Azure Synapse Spark Notebook无法通过UAMI认证连接ADLS Gen2,求解决方法
解决Azure Synapse Spark Notebook通过用户分配托管标识(UAMI)连接ADLS Gen2的问题
确认UAMI的权限配置
确保UAMI已被授予ADLS Gen2存储账户的合适权限(如Storage Blob Data Contributor/Reader),且权限作用范围覆盖目标容器或目录。注意Synapse Pipeline的权限配置可能和Notebook的权限生效范围不同,需检查是否遗漏了目录级的权限设置。将UAMI关联到目标Spark池
- 进入Azure Synapse Studio,打开管理 > Apache Spark池
- 选中需要使用的Spark池,点击托管标识选项卡
- 添加已在Pipeline中使用的用户分配托管标识,保存配置后重启Spark池
在Notebook中显式配置UAMI认证
在Spark代码里指定使用该UAMI进行ADLS Gen2认证,示例代码如下:# 替换占位符为实际信息 storage_account = "<你的存储账户名>" uami_client_id = "<UAMI的客户端ID>" tenant_id = "<你的租户ID>" spark.conf.set(f"fs.azure.account.auth.type.{storage_account}.dfs.core.windows.net", "OAuth") spark.conf.set(f"fs.azure.account.oauth.provider.type.{storage_account}.dfs.core.windows.net", "org.apache.hadoop.fs.azurebfs.oauth2.ClientCredsTokenProvider") spark.conf.set(f"fs.azure.account.oauth2.client.id.{storage_account}.dfs.core.windows.net", uami_client_id) spark.conf.set(f"fs.azure.account.oauth2.client.secret.{storage_account}.dfs.core.windows.net", "") spark.conf.set(f"fs.azure.account.oauth2.client.endpoint.{storage_account}.dfs.core.windows.net", f"https://login.microsoftonline.com/{tenant_id}/oauth2/token")检查网络访问限制
如果ADLS Gen2存储账户设置了防火墙规则,需确认Spark池所在的虚拟网络已被添加到存储账户的允许列表中;或者根据安全要求,开启存储账户的“允许受信任的Microsoft服务访问此存储账户”选项。验证UAMI的身份有效性
在Notebook中运行以下代码,确认UAMI能正常获取访问令牌:from azure.identity import ManagedIdentityCredential uami_client_id = "<UAMI的客户端ID>" credential = ManagedIdentityCredential(client_id=uami_client_id) token = credential.get_token("https://storage.azure.com/.default") print("获取到的令牌:", token.token[:50], "...")若能成功输出令牌,说明UAMI身份认证无问题,需排查Spark配置或权限的细节。
内容的提问来源于stack exchange,提问作者user24568243
相关产品推荐
相关产品推荐

