To manage credentials Azure Databricks offers Secret Management. Secret Management allows users to share credentials in a secure mechanism. Currently Azure Databricks offers two types of Secret Scopes:
- Azure Key Vault-backed: To reference secrets stored in an Azure Key Vault, you can create a secret scope backed by Azure Key Vault. Azure Key Vault-backed secrets are only supported for Azure Databricks Premium Plan.
- Databricks-backed: A Databricks-backed scope is stored in (backed by) an Azure Databricks database. You create a Databricks-backed secret scope using the Databricks CLI (version 0.7.1 and above).
Creating Azure Key Vault
Open a Web Browser. I am using Chrome.
Enter the URL https://portal.azure.com and hit enter.
data:image/s3,"s3://crabby-images/85fdf/85fdf20697571e90faf9ba83f7fb34613ebc8321" alt="Web Browser"
Sign in into your Azure Account.
data:image/s3,"s3://crabby-images/a3729/a372929be3ab01a5c8447cf3a69f3a9109826312" alt="Azure Portal - Login Information"
After successfully logging to Azure Portal, you should see the following screen.
data:image/s3,"s3://crabby-images/26579/26579b0b8ee3a39db33c75ae5a2e7ce32ad0695a" alt="Azure Portal - Home Page"
Click on "All Services" on the top left corner.
data:image/s3,"s3://crabby-images/e5f27/e5f27a587756e37fcdc72d967f20038a62e4b735" alt="Azure Portal - All Services"
Search for "Azure Key Vault" in the "All Services" search text box.
data:image/s3,"s3://crabby-images/25c7d/25c7d097d2d681d00236354e1bd9008b798e1749" alt="Azure Portal - Search for Azure Key Vault service"
Click on "Key vaults". It will open the blade for "Key vaults".
data:image/s3,"s3://crabby-images/bf86f/bf86fc078ff1fabe453ce6871564b64c41f9d6f2" alt="Azure Portal - Azure Key Vault Service View"
Click on "Add". It will open a new blade for creating a key vault "Create key vault".
data:image/s3,"s3://crabby-images/fea12/fea124478ddbe925d6faacfb34f8433fc01010d5" alt="Azure Portal - Create Azure Key Vault"
Enter all the information and click the "Create" button. Once the resource is created, refresh the screen and it will show the new "key vault" which we created.
data:image/s3,"s3://crabby-images/00320/003201115e37ca1c64ac863d18bbe580b1bfeaf9" alt="Azure Portal - Azure Key Vault Service View with the newly created Azure Key Vault service"
Click on the "key vault" name.
data:image/s3,"s3://crabby-images/1c640/1c640864d160ae959c3f3b04290e4571a5a334b6" alt="Azure Portal - Azure Key Vault Overview Page"
Scroll down and click on the "Properties".
data:image/s3,"s3://crabby-images/d0992/d09926ffdc54df5ae6651875fc3aa58d63b38bbe" alt="Azure Portal - Azure Key Vault Menu"
Save the following information for the "key vault" created. We would be using these properties when we connect to the "key Vault" from "databricks"
- DNS Name
- Resource ID
data:image/s3,"s3://crabby-images/674d4/674d46bb045d82e3f5df2374e81748948e2f7a3d" alt="Azure Portal - Azure Key Vault Properties (DNS Name and Resource ID)"
Creating Secret in Azure Key Vault
Click on "Secrets" on the left-hand side.
data:image/s3,"s3://crabby-images/6ba07/6ba076fa87040e26b63844e88088e01dbdad893c" alt="Azure Portal - Azure Key Vault Menu"
Click on "Generate/Import". We will be creating a secret for the "access key" for the "Azure Blob Storage".
data:image/s3,"s3://crabby-images/4ad07/4ad0769a30d49816431dba29dfaa9de06e2f0942" alt="Azure Portal - Azure Key Vault Generate/Import View"
Enter the required information for creating the "secret".
data:image/s3,"s3://crabby-images/45e4f/45e4f15b09b816300b21791a74c34f6a6e98544b" alt="Azure Portal - Azure Key Vault Secret creation view"
After entering all the information click on the "Create" button.
data:image/s3,"s3://crabby-images/9ffd7/9ffd7962dac3b1fab035be351df4952f3e6529ce" alt="Azure Portal - Azure Key Vault Generate/Import View"
Note down the "Name" of the secret.
Creating Azure Key Vault Secret Scope in Databricks
Open a Web Browser. I am using Chrome.
Enter the URL https://portal.azure.com and hit enter.
data:image/s3,"s3://crabby-images/80c57/80c578b1029d3647e935cfc4fb3f88b00e7e15d5" alt="Web Browser"
Sign in into your Azure Account.
data:image/s3,"s3://crabby-images/a3729/a372929be3ab01a5c8447cf3a69f3a9109826312" alt="Azure Portal - Login Information"
Open the Azure Databricks workspace created as part of the Azure Databricks Workspace mentioned in the Requirements section at the top of the article.
data:image/s3,"s3://crabby-images/7b7c7/7b7c7ef98e5007763c1251179072e9b625a53026" alt="Azure Databricks - Workspace
"
Click on Launch Workspace to open Azure Databricks.
data:image/s3,"s3://crabby-images/212a8/212a80d52f5cb2c6f828c60ca727a93d71c74253" alt="Azure Databricks - Home Page"
Copy the "URL" from the browser window.
data:image/s3,"s3://crabby-images/aaa05/aaa05e5cbfe0565b31215dae452bccde20cdb925" alt="Azure Databricks - Home Page"
Build the "URL" for creating the secret scope. https://<Databricks_url>#secrets/createScope.
data:image/s3,"s3://crabby-images/4f52f/4f52fd0ec7fe171420126e6b76862a573845e23e" alt="Azure Databricks - Creating the Azure Key Vault backed secret scope."
Enter all the required information:
- Scope Name.
- DNS Name (this is the "DNS name" which we saved when we created the "Azure Key Vault").
- Resource ID (this is the "Resource ID" which we saved when we created the "Azure Key Vault").
data:image/s3,"s3://crabby-images/216bf/216bf92c8711d775cd8c67828f7ae2741d756c63" alt="Azure Databricks - Creating the Azure Key Vault backed secret scope."
Click the "Create" button.
"Databricks" is now connected with "Azure Key Vault".
Using Azure Key Vault Secret Scope and Secret in Azure Databricks Notebook
Open a Web Browser. I am using Chrome.
Enter the URL https://portal.azure.com and hit enter.
data:image/s3,"s3://crabby-images/85fdf/85fdf20697571e90faf9ba83f7fb34613ebc8321" alt="Web Browser"
Sign in into your Azure Account.
data:image/s3,"s3://crabby-images/a3729/a372929be3ab01a5c8447cf3a69f3a9109826312" alt="Azure Portal - Login Information"
Open the Azure Databricks workspace created as part of the "Azure Databricks Workspace" mentioned in the Requirements section at the top of the article.
data:image/s3,"s3://crabby-images/46f48/46f481f8849d1e580a2c28a9defd90d201bf8c87" alt="Azure Databricks - Workspace"
Click on "Launch Workspace" to open the "Azure Databricks".
data:image/s3,"s3://crabby-images/91bfd/91bfda9686f1e7acfcfcaf803ad6d6f4ad312710" alt="Azure Databricks - Home page"
In the left pane, click Workspace. From the Workspace drop-down, click Create, and then click Notebook.
In the Create Notebook dialog box, enter a name, select Python as the language.
data:image/s3,"s3://crabby-images/37e72/37e724ab9b2a5558dd486f54d0c9e97a5a61bd1f" alt="Azure Databricks - Create a Python Notebook"
Enter the following code in the Notebook
dbutils.secrets.get(scope = "azurekeyvault_secret_scope", key = "BlobStorageAccessKey") #azurekeyvault_secret_scope --> Azure Key Vault based scope which we created in Databricks #BlobStorageAccessKey --> Secret name which we created in Azure Key Vault
data:image/s3,"s3://crabby-images/2d7af/2d7af657f690c4bb2ec735750b077b227f1aef59" alt="command line"
When you run the above command, it should show [REDACTED] which confirms that the secret was used from the Azure Key Vault secrets.
data:image/s3,"s3://crabby-images/650df/650df6e4813da228b3b355d78b1e93544db4f5f7" alt="command line"
In the same notebook we are going to add another command section and use Scala as the language.
%scala val blob_storage_account_access_key = dbutils.secrets.get(scope = "azurekeyvault_secret_scope", key = "BlobStorageAccessKey") //azurekeyvault_secret_scope --> Azure Key Vault based scope which we created in Databricks //BlobStorageAccessKey --> Secret name which we created in Azure Key Vault
data:image/s3,"s3://crabby-images/396bd/396bd6439fe3615e764b26b9ce5fdfce4b1a27c1" alt="command line"
When you run the above command, it should show [REDACTED] which confirms that the secret was used from the Azure Key Vault secrets.
data:image/s3,"s3://crabby-images/be028/be028935f42a0b1b803508e63904586e827d59b0" alt="command line"
References
- https://docs.microsoft.com/en-us/azure/azure-databricks/what-is-azure-databricks
- https://azure.microsoft.com/en-us/pricing/details/key-vault/
- https://docs.microsoft.com/en-us/azure/azure-databricks/what-is-azure-databricks
- https://docs.azuredatabricks.net/user-guide/secrets/index.html#secrets-user-guide
- https://docs.azuredatabricks.net/user-guide/secrets/secret-scopes.html
- https://docs.azuredatabricks.net/user-guide/secrets/secret-scopes.html#create-an-azure-key-vault-backed-secret-scope
No comments:
Post a Comment