Establishing Trust relationship for Databricks on AWS
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-22-2025 09:15 AM
Hello.
Our databricks is on Azure. We are trying to connect with AWS S3 as an external source from Unity Catalog.
We have followed all steps given here, is there anything additional required?
https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/storage-credentials
https://docs.databricks.com/aws/en/connect/unity-catalog/cloud-storage/storage-credentials
- Create IAM Role in AWS account, policy, allowing access on s3 buckets.
- Establish Trust connection for the IAM role
- Create storage credential in Databricks, and collect the external Id
- Modify 1 with stsAssume policy with externalid as databricks Identifier created in step 3.
{ "Version": "2012-10-17", "Statement": [ { "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject", "s3:ListBucket", "s3:GetBucketLocation", "s3:ListBucketMultipartUploads", "s3:ListMultipartUploadParts", "s3:AbortMultipartUpload" ], "Resource": ["arn:aws:s3:::<BUCKET>/*", "arn:aws:s3:::<BUCKET>"], "Effect": "Allow" }, { "Action": ["sts:AssumeRole"], "Resource": ["arn:aws:iam::<AWS-ACCOUNT-ID>:role/<AWS-IAM-ROLE-NAME>"], "Effect": "Allow" } ] }Trust Policy on IAM Role, validates perfect.
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": [ "arn:aws:iam::414351767826:role/unity-catalog-prod-UCMasterRole-14S5ZJVKOTYTL", "arn:aws:iam::<YOUR-AWS-ACCOUNT-ID>:role/<THIS-ROLE-NAME>" ] }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "sts:ExternalId": "<STORAGE-CREDENTIAL-EXTERNAL-ID>" } } } ] }However, databricks storage credential still gives error below on trying to validate this connection.
On databricks : Catalog : Credentials : Databricks Storage Credential --> Validate Configuration
Error
Failed - Assume Role Skipped - Self Assume Role Skipped - ExternalID Condition Missing Permissions Failed to get credentials: the AWS IAM role in the credential is not configured correctly. Please contact your account admin to update the configuration
What could be the reason for the validation to be erroring out? Thanks in advance.
Is there any additional step like setting up credentials?