You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Databricks集群挂载Azure文件共享时遇权限拒绝错误求助

排查Databricks集群挂载Azure文件共享时的Permission Denied错误

问题详情

在Databricks集群上执行Azure文件共享挂载操作时,触发权限拒绝错误:

mount: /mnt/test: permission denied.

添加--verbose参数未获取到额外诊断信息,执行的挂载命令为:

sudo mount -t cifs //<storage_account>.file.core.windows.net/test /mnt/test -o credentials=/etc/smbcredentials/<storage_account>.cred,dir_mode=0777,file_mode=0777,serverino,nosharesock,actimeo=30

完整执行脚本如下:

sudo mkdir /mnt/test
if [ ! -d "/etc/smbcredentials" ]; then
sudo mkdir /etc/smbcredentials
fi
if [ ! -f "/etc/smbcredentials/<storage_account>.cred" ]; then
    sudo bash -c 'echo "username=<storage_account>" >> /etc/smbcredentials/<storage_account>.cred'
    sudo bash -c 'echo "password=<storage_account_key>" >> /etc/smbcredentials/<storage_account>.cred'
fi
sudo chmod 600 /etc/smbcredentials/<storage_account>.cred

sudo bash -c 'echo "//<storage_account>.file.core.windows.net/test /mnt/test cifs nofail,credentials=/etc/smbcredentials/<storage_account>.cred,dir_mode=0777,file_mode=0777,serverino,nosharesock,actimeo=30" >> /etc/fstab'
sudo mount -t cifs //<storage_account>.file.core.windows.net/test /mnt/test -o credentials=/etc/smbcredentials/<storage_account>.cred,dir_mode=0777,file_mode=0777,serverino,nosharesock,actimeo=30

排查步骤

1. 确认Databricks集群的特权模式状态

Databricks非特权集群默认限制内核级操作(如mount),需确认集群是否启用特权模式:

  • 进入集群配置页面,查看"高级选项"->"容器"->"特权模式"是否开启
  • 若未开启,切换为特权模式后重启集群再尝试挂载

2. 修正SMB凭据文件的格式错误

当前脚本写入凭据文件时,命令包含双引号,导致文件内容带引号(如"username=mystorage"),这会使CIFS挂载无法正确解析凭据:

  • 先删除错误的凭据文件:
    sudo rm /etc/smbcredentials/<storage_account>.cred
    
  • 修改脚本中的凭据写入命令,去掉双引号:
    sudo bash -c 'echo username=<storage_account> >> /etc/smbcredentials/<storage_account>.cred'
    sudo bash -c 'echo password=<storage_account_key> >> /etc/smbcredentials/<storage_account>.cred'
    
  • 验证凭据文件内容:
    cat /etc/smbcredentials/<storage_account>.cred
    
    确保输出为无引号的键值对:
    username=<storage_account>
    password=<storage_account_key>
    

3. 测试SMB连接可用性

在集群节点上直接测试与Azure文件共享的SMB连接,排除网络或凭据问题:

smbclient -L //<storage_account>.file.core.windows.net -U <storage_account>%<storage_account_key>

如果能列出共享目录,说明网络和凭据正常;若报错,需检查:

  • 存储账户访问密钥是否正确
  • 存储账户防火墙是否允许集群节点的IP/VNet访问

4. 检查CIFS依赖组件

确认集群节点已安装必要的CIFS工具:

  • RHEL/CentOS系:
    sudo rpm -q cifs-utils || sudo yum install -y cifs-utils
    
  • Ubuntu系:
    sudo dpkg -l cifs-utils || sudo apt-get install -y cifs-utils
    
  • 确认CIFS内核模块已加载:
    lsmod | grep cifs || sudo modprobe cifs
    

5. 验证挂载目录权限

检查挂载目录的所有者和权限:

ls -ld /mnt/test

确保目录由root拥有,权限至少为drwxr-xr-x(sudo mount操作不受普通权限限制,但异常权限可能干扰)


内容的提问来源于stack exchange,提问作者xuxu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 05:05:19