Skip to content

Support bundle-wide group run identities for jobs and pipelines - #6676

Merged
lennartkats-db merged 11 commits into
mainfrom
lennart/run-as-group
Oct 2, 2026
Merged

lennartkats-db merged 11 commits into
mainfrom
lennart/run-as-group

Conversation

@lennartkats-db

@lennartkats-db lennartkats-db commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Support bundle- and target-level run_as.group_name for jobs and pipelines using the direct engine. Preserve explicit per-resource identities, and reject pipeline groups with an actionable error when using Terraform.

Why

The Jobs and Pipelines APIs support group run identities, but inherited bundle run_as rejected them. Terraform's pipeline mapping cannot carry the group field.

Tests

  • ./task fmt, ./task checks, ./task lint
  • go test ./bundle/config/mutator/resourcemutator ./bundle/deploy/terraform/tfdyn -count=1
  • go test ./acceptance -run 'TestAccept/bundle/run_as' -timeout=20m
  • Dogfood E2E with SDK v0.182.0: two group-run SQL jobs succeeded, three pipelines completed, three materialized views returned 42, and inherited pipelines completed again after redeployment. All test resources were removed.

@lennartkats-db
lennartkats-db marked this pull request as ready for review September 14, 2026 15:04
@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Approval status: pending

/acceptance/bundle/ - needs approval

5 files changed
Suggested: @denik
Also eligible: @janniklasrose, @andrewnester, @shreyas-goenka, @pietern, @anton-107

/bundle/ - needs approval

Files: bundle/config/mutator/resourcemutator/run_as.go, bundle/config/mutator/resourcemutator/run_as_test.go
Suggested: @denik
Also eligible: @janniklasrose, @andrewnester, @shreyas-goenka, @pietern, @anton-107

General files (require maintainer)

Files: .nextchanges/bundles/run-as-group.md
Based on git history:

  • @denik -- recent work in .nextchanges/bundles/, bundle/config/mutator/resourcemutator/, acceptance/bundle/run_as/empty_run_as_dict/

Any maintainer (@andrewnester, @anton-107, @denik, @pietern, @shreyas-goenka, @simonfaltum, @renaudhartert-db, @janniklasrose, @rugpanov, @rclarey) can approve all areas.
See OWNERS for ownership rules.

@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: cc2da85

Run: 36939426138

Env ✅​pass 🙈​skip Time
✅​ aws linux 276 20 5:37
✅​ aws windows 278 18 4:07
✅​ azure linux 275 20 5:43
✅​ azure windows 277 18 5:08
✅​ gcp linux 276 20 5:18
✅​ gcp windows 278 18 4:52
Top 6 slowest tests (at least 2 minutes):
duration env testname
5:06 azure windows TestAccept
4:50 gcp windows TestAccept
4:06 aws windows TestAccept
4:04 aws linux TestAccept
4:00 azure linux TestAccept
3:56 gcp linux TestAccept

@lennartkats-db lennartkats-db changed the title Support bundle-wide group run identities for jobs [Draft] Support bundle-wide group run identities for jobs Sep 15, 2026
@lennartkats-db lennartkats-db changed the title [Draft] Support bundle-wide group run identities for jobs Support bundle-wide group run identities for jobs Sep 18, 2026
@lennartkats-db
lennartkats-db requested review from a team as code owners September 29, 2026 08:27
@github-actions github-actions Bot added the DABs DABs related issues label Sep 29, 2026
@lennartkats-db lennartkats-db changed the title Support bundle-wide group run identities for jobs Support bundle-wide group run identities for jobs and pipelines Sep 29, 2026

@shreyas-goenka shreyas-goenka left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can we add validation that the bundle only has jobs / pipeliens or resources that do not support run_as?

Otherwise if we get support for run_as.group_name for dashboards tomorrow, adding top level support would break.

@lennartkats-db

Copy link
Copy Markdown
Contributor Author

@shreyas-goenka We already reject bundle-wide run_as with apps, model-serving endpoints, quality monitors, and dashboards with embed_credentials: true when the identity differs from the deployer. So we shouldn't need a group_name case for those.

The only new case is alerts: those support bundle-wide run_as but not group_name. So alerts now get an error when group_name is used.

return diags
}

if runAs.GroupName != "" {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This can still go out of date if another resource is introduced that supports run_as but not run_as group. Are we confident that this is unlikely to happen? Or should we have a separate allow list for this.

The case I'm trying to prevent is someone adds a resource and run as support but does not realize that run as group support was missing and that just leads us t a bad situation because changing runas down the line is a breaking change.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Makes sense, I added a separate test, PTAL

Comment thread bundle/config/mutator/resourcemutator/run_as_test.go
)

func convertPipelineResource(ctx context.Context, vin dyn.Value) (dyn.Value, error) {
if vin.Get("run_as").Get("group_name").Kind() != dyn.KindInvalid {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this could break existing TF users unnecessarily? The TF binary will be removed anywas in 1-2 weeks so we can remove this bit from the PR.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good callout. This check is a bit too broad so there is an issue for a narrow group of users (specific for Terraform-only users with 1.18 who use this just brand-new released feature). Will followup with a fix.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Followup: #6919 (sent by Isaac)

@lennartkats-db
lennartkats-db added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 07d0293 Oct 2, 2026
31 checks passed
@lennartkats-db
lennartkats-db deleted the lennart/run-as-group branch October 2, 2026 13:38
@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: 07d0293

Run: 37014402392

Env ❌​FAIL 🔄​flaky ✅​pass 🙈​skip Time
❌​ aws linux 3 1434 1118 146:00
❌​ aws windows 3 1359 1143 154:03
❌​ azure linux 3 1283 1170 128:36
❌​ azure windows 3 1208 1195 132:39
❌​ gcp linux 6 2 1267 1174 149:01
❌​ gcp windows 6 2 1192 1199 163:38
10 interesting tests: 6 FAIL, 4 flaky
Test Name aws linux aws windows azure linux azure windows gcp linux gcp windows
❌​ TestAccept ❌​F ❌​F ❌​F ❌​F ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info/DMS= ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/debug/fetch-repository-info/DMS=true ✅​p ✅​p ✅​p ✅​p ❌​F ❌​F
❌​ TestAccept/bundle/dms/provenance ❌​F ❌​F ❌​F ❌​F ❌​F ❌​F
❌​ TestAccept/bundle/dms/provenance/DMS=true ❌​F ❌​F ❌​F ❌​F ❌​F ❌​F
🔄​ TestAccept/bundle/resources/apps/inline_config/DMS= ✅​p ✅​p ✅​p ✅​p 🔄​f ✅​p
🔄​ TestAccept/bundle/resources/apps/inline_config/DMS=true ✅​p ✅​p ✅​p ✅​p 🔄​f ✅​p
🔄​ TestAccept/bundle/resources/apps/lifecycle-started-toggle/DMS= ✅​p ✅​p ✅​p ✅​p ✅​p 🔄​f
🔄​ TestAccept/bundle/resources/apps/lifecycle-started-toggle/DMS=true ✅​p ✅​p ✅​p ✅​p ✅​p 🔄​f
Top 50 slowest tests (at least 2 minutes):
duration env testname
14:02 azure linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
13:28 aws linux TestAccept/bundle/invariant/destroy_idempotent/DMS=/INPUT_CONFIG=cluster.yml.tmpl/READPLAN=
11:31 gcp windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
11:30 gcp windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
10:50 azure linux TestAccept/bundle/resources/clusters/deploy/update-after-create/DMS=true
10:31 gcp linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
10:18 azure linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
9:36 gcp linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
9:05 gcp windows TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=true
8:46 aws windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
8:45 gcp windows TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=
8:32 azure windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
8:30 aws linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
8:22 azure windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
8:13 azure windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
8:10 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
8:05 gcp linux TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=
8:05 aws linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
7:59 aws linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
7:49 azure linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
7:45 aws windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=
7:37 aws windows TestAccept/bundle/invariant/no_drift/DMS=/INPUT_CONFIG=cluster_apply_policy_default_values.yml.tmpl/READPLAN=1
7:32 azure windows TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
7:29 aws windows TestAccept/bundle/invariant/no_drift/DMS=/INPUT_CONFIG=cluster_apply_policy_default_values.yml.tmpl/READPLAN=
7:17 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
7:12 gcp linux TestAccept/bundle/resources/clusters/deploy/local_ssd_count/DMS=true
7:11 aws linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
7:07 azure linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=true
7:01 azure linux TestAccept/bundle/resources/apps/lifecycle-started/DMS=
7:00 gcp linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:52 gcp linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=true
6:50 aws linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:49 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
6:37 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
6:25 azure linux TestAccept/bundle/resources/clusters/deploy/update-after-create/DMS=
6:23 azure linux TestAccept/bundle/config-remote-sync/multiple_resources/DMS=
6:02 aws windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
5:52 aws windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
5:51 azure linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
5:47 aws windows TestAccept/bundle/resources/clusters/lifecycle-started/DMS=
5:46 aws linux TestAccept/bundle/resources/clusters/lifecycle-started/DMS=true
5:29 aws windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
5:12 azure linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
5:09 gcp windows TestAccept/bundle/resources/apps/lifecycle-started-toggle/DMS=true
4:58 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
4:54 gcp windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
4:49 azure windows TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
4:48 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=
4:40 gcp linux TestAccept/bundle/resources/clusters/lifecycle-started-toggle/DMS=true
4:35 gcp linux TestAccept/bundle/resources/apps/lifecycle-started-toggle/DMS=

yiweidai-db pushed a commit to yiweidai-db/cli that referenced this pull request Oct 6, 2026
## Changes

Allow Terraform deployments of pipelines with `run_as.group_name`,
including values inherited from bundle-level `run_as`.

Follow up to databricks#6676.

## Why

The converter rejects the field even though the pinned Terraform
provider supports it.

## Tests

`./task fmt`, `./task checks`, `./task lint`, `./task test`.
deco-sdk-tagging Bot added a commit that referenced this pull request Oct 7, 2026
## Release v1.20.0

### Notable Changes

 * Remove the Terraform deployment engine. `bundle.engine: terraform` and `DATABRICKS_BUNDLE_ENGINE=terraform` now error, and a failed migration of existing Terraform state is reported as an error instead of falling back to Terraform. To keep deploying with Terraform, use Databricks CLI v1.19.x. ([#6888](#6888), [#6889](#6889))

### CLI

 * `databricks aitools install` now supports Kiro, installing Databricks agent skills into its skills directory. ([#6908](#6908))
 * Fixed `databricks api` corrupting integers larger than 2^53 (such as job and pipeline ids) — request bodies and responses now preserve them exactly. ([#6884](#6884))
 * Added `--auth-mode` and `--set <plugin>.<resourceKey>.authMode=obo|sp|both` to `databricks apps init` so AppKit resources can be accessed on behalf of the user, by the service principal, or both. The default stays service principal. ([#6886](#6886))
 * `databricks apps init` now requires a value for every field a service principal resource binding references, prompting for missing values in an interactive terminal and otherwise failing with the `--set` key to use, instead of creating a project with unset variables. ([#6903](#6903))
 * Add `databricks apps init --package-manager <npm|pnpm>` to select the package manager for Node.js templates. Infer the default quietly from template lockfiles and AppKit version, check prerequisites before creating files, and preserve template formatting and pnpm version pins. ([#6902](#6902))
 * Select npm or pnpm from `packageManager` declarations and lockfiles for `apps validate` and project validation during `apps deploy`. ([#6892](#6892))
 * Fix `auth docker host` reporting the credential helper as configured when its executable is missing from `PATH`. ([#6880](#6880))
 * Warn when the CLI binary was built more than 6 months ago and recommend updating. ([#6898](#6898))

### AI Runtime

 * Add an experimental rank-partitioned container images to AI Runtime jobs. ([#6841](#6841))
 * Support snapshot fields directly under `code_source` without requiring `type` or a nested `snapshot` block. ([#6927](#6927))
 * Map AIR priority and Unity Catalog image fields when converting run configurations to bundles. ([#6905](#6905))
 * Add workspace backend validation to `air run --dry-run`. ([#6934](#6934))

### Bundles

 * Warn that `bundle.terraform` is deprecated and has no effect since the Terraform deployment engine was removed. ([#6940](#6940))
 * Direct engine now detects and applies an explicitly configured zero-value boolean or float (e.g. `gcp_attributes.use_preemptible_executors: false`, `azure_attributes.spot_bid_max_price: 0`) added to a resource first deployed without the field, matching the existing handling of an explicit integer zero. ([#6882](#6882))
 * Fix `bundle deployment migrate` failing with "no such file or directory" when the Terraform state has no resources or the configuration no longer declares any of them. ([#6958](#6958))
 * `bundle run` and `pipelines run` now send the per-update `development` parameter for pipelines in development mode targets. Setting `development` on a pipeline is deprecated and now emits a warning; use `mode: development` instead. ([#6863](#6863))
 * Remove the hidden `bundle debug terraform` command. ([#6933](#6933))
 * Add support for `run_as.group_name` at the bundle and target levels for jobs and pipelines. ([#6676](#6676))
 * Fix recreating a secret scope that was deleted outside of the bundle with the direct deployment engine. ([#6970](#6970))
 * Accept title-case booleans (`True`/`False`, as rendered by Azure Pipelines) for boolean variables, and accept the same boolean strings (`yes`/`no`, `on`/`off`, ...) in Python bundles as in YAML. ([#6942](#6942))

### Dependency Updates

 * Bump `github.com/databricks/databricks-sdk-go` from v0.182.0 to v0.185.0. ([#6928](#6928))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DABs DABs related issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants