Repository navigation
feat: read app resource bindings from the AppKit manifest - #6903
Merged
MarioCadenas merged 9 commits intoOct 7, 2026
Merged
Conversation
A manifest resource can declare binding (yamlKey, varFields, staticFields) to describe its databricks.yml app resource entry. The generator uses it when present and falls back to the built-in per-type specs otherwise, which also keep supplying the default permission. Output is unchanged for bindings that match the built-in specs. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Collaborator
Integration test reportCommit: 72a9caa
Top 7 slowest tests (at least 2 minutes):
|
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
The built-in specs referenced a manifest field "id" that volume and experiment
resources do not declare (they declare "path" and "experimentId"). The
generated databricks.yml then used ${var.<res>_id}, a variable with no value,
so deploy failed.
Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
MarioCadenas
added this pull request to stack #6911
October 2, 2026 08:56
MarioCadenas
marked this pull request as ready for review
October 5, 2026 10:43
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
…ences apps init adds the databricks.yml binding variables for a resource bound to the service principal (auth mode sp or both) even when the manifest does not declare them, but nothing checked those variables had values, so bundle validate failed (for example on genie_space_name). Before writing any project files, prompt for missing binding values in an interactive terminal outside flags mode, and otherwise fail with the --set key to use. Resources accessed only on behalf of the user have no binding and are not checked; agentic mode still skips validation. --set now also accepts binding fields the manifest does not declare. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com> # Conflicts: # cmd/apps/init_test.go
Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: MarioCadenas <MarioCadenas@users.noreply.github.com>
atilafassina
approved these changes
Oct 7, 2026
deco-sdk-tagging Bot
added a commit
that referenced
this pull request
Oct 7, 2026
## Release v1.20.0 ### Notable Changes * Remove the Terraform deployment engine. `bundle.engine: terraform` and `DATABRICKS_BUNDLE_ENGINE=terraform` now error, and a failed migration of existing Terraform state is reported as an error instead of falling back to Terraform. To keep deploying with Terraform, use Databricks CLI v1.19.x. ([#6888](#6888), [#6889](#6889)) ### CLI * `databricks aitools install` now supports Kiro, installing Databricks agent skills into its skills directory. ([#6908](#6908)) * Fixed `databricks api` corrupting integers larger than 2^53 (such as job and pipeline ids) — request bodies and responses now preserve them exactly. ([#6884](#6884)) * Added `--auth-mode` and `--set <plugin>.<resourceKey>.authMode=obo|sp|both` to `databricks apps init` so AppKit resources can be accessed on behalf of the user, by the service principal, or both. The default stays service principal. ([#6886](#6886)) * `databricks apps init` now requires a value for every field a service principal resource binding references, prompting for missing values in an interactive terminal and otherwise failing with the `--set` key to use, instead of creating a project with unset variables. ([#6903](#6903)) * Add `databricks apps init --package-manager <npm|pnpm>` to select the package manager for Node.js templates. Infer the default quietly from template lockfiles and AppKit version, check prerequisites before creating files, and preserve template formatting and pnpm version pins. ([#6902](#6902)) * Select npm or pnpm from `packageManager` declarations and lockfiles for `apps validate` and project validation during `apps deploy`. ([#6892](#6892)) * Fix `auth docker host` reporting the credential helper as configured when its executable is missing from `PATH`. ([#6880](#6880)) * Warn when the CLI binary was built more than 6 months ago and recommend updating. ([#6898](#6898)) ### AI Runtime * Add an experimental rank-partitioned container images to AI Runtime jobs. ([#6841](#6841)) * Support snapshot fields directly under `code_source` without requiring `type` or a nested `snapshot` block. ([#6927](#6927)) * Map AIR priority and Unity Catalog image fields when converting run configurations to bundles. ([#6905](#6905)) * Add workspace backend validation to `air run --dry-run`. ([#6934](#6934)) ### Bundles * Warn that `bundle.terraform` is deprecated and has no effect since the Terraform deployment engine was removed. ([#6940](#6940)) * Direct engine now detects and applies an explicitly configured zero-value boolean or float (e.g. `gcp_attributes.use_preemptible_executors: false`, `azure_attributes.spot_bid_max_price: 0`) added to a resource first deployed without the field, matching the existing handling of an explicit integer zero. ([#6882](#6882)) * Fix `bundle deployment migrate` failing with "no such file or directory" when the Terraform state has no resources or the configuration no longer declares any of them. ([#6958](#6958)) * `bundle run` and `pipelines run` now send the per-update `development` parameter for pipelines in development mode targets. Setting `development` on a pipeline is deprecated and now emits a warning; use `mode: development` instead. ([#6863](#6863)) * Remove the hidden `bundle debug terraform` command. ([#6933](#6933)) * Add support for `run_as.group_name` at the bundle and target levels for jobs and pipelines. ([#6676](#6676)) * Fix recreating a secret scope that was deleted outside of the bundle with the direct deployment engine. ([#6970](#6970)) * Accept title-case booleans (`True`/`False`, as rendered by Azure Pipelines) for boolean variables, and accept the same boolean strings (`yes`/`no`, `on`/`off`, ...) in Python bundles as in YAML. ([#6942](#6942)) ### Dependency Updates * Bump `github.com/databricks/databricks-sdk-go` from v0.182.0 to v0.185.0. ([#6928](#6928))
Collaborator
Integration test reportCommit: b5e504a
181 interesting tests: 171 FAIL, 10 flaky
Top 50 slowest tests (at least 2 minutes):
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #6886 (base
apps-init-auth-mode).Changes
AppKit manifests can now describe how a resource is bound to the app in
databricks.yml, so new resource types do not need a CLI change.bindingon a resource:{ yamlKey, varFields: [[manifestField, dabsField]], staticFields?: [[dabsField, value]] }.binding, it drives the app resource entry and the bundle/target variables. Otherwise the existing built-in per-type specs (appResourceSpecs) are used, now labeled as the compat fallback. They also still supply the default permission when the manifest does not declare one.Why
Today every bindable resource type is hardcoded in the CLI. Reading the binding from the manifest keeps the type facts in appkit, like
scopeandappOnly.Tests
uc_table) and the JSON shape are covered too.apps/init/auth-modefixture warehouse now declares a matchingbinding; the existing outputs are unchanged.apps initagainst the re-synced DAB Roadmap for SQL artifacts #623 template (nobindingyet) produces the samedatabricks.ymlandapp.yamlas before this change for a mixed, a warehouse-OBO, and a pure-SP app.binding; that waits for the appkit side.This pull request and its description were written by Isaac.