An Apache Spark-based analytics platform optimized for Azure.
Based on the additional testing, this no longer looks like a Unity Catalog permission issue, catalog binding issue, or problem with the underlying tables.
The key observation is that the same catalog operations (SHOW CATALOGS, USE CATALOG, SHOW SCHEMAS) and table queries execute successfully through a SQL Warehouse, while even a trivial SELECT 1 fails from Serverless notebook compute with:
PERMISSION_DENIED: Cert validation failed. Origin workspace
That points to a failure in the Serverless notebook compute path rather than a problem with the catalog objects themselves.
A few targeted checks that may help further isolate the issue:
Verify whether any serverless network connectivity configuration (NCC) or serverless egress policy is associated with the workspace. Certificate validation failures can occur when Serverless compute cannot successfully reach required control-plane or governance endpoints.
Compare behaviour between Serverless notebook compute and a classic/all-purpose cluster in the same workspace. If Spark SQL succeeds on classic compute but fails only on Serverless, that further narrows the issue to the Serverless execution path.
- Run a simple Spark operation from Python rather than SQL:
spark.range(1).count()
If this also hangs or fails, it strengthens the conclusion that the issue occurs when a Spark session attempts to initialise or communicate with backend services, rather than being specific to SQL parsing or Unity Catalog commands.
- Check whether the issue is reproducible across multiple users in the same workspace. If all users experience the same behaviour, that would indicate a workspace-level Serverless configuration issue rather than a user-specific permission problem.
Given that SQL Warehouse access to the metastore and tables is working correctly, I would avoid spending additional time recreating catalogs, changing table grants, or modifying Unity Catalog permissions. The evidence gathered so far points away from those areas and toward the Serverless notebook compute environment itself.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.