<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why External Secrets in Unity Catalog Matter in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/why-external-secrets-in-unity-catalog-matter/m-p/168407#M12105</link>
    <description>&lt;P&gt;Modern data and AI workloads rarely operate in isolation. Pipelines connect to operational databases. Notebooks call third-party APIs. Agents invoke external tools. Applications use tokens, passwords, certificates, and API keys to reach the systems around them.&lt;/P&gt;&lt;P&gt;Every one of those integrations creates the same uncomfortable question: &lt;STRONG&gt;where should the credential live?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Many organizations already have a cloud-standard answer, such as AWS Secrets Manager or Azure Key Vault. But when a workload moves into a data platform, teams often copy the same secret into a platform-specific store. That creates two sources of truth, two permission models, two audit trails, and a rotation process that can fail in several places.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/en/security/secrets/external-secrets" target="_self"&gt;External secrets in Unity Catalog&lt;/A&gt; are designed to remove that duplication. The secret value remains in the external cloud secret manager, while Unity Catalog presents it as a governed securable object that Databricks workloads can discover and reference.&lt;/P&gt;&lt;P&gt;That sounds like a small integration feature. It is actually an important step toward treating credentials as governed infrastructure rather than application configuration.&lt;/P&gt;&lt;P&gt;Without an external-secret integration, a common operating model looks like this:&lt;/P&gt;&lt;P&gt;1. A security or platform team creates a credential in the enterprise secret manager.&lt;BR /&gt;2. A data team copies that credential into Databricks.&lt;BR /&gt;3. Permissions are configured again in a second system.&lt;BR /&gt;4. Rotation requires both copies to be updated in the correct order.&lt;BR /&gt;5. Auditors must reconcile cloud logs, workspace configuration, code usage, and a separate access model.&lt;/P&gt;&lt;P&gt;This model works until it does not. A missed rotation can stop a production pipeline. An old copy can remain active after the source secret changes. A broad permission inherited in one platform can undermine a narrow policy in another. An incident investigation can become a manual exercise in joining events across tools.&lt;/P&gt;&lt;P&gt;The technical problem is duplication. The customer problem is &lt;STRONG&gt;operational uncertainty:&lt;/STRONG&gt;&amp;nbsp;teams cannot easily prove that the right workload used the right credential under the right policy at the right time.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What external secrets change&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;External secrets separate the secret's &lt;STRONG&gt;system of record&lt;/STRONG&gt; from its &lt;STRONG&gt;governance and consumption interface.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- The cloud secret manager remains responsible for storing and changing the value.&lt;BR /&gt;- Unity Catalog provides a three-level name, such as `catalog.schema.secret`, and governs access with privileges including `READ SECRET` and `REFERENCE SECRET`.&lt;BR /&gt;- Databricks retrieves the current value from the external manager when a workload reads it instead of storing the value in Unity Catalog.&lt;BR /&gt;- Databricks audit events retain the Databricks user identity, while cloud-side logs record the connection's service credential.&lt;/P&gt;&lt;P&gt;This gives customers a practical bridge between cloud security controls and data-platform governance. Existing secret-management investments remain in place, while data and AI teams gain a consistent Unity Catalog interface.&lt;/P&gt;</description>
    <pubDate>Sat, 12 Sep 2026 03:52:16 GMT</pubDate>
    <dc:creator>pradeep_singh</dc:creator>
    <dc:date>2026-09-12T03:52:16Z</dc:date>
    <item>
      <title>Why External Secrets in Unity Catalog Matter</title>
      <link>https://community.databricks.com/t5/get-started-discussions/why-external-secrets-in-unity-catalog-matter/m-p/168407#M12105</link>
      <description>&lt;P&gt;Modern data and AI workloads rarely operate in isolation. Pipelines connect to operational databases. Notebooks call third-party APIs. Agents invoke external tools. Applications use tokens, passwords, certificates, and API keys to reach the systems around them.&lt;/P&gt;&lt;P&gt;Every one of those integrations creates the same uncomfortable question: &lt;STRONG&gt;where should the credential live?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Many organizations already have a cloud-standard answer, such as AWS Secrets Manager or Azure Key Vault. But when a workload moves into a data platform, teams often copy the same secret into a platform-specific store. That creates two sources of truth, two permission models, two audit trails, and a rotation process that can fail in several places.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/aws/en/security/secrets/external-secrets" target="_self"&gt;External secrets in Unity Catalog&lt;/A&gt; are designed to remove that duplication. The secret value remains in the external cloud secret manager, while Unity Catalog presents it as a governed securable object that Databricks workloads can discover and reference.&lt;/P&gt;&lt;P&gt;That sounds like a small integration feature. It is actually an important step toward treating credentials as governed infrastructure rather than application configuration.&lt;/P&gt;&lt;P&gt;Without an external-secret integration, a common operating model looks like this:&lt;/P&gt;&lt;P&gt;1. A security or platform team creates a credential in the enterprise secret manager.&lt;BR /&gt;2. A data team copies that credential into Databricks.&lt;BR /&gt;3. Permissions are configured again in a second system.&lt;BR /&gt;4. Rotation requires both copies to be updated in the correct order.&lt;BR /&gt;5. Auditors must reconcile cloud logs, workspace configuration, code usage, and a separate access model.&lt;/P&gt;&lt;P&gt;This model works until it does not. A missed rotation can stop a production pipeline. An old copy can remain active after the source secret changes. A broad permission inherited in one platform can undermine a narrow policy in another. An incident investigation can become a manual exercise in joining events across tools.&lt;/P&gt;&lt;P&gt;The technical problem is duplication. The customer problem is &lt;STRONG&gt;operational uncertainty:&lt;/STRONG&gt;&amp;nbsp;teams cannot easily prove that the right workload used the right credential under the right policy at the right time.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What external secrets change&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;External secrets separate the secret's &lt;STRONG&gt;system of record&lt;/STRONG&gt; from its &lt;STRONG&gt;governance and consumption interface.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- The cloud secret manager remains responsible for storing and changing the value.&lt;BR /&gt;- Unity Catalog provides a three-level name, such as `catalog.schema.secret`, and governs access with privileges including `READ SECRET` and `REFERENCE SECRET`.&lt;BR /&gt;- Databricks retrieves the current value from the external manager when a workload reads it instead of storing the value in Unity Catalog.&lt;BR /&gt;- Databricks audit events retain the Databricks user identity, while cloud-side logs record the connection's service credential.&lt;/P&gt;&lt;P&gt;This gives customers a practical bridge between cloud security controls and data-platform governance. Existing secret-management investments remain in place, while data and AI teams gain a consistent Unity Catalog interface.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Sep 2026 03:52:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/why-external-secrets-in-unity-catalog-matter/m-p/168407#M12105</guid>
      <dc:creator>pradeep_singh</dc:creator>
      <dc:date>2026-09-12T03:52:16Z</dc:date>
    </item>
  </channel>
</rss>

