You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Unity Catalog使用服务主体访问外部存储位置遇403权限问题

问题描述

通过Unity Catalog使用Service Principal访问Azure Data Lake Storage Gen2时触发403权限错误,已完成以下配置:

  • 为存储账户分配Contributor角色的Managed Identity
  • 将Managed Identity添加为Storage Credential
  • 以此凭据将存储容器添加为外部位置
  • 为Service Principal授予该外部位置的All Privileges权限

使用以下PySpark代码尝试写入数据:

from pyspark.sql.types import StringType

spark.conf.set(f"fs.azure.account.auth.type.{storage_account}.dfs.core.windows.net", "OAuth")
spark.conf.set(f"fs.azure.account.oauth.provider.type.{storage_account}.dfs.core.windows.net", "org.apache.hadoop.fs.azurebfs.oauth2.ClientCredsTokenProvider")
spark.conf.set(f"fs.azure.account.oauth2.client.id.{storage_account}.dfs.core.windows.net", client_id)
spark.conf.set(f"fs.azure.account.oauth2.client.secret.{storage_account}.dfs.core.windows.net", client_secret)
spark.conf.set(f"fs.azure.account.oauth2.client.endpoint.{storage_account}.dfs.core.windows.net", f"https://login.microsoftonline.com/{tenant_id}/oauth2/token")

# create and write dataframe
df = spark.createDataFrame(["10","11","13"], StringType()).toDF("values")
df.write \
  .format("delta") \
  .mode("overwrite") \
  .save(f"abfss://{container}@{storage_account}.dfs.core.windows.net/example/example-0")

执行后返回错误:

Operation failed: "This request is not authorized to perform this operation using this permission.", 403, HEAD, https://{storage-account}.dfs.core.windows.net/{container-name}/example/example-0?upn=false&action=getStatus&timeout=90

排查与解决步骤
  1. 调整Managed Identity的存储权限
    替换Contributor角色,给Managed Identity分配Storage Blob Data Contributor角色(可针对存储账户或具体容器)。该角色更精准覆盖ADLS Gen2的读写操作,避免Contributor角色在部分场景下的权限遗漏。

  2. 验证Unity Catalog权限绑定
    在Unity Catalog控制台确认:

    • 外部位置已正确关联对应的Storage Credential
    • Service Principal的All Privileges权限已成功应用,且无拒绝策略覆盖
  3. 改用Unity Catalog外部表访问存储
    直接使用ABFSS路径会绕开Unity Catalog权限控制,转而使用代码中配置的Service Principal直接访问存储(该主体无存储层级RBAC权限)。正确流程是先创建外部表:

    CREATE EXTERNAL TABLE IF NOT EXISTS example_table (values STRING)
    LOCATION 'abfss://{container}@{storage_account}.dfs.core.windows.net/example/example-0'
    USING DELTA;
    

    再通过Spark写入表:

    df.write.format("delta").mode("overwrite").saveAsTable("example_table")
    
  4. 移除手动配置的Spark认证参数
    使用Unity Catalog时,无需手动设置fs.azure.*系列配置,Unity Catalog会自动通过Storage Credential关联的Managed Identity完成认证。手动配置的OAuth参数会覆盖默认逻辑,导致权限验证失败,直接删除所有spark.conf.set的Azure认证代码即可。

  5. 等待权限同步生效
    Azure RBAC和Unity Catalog权限可能需要5-10分钟完成同步,配置后等待一段时间再测试。

内容的提问来源于stack exchange,提问作者Joost Dübken

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.29 05:25:23