You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Synapse托管标识创建Kusto Client并复用现有代码

问题描述

我希望将当前使用AAD应用密钥的KustoClient替换为使用Synapse托管标识。我了解可通过链接服务读取Kusto集群,但希望尽可能复用现有用于执行export命令的KustoClient代码,请问是否可借助msparkutils凭据或Azure Identity的DefaultAzureCredential实现?

当前创建Kusto Client的代码:

kcsb = KustoConnectionStringBuilder.with_aad_application_key_authentication(kusto_cluster
, service_principal_id, service_principal_secret, tenant_id)
解决方案

可以通过两种方式实现,无需大幅改动现有代码:

方案一:使用Azure Identity的DefaultAzureCredential

借助DefaultAzureCredential可自动适配Synapse的托管标识环境,无需手动配置密钥或凭据。需先确保安装azure-identity和azure-kusto-data包,再修改连接字符串构建逻辑:

from azure.identity import DefaultAzureCredential
from azure.kusto.data import KustoConnectionStringBuilder

# 初始化托管标识凭据
credential = DefaultAzureCredential()
# 构建托管标识认证的连接字符串
kcsb = KustoConnectionStringBuilder.with_aad_managed_service_identity_authentication(kusto_cluster)
# 为连接字符串绑定凭据(适配部分Kusto SDK版本)
kcsb.set_credential(credential)

方案二:使用msparkutils获取凭据

如果在Synapse Spark池中运行,可直接用msparkutils获取托管标识的访问令牌,再传递给KustoClient:

from azure.kusto.data import KustoConnectionStringBuilder
import msparkutils

# 获取Kusto集群的访问令牌
token = msparkutils.credentials.getToken(kusto_cluster)
# 构建令牌认证的连接字符串
kcsb = KustoConnectionStringBuilder.with_token_authentication(kusto_cluster, token)

注意事项

  • 确保Synapse的托管标识已被授予Kusto集群的相应权限(如数据库查看者或数据库管理员),否则会触发认证失败。
  • 两种方案都能直接复用现有执行export命令的代码,仅需替换连接字符串的构建逻辑。

内容的提问来源于stack exchange,提问作者s528060

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 10:44:56