Repository navigation
Support bundle-wide group run identities for jobs and pipelines - #6676
Conversation
Approval status: pending
|
Integration test reportCommit: cc2da85
Top 6 slowest tests (at least 2 minutes):
|
shreyas-goenka
left a comment
There was a problem hiding this comment.
can we add validation that the bundle only has jobs / pipeliens or resources that do not support run_as?
Otherwise if we get support for run_as.group_name for dashboards tomorrow, adding top level support would break.
|
@shreyas-goenka We already reject bundle-wide The only new case is alerts: those support bundle-wide |
| return diags | ||
| } | ||
|
|
||
| if runAs.GroupName != "" { |
There was a problem hiding this comment.
This can still go out of date if another resource is introduced that supports run_as but not run_as group. Are we confident that this is unlikely to happen? Or should we have a separate allow list for this.
The case I'm trying to prevent is someone adds a resource and run as support but does not realize that run as group support was missing and that just leads us t a bad situation because changing runas down the line is a breaking change.
There was a problem hiding this comment.
Makes sense, I added a separate test, PTAL
| ) | ||
|
|
||
| func convertPipelineResource(ctx context.Context, vin dyn.Value) (dyn.Value, error) { | ||
| if vin.Get("run_as").Get("group_name").Kind() != dyn.KindInvalid { |
There was a problem hiding this comment.
this could break existing TF users unnecessarily? The TF binary will be removed anywas in 1-2 weeks so we can remove this bit from the PR.
There was a problem hiding this comment.
Good callout. This check is a bit too broad so there is an issue for a narrow group of users (specific for Terraform-only users with 1.18 who use this just brand-new released feature). Will followup with a fix.
Integration test reportCommit: 07d0293
10 interesting tests: 6 FAIL, 4 flaky
Top 50 slowest tests (at least 2 minutes):
|
## Changes Allow Terraform deployments of pipelines with `run_as.group_name`, including values inherited from bundle-level `run_as`. Follow up to databricks#6676. ## Why The converter rejects the field even though the pinned Terraform provider supports it. ## Tests `./task fmt`, `./task checks`, `./task lint`, `./task test`.
## Release v1.20.0 ### Notable Changes * Remove the Terraform deployment engine. `bundle.engine: terraform` and `DATABRICKS_BUNDLE_ENGINE=terraform` now error, and a failed migration of existing Terraform state is reported as an error instead of falling back to Terraform. To keep deploying with Terraform, use Databricks CLI v1.19.x. ([#6888](#6888), [#6889](#6889)) ### CLI * `databricks aitools install` now supports Kiro, installing Databricks agent skills into its skills directory. ([#6908](#6908)) * Fixed `databricks api` corrupting integers larger than 2^53 (such as job and pipeline ids) — request bodies and responses now preserve them exactly. ([#6884](#6884)) * Added `--auth-mode` and `--set <plugin>.<resourceKey>.authMode=obo|sp|both` to `databricks apps init` so AppKit resources can be accessed on behalf of the user, by the service principal, or both. The default stays service principal. ([#6886](#6886)) * `databricks apps init` now requires a value for every field a service principal resource binding references, prompting for missing values in an interactive terminal and otherwise failing with the `--set` key to use, instead of creating a project with unset variables. ([#6903](#6903)) * Add `databricks apps init --package-manager <npm|pnpm>` to select the package manager for Node.js templates. Infer the default quietly from template lockfiles and AppKit version, check prerequisites before creating files, and preserve template formatting and pnpm version pins. ([#6902](#6902)) * Select npm or pnpm from `packageManager` declarations and lockfiles for `apps validate` and project validation during `apps deploy`. ([#6892](#6892)) * Fix `auth docker host` reporting the credential helper as configured when its executable is missing from `PATH`. ([#6880](#6880)) * Warn when the CLI binary was built more than 6 months ago and recommend updating. ([#6898](#6898)) ### AI Runtime * Add an experimental rank-partitioned container images to AI Runtime jobs. ([#6841](#6841)) * Support snapshot fields directly under `code_source` without requiring `type` or a nested `snapshot` block. ([#6927](#6927)) * Map AIR priority and Unity Catalog image fields when converting run configurations to bundles. ([#6905](#6905)) * Add workspace backend validation to `air run --dry-run`. ([#6934](#6934)) ### Bundles * Warn that `bundle.terraform` is deprecated and has no effect since the Terraform deployment engine was removed. ([#6940](#6940)) * Direct engine now detects and applies an explicitly configured zero-value boolean or float (e.g. `gcp_attributes.use_preemptible_executors: false`, `azure_attributes.spot_bid_max_price: 0`) added to a resource first deployed without the field, matching the existing handling of an explicit integer zero. ([#6882](#6882)) * Fix `bundle deployment migrate` failing with "no such file or directory" when the Terraform state has no resources or the configuration no longer declares any of them. ([#6958](#6958)) * `bundle run` and `pipelines run` now send the per-update `development` parameter for pipelines in development mode targets. Setting `development` on a pipeline is deprecated and now emits a warning; use `mode: development` instead. ([#6863](#6863)) * Remove the hidden `bundle debug terraform` command. ([#6933](#6933)) * Add support for `run_as.group_name` at the bundle and target levels for jobs and pipelines. ([#6676](#6676)) * Fix recreating a secret scope that was deleted outside of the bundle with the direct deployment engine. ([#6970](#6970)) * Accept title-case booleans (`True`/`False`, as rendered by Azure Pipelines) for boolean variables, and accept the same boolean strings (`yes`/`no`, `on`/`off`, ...) in Python bundles as in YAML. ([#6942](#6942)) ### Dependency Updates * Bump `github.com/databricks/databricks-sdk-go` from v0.182.0 to v0.185.0. ([#6928](#6928))
Changes
Support bundle- and target-level
run_as.group_namefor jobs and pipelines using the direct engine. Preserve explicit per-resource identities, and reject pipeline groups with an actionable error when using Terraform.Why
The Jobs and Pipelines APIs support group run identities, but inherited bundle
run_asrejected them. Terraform's pipeline mapping cannot carry the group field.Tests
./task fmt,./task checks,./task lintgo test ./bundle/config/mutator/resourcemutator ./bundle/deploy/terraform/tfdyn -count=1go test ./acceptance -run 'TestAccept/bundle/run_as' -timeout=20m42, and inherited pipelines completed again after redeployment. All test resources were removed.