You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Secret Scope在Databricks中挂载Azure Data Lake失败求助

挂载Azure Data Lake Storage时出现NullPointerException的排查方案

无法通过Secret Scope挂载Azure Data Lake Storage,执行脚本时抛出NullPointerException。脚本中的applicationID和tenantID已替换为占位符,实际值来自Azure应用注册,且已为服务主体分配Azure Blob Storage的Blob Contributor权限。

执行脚本

adlsAccountName = "adfsourcefileaccount"
adlsContainerName = "databricks"

mountPoint = "/mnt/{0}/{1}".format(adlsAccountName, adlsContainerName)

applicationId = "xxx"

tenantId = "yyy"

secret_scope = "create-mount"

secret_key = "adfsourcefileaccount"

authenticationKey = dbutils.secrets.get(scope = secret_scope, key = secret_key)

endpoint = "https://login.microsoftonline.com/"+ tenantId + "/oauth2/token"

source = "abfss://" + adlsContainerName + "@" + adlsAccountName + ".dfs.core.windows.net/"

configs = {"fs.azure.account.auth.type": "OAuth",
           "fs.azure.account.oauth.provider.type": "org.apache.hadoop.fs.azurebfs.oauth2.ClientCredsTokenProvider",
           "fs.azure.account.oauth2.client.id": applicationId,
           "fs.azure.account.oauth2.client.secret":authenticationKey,
           "fs.azure.account.oauth2.client.endpoint":endpoint}

if (any(mount.mountPoint == mountPoint for mount in dbutils.fs.mounts())):

    dbutils.fs.ls(mountPoint)

    print(mountPoint + "already exists")
else:

    mountstatus = dbutils.fs.mount(
        source = source,
        mount_point = mountPoint,
        extra_configs = configs
    )

    print(mountPoint + " : mount point is created and status is " + str(mountstatus))

排查步骤

  • 验证Secret Scope与密钥:确认create-mount Secret Scope存在,adfsourcefileaccount密钥已正确存储服务主体的客户端密钥。可执行dbutils.secrets.list("create-mount")检查密钥是否存在,避免因密钥缺失导致authenticationKey为空。
  • 修正服务主体权限:ADLS Gen2需要的是Storage Blob Data Contributor权限(而非普通Blob Contributor),确保该权限直接分配给目标存储账户或容器,且权限已生效。
  • 核对存储资源信息:确认adfsourcefileaccount是有效的ADLS Gen2账户名,databricks容器已在该账户中创建,无名称拼写错误。
  • 检查OAuth端点格式:确保tenantID为正确的GUID格式,拼接后的端点https://login.microsoftonline.com/[tenant-id]/oauth2/token无格式错误。
  • 直接测试存储访问:先执行dbutils.fs.ls(source, configs)直接访问存储,不挂载,排查是挂载逻辑问题还是权限/配置问题。
  • 升级Databricks Runtime:旧版本Runtime可能存在兼容性问题,建议使用7.3 LTS及以上版本。

内容的提问来源于stack exchange,提问作者awesome_sangram

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 23:55:17