You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从Azure Databricks写入OneLake遇403权限错误,求认证方法

解决Azure Databricks向OneLake写入的403认证问题

针对你遇到的403权限错误,以下是几种在Azure Databricks中向OneLake完成身份认证的可行方案:

方案1:Azure AD服务主体认证(生产环境推荐)

通过注册Azure AD服务主体并分配权限,实现无用户交互的自动化认证:

  1. 在Azure AD中注册一个服务主体,为其分配OneLake对应工作区/湖仓的Contributor或Storage Blob Data Contributor权限(权限需在Fabric控制台中配置)。
  2. 在Databricks Secrets中存储服务主体的租户ID、客户端ID、客户端密钥,避免硬编码敏感信息。
  3. 配置Spark参数并执行写入:
# 从Databricks Secrets读取凭据
tenant_id = dbutils.secrets.get(scope="你的密钥范围", key="tenant-id")
client_id = dbutils.secrets.get(scope="你的密钥范围", key="client-id")
client_secret = dbutils.secrets.get(scope="你的密钥范围", key="client-secret")

# 配置OneLake的Azure AD认证参数
spark.conf.set("fs.azure.account.auth.type.onelake.dfs.fabric.microsoft.com", "OAuth")
spark.conf.set("fs.azure.account.oauth.provider.type.onelake.dfs.fabric.microsoft.com", "org.apache.hadoop.fs.azurebfs.oauth2.ClientCredsTokenProvider")
spark.conf.set("fs.azure.account.oauth2.client.id.onelake.dfs.fabric.microsoft.com", client_id)
spark.conf.set("fs.azure.account.oauth2.client.secret.onelake.dfs.fabric.microsoft.com", client_secret)
spark.conf.set("fs.azure.account.oauth2.client.endpoint.onelake.dfs.fabric.microsoft.com", f"https://login.microsoftonline.com/{tenant_id}/oauth2/token")

# 读取源数据
df_zipped = spark.read.format("parquet").option("compression", "gzip").option("header", True).load("/mnt/defined/measuremts-2019.gz.parquet")

# 使用ABFSS格式路径写入OneLake(推荐格式)
oneLake_path = "abfss://22f90e-f0d9-4559008060a@onelake.dfs.fabric.microsoft.com/d36-47c2-83e3-676eec7d9/Files/RAW"
df_zipped.write.format("csv").option("header", "true").mode("overwrite").save(oneLake_path)

方案2:Azure AD身份传递(适合交互式场景)

如果你的Databricks集群启用了Azure AD凭据传递功能,可直接复用当前用户的身份访问OneLake:

  1. 确保Databricks集群开启Azure AD credential passthrough for Azure Storage选项。
  2. 给当前Azure AD用户分配OneLake对应工作区/湖仓的写入权限。
  3. 直接使用ABFSS路径执行写入:
df_zipped = spark.read.format("parquet").option("compression", "gzip").option("header", True).load("/mnt/defined/measuremts-2019.gz.parquet")

oneLake_path = "abfss://22f90e-f0d9-4559008060a@onelake.dfs.fabric.microsoft.com/d36-47c2-83e3-676eec7d9/Files/RAW"
df_zipped.write.format("csv").option("header", "true").mode("overwrite").save(oneLake_path)

方案3:SAS令牌认证(仅临时测试使用)

生成OneLake湖仓的SAS令牌(需包含写入权限),通过Spark配置传入令牌:

sas_token = dbutils.secrets.get(scope="你的密钥范围", key="onelake-sas-token")

# 配置SAS令牌认证参数
spark.conf.set("fs.azure.account.auth.type.onelake.dfs.fabric.microsoft.com", "SAS")
spark.conf.set("fs.azure.sas.token.provider.type.onelake.dfs.fabric.microsoft.com", "org.apache.hadoop.fs.azurebfs.sas.FixedSASTokenProvider")
spark.conf.set("fs.azure.sas.fixed.token.onelake.dfs.fabric.microsoft.com", sas_token)

df_zipped = spark.read.format("parquet").option("compression", "gzip").option("header", True).load("/mnt/defined/measuremts-2019.gz.parquet")
oneLake_path = "abfss://22f90e-f0d9-4559008060a@onelake.dfs.fabric.microsoft.com/d36-47c2-83e3-676eec7d9/Files/RAW"
df_zipped.write.format("csv").option("header", "true").mode("overwrite").save(oneLake_path)

关键注意事项

  • 所有身份(服务主体/用户)必须拥有OneLake目标湖仓的写入权限,权限需在Fabric工作区或湖仓的权限设置中配置。
  • 优先使用ABFSS格式路径而非直接HTTPS URL,Spark对ABFSS的兼容性更完善。
  • 敏感凭据必须存入Databricks Secrets,禁止在代码中硬编码。

内容的提问来源于stack exchange,提问作者rpshgupta

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 17:23:17