A team is designing a GenAI application that must call an external LLM provider from a Databricks notebook and from a Model Serving endpoint. The security team requires that the provider API key never appear in notebook source code, Git history, or the model artifact, and that the same governed credential be reused by both the notebook and the serving endpoint. Which design satisfies these requirements?
A Unity Catalog connection centralizes credential storage and access control, so the API key never appears in code or artifacts. Both notebooks and Model Serving endpoints can reference the same governed connection, giving consistent secret rotation and auditability. This directly meets the requirement that one governed credential be reused without exposing the plaintext anywhere in source or configuration.
Why this answer
Centralizing the external provider credential in a Unity Catalog connection keeps plaintext out of source code, Git history, and artifacts while letting both notebooks and Model Serving endpoints reference the same governed object. Secret scopes with manual injection, widget defaults, and cluster Spark configurations either leak the value or fail to reach the serving runtime.
Exam trap
The trap here is treating any secret scope reference as sufficient, when the requirement also demands that the same governed credential be consumable by a Model Serving endpoint, which a manually resolved secret does not satisfy.