Databricks GitHub Action授权失败问题排查求助
Databricks GitHub Action授权失败排查方案
问题背景
此前运行正常的Databricks GitHub Action突然报错,持续返回:
Error: Authorization failed. Your token may be expired or lack the valid scope
该Action仅用于更新Databricks仓库,相关配置及运行日志如下:
GitHub Action配置
name: "Update Databricks PROD repo" on: push: branches: - main jobs: sync_job: runs-on: ubuntu-latest name: Job to sync Databricks PROD repo when releasing steps: - name: update databricks prod repo run: | echo "updating databricks repo: prod" python -m pip install --upgrade databricks-cli cat > ~/.databrickscfg << EOF [DEFAULT] host = ${{ vars.DATABRICKS_HOST }} token = ${{ secrets.DATABRICKS_TOKEN }} jobs-api-version = 2.1 EOF databricks repos update --path /Repos/prod/mindset_etl --branch main
Action运行日志
echo "updating databricks repo: prod" python -m pip install --upgrade databricks-cli cat > ~/.databrickscfg << EOF [DEFAULT] host = https://adb-xxxxxxxxxxxxxxxx.2.azuredatabricks.net/?o=xxxxxxxxxxxxxxxx token = *** jobs-api-version = 2.1 EOF databricks repos update --path /Repos/prod/mindset_etl --branch main shell: /usr/bin/bash -e {0} updating databricks repo: prod Defaulting to user installation because normal site-packages is not writeable Collecting databricks-cli Downloading databricks_cli-0.18.0-py2.py3-none-any.whl (150 kB) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 150.3/150.3 KB 3.4 MB/s eta 0:00:00 Collecting urllib3<3,>=1.26.7 Downloading urllib3-2.2.1-py3-none-any.whl (121 kB) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 121.1/121.1 KB 13.7 MB/s eta 0:00:00 Requirement already satisfied: click>=7.0 in /usr/lib/python3/dist-packages (from databricks-cli) (8.0.3) Requirement already satisfied: oauthlib>=3.1.0 in /usr/lib/python3/dist-packages (from databricks-cli) (3.2.0) Requirement already satisfied: pyjwt>=1.7.0 in /usr/lib/python3/dist-packages (from databricks-cli) (2.3.0) Requirement already satisfied: requests>=2.17.3 in /usr/lib/python3/dist-packages (from databricks-cli) (2.25.1) Requirement already satisfied: six>=1.10.0 in /usr/lib/python3/dist-packages (from databricks-cli) (1.16.0) Collecting tabulate>=0.7.7 Downloading tabulate-0.9.0-py3-none-any.whl (35 kB) Installing collected packages: urllib3, tabulate, databricks-cli Successfully installed databricks-cli-0.18.0 tabulate-0.9.0 urllib3-2.2.1 /usr/lib/python3/dist-packages/requests/__init__.py:87: RequestsDependencyWarning: urllib3 (2.2.1) or chardet (4.0.0) doesn't match a supported version! warnings.warn("urllib3 ({}) or chardet ({}) doesn't match a supported " Error: Authorization failed. Your token may be expired or lack the valid scope
可能的原因及排查方向
- Databricks令牌过期:Databricks个人访问令牌默认最长有效期为90天,若令牌超出有效期会直接触发授权失败。需在Databricks控制台重新生成令牌,并更新GitHub仓库的
DATABRICKS_TOKEN密钥。 - 令牌权限范围不足:执行
databricks repos update操作需要令牌具备仓库读写权限。检查生成令牌时是否勾选了Repos Read/Write相关权限,或是否后续权限被管理员调整。 - 主机地址格式异常:日志中host带
?o=xxxxxxxxxxxxxxxx参数,虽多数场景可正常识别,但部分情况下会导致CLI解析错误。尝试去掉参数,仅保留基础地址(如https://adb-xxxxxxxxxxxxxxxx.2.azuredatabricks.net/),更新GitHub的DATABRICKS_HOST变量后重试。 - CLI版本兼容性问题:日志中安装了最新的0.18.0版本,同时出现urllib3版本不兼容警告。虽警告不直接导致授权失败,但版本冲突可能引发潜在问题。可指定安装稳定版本(如
pip install databricks-cli==0.17.7)测试。 - 仓库路径/权限变更:确认
/Repos/prod/mindset_etl路径正确,且令牌对应用户对该仓库有分支切换、更新权限。若仓库被移动或权限被修改,也会导致授权失败。
内容的提问来源于stack exchange,提问作者iambdot
相关产品推荐
相关产品推荐

