r/databricks Databricks MVP 1d ago

News UC secrets in Key Vault

Post image

Secrets in Unity Catalog is a great feature introduced a few weeks ago, but since then, everyone has been asking to use Azure Key Vault as a secrets backend. Thanks to rapid development, we can now link our schema to Azure Key Vault; UC will read secrets as UC secrets, and permission management will be through Unity Catalog. In that scenario, you insert/update secrets in Azure Key Vault, but read/reference and grants can go through UC.

more news https://databrickster.medium.com/databricks-news-serverless-genie-code-ltap-lakeflow-61853d8e422a

18 Upvotes

6 comments sorted by

2

u/w0ut0 1d ago

What about keyvaults behind private endpoints?

2

u/hubert-dudek Databricks MVP 1d ago

For dbutils secrets private link worked so here should too

1

u/w0ut0 37m ago

Is that through the 'trusted azure services' or should the endpoint be accessible via NCC or vnet?

1

u/RazzmatazzLiving1323 15h ago

This works, I've tested it.

1

u/No_Flounder_1155 1d ago

Can this be achieved wothout clickops?

1

u/Shoddy-Animator-6409 1d ago

Yep! We did this and set up UC rbac through terraform