MadhuB
Valued Contributor

SP Access to the Databricks workspace - 

The service principal, underlying the Azure DevOps service connection, should be granted the required permissions to the databricks workspace and underlying catalog objects. Create a databricks workflow and make the principal as the owner with execution rights.

Optional Step- You can test this approach with the below sample code to be executed through Azure CLI task from a release pipeline. The SP deploys the code/notebooks through AAD authentication from the build location.

python.exe -m pip install --upgrade pip databricks-cli
$token=$(az account get-access-token --resource 2ff814a6-3304-4ab8-85cb-cd0e6f879c1d --query "accessToken" --output tsv)
$Env:DATABRICKS_AAD_TOKEN = $token
databricks configure --aad-token --host $(DatabricksUCDomain)
databricks --debug workspace import_dir $(System.DefaultWorkingDirectory)/ArtifactsDrop/ ///Workspace/ProjectFolder/ --overwrite

DevOps Service Connection screen to identify the Principal

MadhuB_2-1736978008308.png

 

Workflow Execution -
The SP should be granted Service principal: Manager and Service principal: User roles in the databricks admin console for the successful execution of the Job. Further make the SP as the Owner of the workflow. Refer to the below screens.

Screens to Grant SP access in the admin account console - 

MadhuB_1-1736977857890.png

 

MadhuB_0-1736977808361.png