的凭据:

from azure.identity import DefaultAzureCredential

# 初始化多租户凭据
credential = DefaultAzureCredential(additionally_allowed_tenants=['*'])

# 结合Spark读取ADLS的示例:配置Spark使用自定义凭据
storage_account = "<你的存储账户名>"
spark.conf.set(f"fs.azure.account.auth.type.{storage_account}.dfs.core.windows.net", "OAuth")
spark.conf.set(f"fs.azure.account.oauth.provider.type.{storage_account}.dfs.core.windows.net", "org.apache.hadoop.fs.azurebfs.oauth2.ClientCredsTokenProvider")
spark.conf.set(f"fs.azure.account.oauth2.client.id.{storage_account}.dfs.core.windows.net", "<你的应用ID>")
spark.conf.set(f"fs.azure.account.oauth2.client.secret.{storage_account}.dfs.core.windows.net", "<你的应用密钥>")
spark.conf.set(f"fs.azure.account.oauth2.client.endpoint.{storage_account}.dfs.core.windows.net", "https://login.microsoftonline.com/<租户ID>/oauth2/token")

# 读取ADLS文件到DataFrame
df = spark.read.csv(f"abfss://<容器名>@{storage_account}.dfs.core.windows.net/目标路径")

这种方式灵活性最高,适合单个任务有特殊租户需求的场景。

注意事项

  • 生产环境尽量用具体租户ID替代*,降低安全风险。
  • 确保你的Azure应用已经在目标租户中获得了ADLS的访问权限(比如分配Storage Blob Data Contributor角色)。

内容的提问来源于stack exchange,提问作者Soumik Das

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 04:57:15