You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用系统托管标识后,Azure Databricks连接Azure Storage account时DefaultAzureCredential认证失败求助

启用系统托管标识后,Azure Databricks连接Azure Storage account时DefaultAzureCredential认证失败求助

看起来你在给Azure Databricks启用系统托管身份后,连接存储账户碰到了认证卡壳的问题,我来帮你梳理几个关键排查方向:

首先先把你遇到的错误信息贴出来方便参考:

DefaultAzureCredential failed to retrieve a token from the included credentials.
Attempted credentials:
EnvironmentCredential: EnvironmentCredential authentication unavailable. Environment
variables are not fully configured.
Visit https://aka.ms/azsdk/python/identity/environmentcredential/troubleshoot to
troubleshoot this issue.
ManagedIdentityCredential: ManagedIdentityCredential authentication unavailable, no response from the IMDS endpoint.
SharedTokenCacheCredential: SharedTokenCacheCredential authentication unavailable. No accounts were found in the cache.
AzureCliCredential: Azure CLI not found on path
AzurePowerShellCredential: PowerShell is not installed
AzureDeveloperCliCredential: Azure Developer CLI coul...

从错误里最关键的点是ManagedIdentityCredential无法连接IMDS端点,这是系统托管身份获取令牌的核心通道,咱们从这里入手:

  • 先确认托管身份的权限和配置是否到位

    1. 打开Azure门户,找到你的Databricks工作区,进入「标识」选项卡,确认系统托管身份的状态是「开启」
    2. 转到目标存储账户的「访问控制(IAM)」,检查是否给这个Databricks系统托管身份分配了合适的角色,比如Storage Blob Data Contributor(如果是读写需求),别只加普通的Reader角色,那会没权限操作存储内容
  • 排查IMDS端点的网络访问问题
    如果你的Databricks集群部署在自定义虚拟网络里:

    1. 检查虚拟网络的NSG(网络安全组)规则,确保允许集群节点向169.254.169.254这个地址发起HTTPS(443端口)的出站请求,IMDS端点就在这个地址上
    2. 查看虚拟网络的路由表,确认没有把IMDS的流量路由到NAT网关或者其他自定义路由,IMDS的流量需要直接走Azure默认路由,不能被拦截
  • 简化认证方式测试,缩小问题范围
    你可以暂时跳过DefaultAzureCredential,直接用ManagedIdentityCredential来测试连接,代码示例如下:

    from azure.identity import ManagedIdentityCredential
    from azure.storage.blob import BlobServiceClient
    
    # 替换成你的存储账户URL
    account_url = "https://your-storage-account-name.blob.core.windows.net"
    credential = ManagedIdentityCredential()
    blob_client = BlobServiceClient(account_url=account_url, credential=credential)
    
    # 尝试列出容器来验证
    containers = blob_client.list_containers()
    for container in containers:
        print(container.name)
    

    如果这样还是报IMDS相关的错,那基本可以确定是网络或者托管身份配置的问题;如果成功了,那可能是DefaultAzureCredential的优先级配置有干扰

  • 检查Databricks Runtime版本
    确保你的集群用的是较新的Databricks Runtime(比如11.0及以上),旧版本对系统托管身份的支持可能不完善,升级到新版本有时候能解决这类兼容性问题

最后还有个小提醒:如果是刚配置的托管身份和权限,可能需要等个3-5分钟让Azure的权限同步生效,别刚设置完就立刻测试哦~

备注:内容来源于stack exchange,提问作者user6249539

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 09:25:28