1. Overview
Auxia authenticates to your Unity Catalog as a service principal you create, asks Unity Catalog for short-lived credentials scoped to each table, reads that table’s underlying data files directly from your cloud storage, and ingests them on a recurring schedule — read-only. Flow:- Databricks workspace on AWS with Unity Catalog enabled
- Table data backed by Amazon S3
- Source tables are Unity Catalog managed Delta tables
- A metastore/catalog admin who can create a service principal and run
GRANTstatements
2. Create a Service Principal
In your Databricks account, create a dedicated service principal and generate an OAuth secret (client ID + secret). Share the following with your Auxia solutions engineer over a secure channel:- the service principal client ID and secret, and
- your workspace URL — e.g.
https://<your-workspace>.cloud.databricks.com(the workspace host, not the Databricks account-console URL).
The service principal needs no workspace entitlements (no admin, cluster, or SQL-warehouse access) beyond the table grants in Step 4.
3. Enable External Data Access on the Metastore
A metastore admin enables external data access on the Unity Catalog metastore (theexternal_access_enabled setting). This one-time setting is what allows credential vending.
4. Grant Read Access to the Service Principal
Run the following for each catalog, schema, and table to be ingested:EXTERNAL USE SCHEMA is the credential-vending privilege; it can only be granted by the catalog owner.
5. Enable Change Data Feed
Auxia loads new data incrementally using Delta’s Change Data Feed (CDF). Enable it on each table before the first load:CDF only records changes from the point it is enabled, so turn it on before Auxia’s initial load.
6. Confirm the Tables with Auxia
For each table you want to share, provide your Auxia solutions engineer with:- the fully-qualified name
catalog.schema.table(base tables, not views); - confirmation that the table is append-only, and its event-timestamp / partition column.
7. Security & Governance
- Read-only, scoped to the tables you explicitly grant.
- No standing credentials — each request vends short-lived credentials scoped to a single table’s storage location.
- No broad bucket access to your cloud account.
- Auditable — Unity Catalog audits each credential-issuance event; the file-level reads appear in your own cloud storage / CloudTrail logs.
- Revocable — removing a grant (or disabling the service principal) blocks all future access; an already-issued credential remains valid only until it expires (about an hour).
- The only long-lived secret is the service principal’s OAuth credential, which you can rotate at any time.
8. Recommended Practices
- Enable Change Data Feed before the first load so incremental reads are available from day one.
- Keep the service principal least-privileged — grant only the catalogs, schemas, and tables to be ingested, and no other workspace entitlements.
- Share schema and a small sample (or a few days of history) first so the connection can be validated before the full historical load.
- Share base tables, not views — Auxia reads the underlying managed Delta tables directly.