You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用存储账户密钥访问Azure Data Lake Storage Gen2时遇403权限错误

使用存储账户密钥访问Azure Data Lake Storage Gen2时出现403权限错误的排查与解决

问题场景

按照Databricks文档配置Spark参数,仅通过存储账户密钥访问Azure Data Lake Storage Gen2的目录路径:

spark.conf.set(
    "fs.azure.account.key.<storage-account>.dfs.core.windows.net",
    dbutils.secrets.get(scope="<scope>", key="<storage-account-access-key>"))

但执行目录列表操作时返回403权限错误:

ExecutionError: An error occurred while calling z:com.databricks.backend.daemon.dbutils.FSUtils.ls.
: Operation failed: "This request is not authorized to perform this operation using this permission.", 403, GET, https://<storage-account>.dfs.core.windows.net/<my-container>?upn=false&resource=filesystem&maxResults=5000&timeout=90&recursive=false, AuthorizationPermissionMismatch, "This request is not authorized to perform this operation using this permission. RequestId:ef2753bb-501f-00bf-3c6c-26d7f4000000 Time:2023-01-12T09:56:54.1924327Z"
    at shaded.databricks.azurebfs.org.apache.hadoop.fs.azurebfs.services.AbfsRestOperation.execute(AbfsRestOperation.java:248)

排查与解决步骤

1. 确认存储账户密钥有效性

  • 检查是否使用了Azure门户中存储账户>安全性+网络>访问密钥下的完整密钥字符串,避免复制时遗漏或多带空格。
  • 尝试轮换存储账户密钥后重新配置,排除密钥过期或无效的可能。

2. 验证ADLS Gen2的ACL权限

存储账户密钥本身拥有账户级完全权限,但ADLS Gen2的分层命名空间会受POSIX-style ACL限制:

  • 检查目标容器的ACL:确保存储账户身份($<storage-account-name>)被授予read+execute权限(目录列表需要execute权限遍历,read权限查看内容)。
  • 若目录设置了自定义ACL,需确认$<storage-account-name>主体在对应层级的ACL中拥有足够权限。

3. 检查存储账户网络配置

  • 若存储账户启用了防火墙/虚拟网络限制,需确认Databricks集群IP在允许列表中,或开启了“允许受信任的Microsoft服务访问此存储账户”选项。
  • VNet注入的Databricks工作区需确保与存储账户的VNet有对等互联或服务端点连通。

4. 核对Spark配置与访问路径

  • 确认spark.conf.set中的存储账户名称拼写正确,格式为fs.azure.account.key.<storage-account-name>.dfs.core.windows.net。
  • 执行目录列表时使用正确的ADLS Gen2路径格式:abfss://<container-name>@<storage-account-name>.dfs.core.windows.net/<directory-path>,避免使用Blob存储的wasbs://协议。

5. 验证密钥读取正确性

可临时打印密钥的前几位(注意不泄露完整密钥),确认dbutils.secrets.get能正常读取到密钥内容:

print(dbutils.secrets.get(scope="<scope>", key="<storage-account-access-key>")[:5])

核心原因说明

虽然存储账户密钥本身是账户级的最高权限凭证,但ADLS Gen2的分层命名空间引入的ACL规则会优先于账户级权限。如果容器或目录的ACL未授予存储账户身份($<storage-account-name>)足够的操作权限,即使密钥正确也会触发403错误。

内容的提问来源于stack exchange,提问作者Salvatore Nedia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 20:05:35