Migrating Service Principals from Non-Unity to Unity-Enabled Databricks Workspaces - Entitlements Mi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-23-2024 04:03 AM
Hello Databricks Community,
I am currently in the process of migrating Service Principals from a non-Unity workspace to a Unity-enabled workspace in Databricks. While the Service Principals themselves seem to be migrating correctly, I am facing an issue where the permissions (entitlements) associated with the Service Principals in the source workspace are not matching in the target Unity-enabled workspace.
The Service Principals in the source workspace have specific permissions such as:
- Allow cluster creation
- Databricks SQL access
- Workspace access
However, after migrating these Service Principals, the entitlements (permissions) in the target Unity-enabled workspace are not transferred correctly, resulting in a mismatch.
Code:
Here’s the code I’m using for migrating the Service Principals:
pythonCopy codedef import_service_principal(sp, target_host, target_token): headers = get_headers(target_token) url = f'{target_host}/api/2.0/preview/scim/v2/ServicePrincipals' sp_check_url = f'{url}/{sp["applicationId"]}' # Check if service principal already exists by application ID # Check if the service principal already exists in the target system if resource_exists(sp_check_url, headers): logging.warning(f"Service Principal with ID {sp['applicationId']} already exists in target system. Skipping import.") return False data = { "schemas": sp.get("schemas", []), "applicationId": sp["applicationId"], "displayName": sp.get("displayName", ""), "description": sp.get("description", "") } try: make_request_with_error_handling(url, headers, method='POST', data=data) logging.info(f"Service Principal {sp['applicationId']} imported successfully.") return True except KeyError as ke: logging.error(f"KeyError importing service principal: {sp}. Missing key: {ke}") except requests.exceptions.HTTPError as err: if err.response.status_code == 409: logging.warning(f"Service Principal with ID {sp['applicationId']} already exists in target system. Skipping import.") else: logging.error(f"HTTP error occurred importing service principal: {sp}. Error: {err}") except Exception as e: logging.error(f"Error importing service principal: {sp}. Error: {e}") return FalseIssue:
- Permissions like "Allow cluster creation", "Databricks SQL access", and "Workspace access" are not migrating properly from the source non-Unity workspace to the Unity-enabled target workspace.
- The entitlements (permissions) are not transferred as expected, causing mismatches between the source and target workspaces.
Has anyone encountered a similar issue when migrating Service Principals from a non-Unity to a Unity-enabled Databricks workspace? If so, could you provide any suggestions, solutions, or steps to ensure that the permissions and entitlements are correctly migrated as well?
Thank you in advance for your help!