Install python packages from Azure DevOps feed with service principal authentication

Marco37
Contributor III

At the moment I install python packages from our Azure DevOps feed with a PAT token as authentication mechanism. This works well, but I want to use a service principal instead of the PAT token.

  • I have created an Azure service principal and assigned it the "Feed Reader" permission on the Azure DevOps feed.
  • I have added it's secret to an Azure keyvault and databricks has permission to read this secret
  • In databricks I have created a secret scope pointing to this keyvault
  • Within my cluster policy I have defined these environment variables:
    AZ_DEVOPS_PROJECT_NAME=<project>
    AZ_DEVOPS_TOKEN={{secrets/<keyvault>/<secret name>}}
    AZ_DEVOPS_ORG_NAME=<organization name>
    AZ_DEVOPS_FEED_NAME=<feed name>
    and it points to an init script that contains this script:
    pip config set global.index-url https://${AZ_DEVOPS_FEED_NAME}:${AZ_DEVOPS_TOKEN}@pkgs.dev.azure.com/${AZ_DEVOPS_ORG_NAME}/${AZ_DEVOPS_PROJECT_NAME}/_packaging/${AZ_DEVOPS_FEED_NAME}/pypi/simple/

The cluster is able to read the secret from the keyvault

Marco37_0-1753975679472.png

The index URL is set to the correct feed

Marco37_1-1753975813527.png

But I'm not able to install a package from the Azure DevOps feed

Marco37_2-1753975934347.png

For the PAT token setup I'm using exactly the same configuration and that works fine.

Is what I'm trying to do not possible, or am I missing something?

Regards,

Marco