如何通过Terraform启用Azure Databricks工作区的Unity Catalog?
如何通过Terraform为Azure Databricks工作区启用Unity Catalog
要在现有Terraform配置中启用Unity Catalog,你需要完成以下关键配置:
1. 更新Databricks工作区资源,添加Unity Catalog关联配置
在你的azurerm_databricks_workspace资源块中,新增unity_catalog_configuration块,关联已生成的托管标识、访问连接器和存储根路径:
resource "azurerm_databricks_workspace" "this" { name = "${local.prefix}-workspace" resource_group_name = azurerm_resource_group.this.name location = azurerm_resource_group.this.location sku = "premium" managed_resource_group_name = "${local.prefix}-workspace-rg" tags = local.tags # 新增Unity Catalog配置块 unity_catalog_configuration { managed_identity_id = azurerm_user_assigned_identity.this.id # 替换为你的托管标识资源引用 storage_root_path = "abfss://${azurerm_storage_container.this.name}@${azurerm_storage_account.this.name}.dfs.core.windows.net/" access_connector_id = azurerm_databricks_access_connector.this.id # 替换为你的访问连接器资源引用 } }
2. 创建并关联Unity Catalog元存储
启用Unity Catalog后,需要创建元存储并分配给工作区,才能正常使用Catalog功能:
# 创建Unity Catalog元存储 resource "azurerm_databricks_metastore" "this" { name = "${local.prefix}-metastore" resource_group_name = azurerm_resource_group.this.name location = azurerm_resource_group.this.location storage_root_path = azurerm_databricks_workspace.this.unity_catalog_configuration[0].storage_root_path managed_identity_id = azurerm_user_assigned_identity.this.id } # 将元存储分配给Databricks工作区 resource "azurerm_databricks_metastore_assignment" "this" { workspace_id = azurerm_databricks_workspace.this.id metastore_id = azurerm_databricks_metastore.this.id default_catalog = "hive_metastore" # 可指定默认目录名称 }
关键注意事项
- 确保你的托管标识对目标存储容器拥有存储Blob数据参与者权限,否则Unity Catalog无法读写存储
- 存储根路径必须使用
abfss://格式(ADLS Gen2路径),不能用旧的wasbs://格式 - 访问连接器需已配置为允许Databricks服务访问相关资源
内容的提问来源于stack exchange,提问作者Ruben Ravnå
相关产品推荐
相关产品推荐

