cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
Community Platform Discussions
Connect with fellow community members to discuss general topics related to the Databricks platform, industry trends, and best practices. Share experiences, ask questions, and foster collaboration within the community.
cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

Get exceptionTraceId details

dvmentalmadess
Valued Contributor

I'm getting the following error:

 

 

module.consumer_stage_catalog.databricks_external_location.catalog: Creating...
ā•·
ā”‚ Error: cannot create external location: AWS IAM role does not have READ permissions on url s3://[bucket name]/catalogs. Please contact your account admin to update the storage credential. PERMISSION_DENIED: Access denied. Cause: 403 Forbidden error from cloud storage provider. exceptionTraceId=[UUID]
ā”‚ 
ā”‚   with module.consumer_stage_catalog.databricks_external_location.catalog,
ā”‚   on .terraform/modules/consumer_stage_catalog/terraform/databricks_catalog.tf line 49, in resource "databricks_external_location" "catalog":
ā”‚   49: resource "databricks_external_location" "catalog" {

 

 

Where can I find the logs to look up the details for exceptionTraceId? I only see documentation to setup audit logs and billing logs and the docs don't mention exceptions - I don't see schema or examples that include exceptionTraceId. This is the result of a Databricks API call and there's no running cluster involved so I can't check the cluster logs.

1 REPLY 1

@Retired_mod 

Thanks for your reply. I had hoped there was a way to see the original exeception to retrieve the S3 request id values so I could open an AWS support ticket, if the IAM identity and denied permission weren't already listed in the original exception. After reading this thread which mentioned looking up exceptionTraceId in Databricks logs I had hoped that's where I would find the information I needed.

I was asking after I had already investigated both the IAM resource and identity policies, compared them to existing policies that were functioning as well as to the DBR documentation, and also used the AWS IAM Policy Simulator.

As it so happens, I'm pretty sure I did find the problem after posting this. I'm just waiting for a response to confirm. 

That said, I'd be interested in the relevant thread you mentioned but the link provided just points to the same resource url as the previous link you provided. If you'd be willing to update the post or share the link in a reply I'd love to read more.

If the API team ends up reading this, I'd like to provide the following feedback. Providing the means to access the AWS request and extended request id values would be useful for resolving issues. Especially one like this where the likely cause is a context key that a policy condition relies on. Having the ids required to open up an AWS support case would have allowed me to work with AWS support who are likely to have the context values sent in the request which would have reduced the time to resolution significantly. The only reason I even have an idea why this isn't working is because I happened to notice the External ID value displayed in the list of credentials and that it was different than every other instance.

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you wonā€™t want to miss the chance to attend and share knowledge.

If there isnā€™t a group near you, start one and help create a community that brings people together.

Request a New Group