Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-31-2025 08:39 AM
At the moment I install python packages from our Azure DevOps feed with a PAT token as authentication mechanism. This works well, but I want to use a service principal instead of the PAT token.
- I have created an Azure service principal and assigned it the "Feed Reader" permission on the Azure DevOps feed.
- I have added it's secret to an Azure keyvault and databricks has permission to read this secret
- In databricks I have created a secret scope pointing to this keyvault
- Within my cluster policy I have defined these environment variables:
AZ_DEVOPS_PROJECT_NAME=<project>
AZ_DEVOPS_TOKEN={{secrets/<keyvault>/<secret name>}}
AZ_DEVOPS_ORG_NAME=<organization name>
AZ_DEVOPS_FEED_NAME=<feed name>
and it points to an init script that contains this script:
pip config set global.index-url https://${AZ_DEVOPS_FEED_NAME}:${AZ_DEVOPS_TOKEN}@pkgs.dev.azure.com/${AZ_DEVOPS_ORG_NAME}/${AZ_DEVOPS_PROJECT_NAME}/_packaging/${AZ_DEVOPS_FEED_NAME}/pypi/simple/
The cluster is able to read the secret from the keyvault
The index URL is set to the correct feed
But I'm not able to install a package from the Azure DevOps feed
For the PAT token setup I'm using exactly the same configuration and that works fine.
Is what I'm trying to do not possible, or am I missing something?
Regards,
Marco
Labels:
- Labels:
-
Partner