You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无需PAT令牌,从Azure API管理调用Azure Databricks API的方法

可行的无交互认证方案

方案1:Azure AD服务主体认证

这是通用的服务对服务无交互认证方案,步骤如下:

  • 在Azure AD中注册服务主体,记录其客户端ID、客户端密钥和租户ID
  • 登录Databricks工作区,将该服务主体添加为工作区用户,并分配所需权限(如Workspace User、Cluster Admin等,根据API调用需求调整)
  • 在Azure API管理的API策略中,添加获取Azure AD令牌并注入请求头的逻辑:
<choose>
    <when condition="@(!context.Request.Headers.ContainsKey("Authorization"))">
        <send-request mode="new" response-variable-name="databricksToken" timeout="20" ignore-error="false">
            <set-url>https://login.microsoftonline.com/{租户ID}/oauth2/v2.0/token</set-url>
            <set-method>POST</set-method>
            <set-header name="Content-Type" exists-action="override">
                <value>application/x-www-form-urlencoded</value>
            </set-header>
            <set-body>@($"client_id={客户端ID}&client_secret={客户端密钥}&grant_type=client_credentials&scope=2ff814a6-3304-4ab8-85cb-cd0e6f879c1d%2F.default")</set-body>
        </send-request>
        <set-header name="Authorization" exists-action="override">
            <value>@($"Bearer {((JObject)context.Variables["databricksToken"]).GetValue("access_token")}")</value>
        </set-header>
    </when>
</choose>

注:2ff814a6-3304-4ab8-85cb-cd0e6f879c1d是Databricks的固定Azure AD资源ID,无需修改

方案2:托管标识(Managed Identity)认证

无需管理客户端密钥,安全性更高,适合Azure内部服务间调用:

  • 给Azure API管理启用系统分配托管标识(或创建用户分配托管标识并关联)
  • 在Databricks工作区中,将该托管标识添加为工作区用户,并分配对应权限
  • 在API管理的API策略中,利用托管标识自动获取令牌:
<authentication-managed-identity resource="2ff814a6-3304-4ab8-85cb-cd0e6f879c1d" output-token-variable-name="databricksToken" ignore-error="false" />
<set-header name="Authorization" exists-action="override">
    <value>@($"Bearer {context.Variables["databricksToken"]}")</value>
</set-header>

注:如果使用用户分配托管标识,需在authentication-managed-identity标签中添加client-id属性指定标识的客户端ID

方案3:Databricks原生服务主体认证

使用Databricks自身的服务主体实现认证:

  • 在Databricks工作区中创建服务主体,生成其令牌(注意令牌有效期)
  • 在API管理的命名值中存储该令牌(避免硬编码)
  • 在API策略中直接注入Authorization头:
<set-header name="Authorization" exists-action="override">
    <value>@($"Bearer {{databricks-service-principal-token}}")</value>
</set-header>

注:这种方式需要定期更新令牌,自动化程度低于前两种,适合短期场景


内容的提问来源于stack exchange,提问作者Vinit Patel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 06:48:27