Azure / Azure/azure-storage-python

additionally_allowed_tenants config not found in Spark session for Multi-tenant app

Open
#718 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
343
Forks
243
PR merge metrics
No merged PRs in 30d

Description

We have a multi-tenant Azure app (Tenant A, Tenant B). We are using Tenant A's Service Principle credentials to access the ADLS files on Tenant B. We are using pySpark for this job.

Using the above multi-tenant app credential, we are getting 401 unauthorized error in spark session.

But if we are using Python library (azure.identity), then using the following 'additionally_allowed_tenants' options enables us to authorize the access Tenant B's ADLS containers using Tenant A's credentials.

`default_credential = DefaultAzureCredential(additionally_allowed_tenants=['*'])`

We want to achieve the same with pySpark, but we can't see any option or configuration available to do it through Spark session.

We are using:
- Apache Spark 3.5.0
- Databricks Notebook (Runtime Version 14.3 LTS)
- [Azure Service Principle](https://docs.databricks.com/en/connect/storage/azure-storage.html#language-Azure%C2%A0service%C2%A0principal)

Please guide us to resolve this issue.

Contributor guide

Open the contributing guide

Research direction

Start with the Databricks and Apache Spark service-principal configuration described in the issue, then compare it with Python azure.identity's additionally_allowed_tenants behavior. Determine whether Spark exposes an equivalent tenant-allowlist setting for cross-tenant ADLS access; done means a documented or implemented configuration that avoids the reported 401 response.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, python, spark
Domain
cloud, data-engineering
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.