Establishing Trust relationship for Databricks on AWS

gdschld
New Contributor

Hello.

Our databricks is on Azure. We are trying to connect with AWS S3 as an external source from Unity Catalog.

We have followed all steps given here, is there anything additional required?
https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/storage-credentials
  1. Create IAM Role in AWS account, policy, allowing access on s3 buckets.
  2. Establish Trust connection for the IAM role
  3. Create storage credential in Databricks, and collect the external Id
  4. Modify 1 with stsAssume policy with externalid as databricks Identifier created in step 3.

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Action": [
            "s3:GetObject",
            "s3:PutObject",
            "s3:DeleteObject",
            "s3:ListBucket",
            "s3:GetBucketLocation",
            "s3:ListBucketMultipartUploads",
            "s3:ListMultipartUploadParts",
            "s3:AbortMultipartUpload"
          ],
          "Resource": ["arn:aws:s3:::<BUCKET>/*", "arn:aws:s3:::<BUCKET>"],
          "Effect": "Allow"
        },
        {
          "Action": ["sts:AssumeRole"],
          "Resource": ["arn:aws:iam::<AWS-ACCOUNT-ID>:role/<AWS-IAM-ROLE-NAME>"],
          "Effect": "Allow"
        }
      ]
    }


    Trust Policy on IAM Role, validates perfect.

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Principal": {
            "AWS": [
              "arn:aws:iam::414351767826:role/unity-catalog-prod-UCMasterRole-14S5ZJVKOTYTL",
              "arn:aws:iam::<YOUR-AWS-ACCOUNT-ID>:role/<THIS-ROLE-NAME>"
            ]
          },
          "Action": "sts:AssumeRole",
          "Condition": {
            "StringEquals": {
              "sts:ExternalId": "<STORAGE-CREDENTIAL-EXTERNAL-ID>"
            }
          }
        }
      ]
    }

    However, databricks storage credential still gives error below on trying to validate this connection.

    On databricks : Catalog : Credentials : Databricks Storage Credential --> Validate Configuration

    Error

    Failed - Assume Role
    Skipped - Self Assume Role
    Skipped - ExternalID Condition
    
    Missing Permissions
    Failed to get credentials: the AWS IAM role in the credential is not configured correctly. Please contact your account admin to update the configuration

    What could be the reason for the validation to be erroring out? Thanks in advance.

    Is there any additional step like setting up credentials?