使用服务主体在Databricks中创建Token失败,请求排查
Databricks服务主体创建Token未授权问题排查
问题描述
我使用以下PowerShell代码在Databricks工作区中创建Token,该脚本通过服务主体(SPN)进行身份验证,且该服务主体已被添加为工作区用户并加入管理员组,但持续收到未授权访问错误,请问哪里操作有误?
function Get-DatabricksTokenWithRestAPI { [CmdletBinding()] param ( [Parameter(Mandatory=$true)] [string]$DatabricksInstanceUrl, [Parameter(Mandatory=$true)] [string]$ClientId, [Parameter(Mandatory=$true)] [string]$ClientSecret, [Parameter(Mandatory=$true)] [string]$TenantId ) # Define the REST API endpoint for listing the user's tokens $listTokensEndpoint = "$DatabricksInstanceUrl/api/2.0/token/list" # Define the body of the REST API request $body = @{ "client_id" = $ClientId "client_secret" = $ClientSecret "tenant_id" = $TenantId } # Send the list tokens REST API request and retrieve the response $listTokensResponse = Invoke-RestMethod -Method Post -Uri $listTokensEndpoint -Body ($body | ConvertTo-Json) # Check if a Databricks token already exists in the workspace foreach ($tokenInfo in $listTokensResponse.token_infos) { if ($tokenInfo.comment -eq "Databricks CLI token") { Write-Host "Using existing Databricks token" return $tokenInfo.token_value } } # Define the REST API endpoint for generating a token $generateTokenEndpoint = "$DatabricksInstanceUrl/api/2.0/token/create" # Send the generate token REST API request and retrieve the response $generateTokenResponse = Invoke-RestMethod -Method Post -Uri $generateTokenEndpoint -Body ($body | ConvertTo-Json) # Retrieve the token from the response $token = $generateTokenResponse.token_value return $token }
错误原因及修复方案
身份验证流程错误
你直接将SPN的凭证放入Databricks API请求体的方式不被支持。SPN需要先向Azure AD申请访问令牌,再用该令牌作为Bearer Token调用Databricks API。
修复步骤:- 先获取Azure AD访问令牌:
$aadTokenEndpoint = "https://login.microsoftonline.com/$TenantId/oauth2/v2.0/token" $aadBody = @{ grant_type = "client_credentials" client_id = $ClientId client_secret = $ClientSecret scope = "$DatabricksInstanceUrl/.default" } $aadResponse = Invoke-RestMethod -Method Post -Uri $aadTokenEndpoint -Body $aadBody $accessToken = $aadResponse.access_token - 调用Databricks API时添加Authorization头,不再在请求体中传递SPN凭证:
$listTokensResponse = Invoke-RestMethod -Method Post -Uri $listTokensEndpoint ` -Headers @{Authorization = "Bearer $accessToken"} ` -ContentType "application/json"
- 先获取Azure AD访问令牌:
API请求体格式错误
token/list接口不需要请求体,你当前传递的SPN凭证会被Databricks视为无效请求,导致认证失败。token/create接口需要的请求体是包含令牌备注和有效期的JSON,而非SPN凭证:$createBody = @{ comment = "Databricks CLI token" lifetime_seconds = 31536000 # 可自定义有效期,单位为秒 } | ConvertTo-Json $generateTokenResponse = Invoke-RestMethod -Method Post -Uri $generateTokenEndpoint ` -Headers @{Authorization = "Bearer $accessToken"} ` -Body $createBody ` -ContentType "application/json"
权限配置验证
即使SPN已加入管理员组,仍需确认:- SPN的工作区权限是否完成同步,可尝试重新添加SPN到工作区并等待数分钟。
- 确认工作区未限制管理员组的令牌生成权限,默认管理员组拥有该权限,但自定义权限规则可能覆盖默认设置。
内容的提问来源于stack exchange,提问作者Sudama Tripathi
相关产品推荐
相关产品推荐

