Azure / Azure/azure-storage-python
additionally_allowed_tenants config not found in Spark session for Multi-tenant app
- Dominant language
- Python
- Stars
- 343
- Forks
- 243
- PR merge metrics
- No merged PRs in 30d
Description
We have a multi-tenant Azure app (Tenant A, Tenant B). We are using Tenant A's Service Principle credentials to access the ADLS files on Tenant B. We are using pySpark for this job.
Using the above multi-tenant app credential, we are getting 401 unauthorized error in spark session.
But if we are using Python library (azure.identity), then using the following 'additionally_allowed_tenants' options enables us to authorize the access Tenant B's ADLS containers using Tenant A's credentials.
`default_credential = DefaultAzureCredential(additionally_allowed_tenants=['*'])`
We want to achieve the same with pySpark, but we can't see any option or configuration available to do it through Spark session.
We are using:
- Apache Spark 3.5.0
- Databricks Notebook (Runtime Version 14.3 LTS)
- [Azure Service Principle](https://docs.databricks.com/en/connect/storage/azure-storage.html#language-Azure%C2%A0service%C2%A0principal)
Please guide us to resolve this issue.
Contributor guide
Research direction
Start with the Databricks and Apache Spark service-principal configuration described in the issue, then compare it with Python azure.identity's additionally_allowed_tenants behavior. Determine whether Spark exposes an equivalent tenant-allowlist setting for cross-tenant ADLS access; done means a documented or implemented configuration that avoids the reported 401 response.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, python, spark
- Domain
- cloud, data-engineering
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100