<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Attach instance profile to service principal. in Data Engineering</title>
    <link>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12791#M7553</link>
    <description>&lt;P&gt;Hi, Could you please check if these were followed:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/administration-guide/users-groups/service-principals.html" target="test_blank"&gt;https://docs.databricks.com/administration-guide/users-groups/service-principals.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/iam/instance-profile-tutorial.html" target="test_blank"&gt;https://docs.databricks.com/aws/iam/instance-profile-tutorial.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/iam/manage-instance-profiles.html" target="test_blank"&gt;https://docs.databricks.com/aws/iam/manage-instance-profiles.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if this helps. &lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2023 22:38:25 GMT</pubDate>
    <dc:creator>Debayan</dc:creator>
    <dc:date>2023-01-11T22:38:25Z</dc:date>
    <item>
      <title>Attach instance profile to service principal.</title>
      <link>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12790#M7552</link>
      <description>&lt;P&gt;Hey Guys, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having some permission issues using service principal and instance profile and i hope you could help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a service principal and attached to it an instance profile - databricks-my-profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a s3 bucket with policy that allow read/write only to service principal databricks-my-profile. this bucket has been mount into dbfs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cluster with databricks-my-profile instance profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While im able to read &amp;amp; write into this s3 bucket from databricks environment( from notebooks, jobs) which is good since the cluster have an instance profile that fits with the s3 bucket restrictions, I can't read &amp;amp; write data from this bucket using my service principal but i can see in its roles that databricks-my-profile exists for this specific sp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to copy files into the bucket using databricks cli and with the sp token and got an error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command use to upload files:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;databricks fs ls dbfs:/mnt/my_mounted_bucket --profile my-service-principal&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;Error i get after runnnig the command:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;Error: Authorization failed. Your token may be expired or lack the valid scope&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does some one have any idea why this is failing? or how i should debug this issue? &lt;/P&gt;&lt;P&gt;I check the s3 bucket policy and the restriction are only on instance profile - so this don't happening because ip restrictions or something like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you can help me.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 16:05:09 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12790#M7552</guid>
      <dc:creator>Orianh</dc:creator>
      <dc:date>2023-01-10T16:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Attach instance profile to service principal.</title>
      <link>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12793#M7555</link>
      <description>&lt;P&gt;Hey @Kaniz Fatma​&amp;nbsp;, @Debayan Mukherjee​,  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, Databricks is not support using DBFS API with service principal &amp;amp; attached instance profile on a mounted s3 bucket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if this exists in docs (might miss it) but this info can be achieved using debug flag (--debug) on the cli command that i specified...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 09:40:55 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12793#M7555</guid>
      <dc:creator>Orianh</dc:creator>
      <dc:date>2023-01-17T09:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Attach instance profile to service principal.</title>
      <link>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12791#M7553</link>
      <description>&lt;P&gt;Hi, Could you please check if these were followed:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/administration-guide/users-groups/service-principals.html" target="test_blank"&gt;https://docs.databricks.com/administration-guide/users-groups/service-principals.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/iam/instance-profile-tutorial.html" target="test_blank"&gt;https://docs.databricks.com/aws/iam/instance-profile-tutorial.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/iam/manage-instance-profiles.html" target="test_blank"&gt;https://docs.databricks.com/aws/iam/manage-instance-profiles.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let us know if this helps. &lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 22:38:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/attach-instance-profile-to-service-principal/m-p/12791#M7553</guid>
      <dc:creator>Debayan</dc:creator>
      <dc:date>2023-01-11T22:38:25Z</dc:date>
    </item>
  </channel>
</rss>

