Uh oh!
There was an error while loading. Please reload this page.
Show actionable errors for collaborative deployment scenarios - #1386
Conversation
dc33b28 to
c46ecdeCompareCodecov ReportAttention: Patch coverage is
Additional details and impacted files@@ Coverage Diff @@## main #1386 +/- ##
==========================================
+ Coverage 52.25% 53.75% +1.50%
==========================================
Files 317 352 +35 Lines 18004 20410 +2406 ==========================================
+ Hits 9408 10972 +1564 - Misses 7903 8636 +733 - Partials 693 802 +109 ☔ View full report in Codecov by Sentry. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
8d26485 to
16b80eaCompare16b80ea to
7fff4bcCompare737f02f to
3c20decCompare3c20dec to
b384b36Comparelennartkats-db
commented
Jul 11, 2024
@pietern could you take another look? |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
| assistance := "For assistance, contact the owners of this project." | ||
| if len(managersSlice) > 0 { | ||
| assistance = fmt.Sprintf("For assistance, users or groups with appropriate permissions may include: %s.", strings.Join(managersSlice, ", ")) |
| } | ||
| func ReportPermissionDenied(ctx context.Context, b *bundle.Bundle, path string) diag.Diagnostics { | ||
| log.Errorf(ctx, "Failed to update %v", path) |
There was a problem hiding this comment.
Ping. If this is not the case, please include a comment stating why this log statement shouldn't be removed.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
pietern
commented
Jul 15, 2024
@shreyas-goenka Can you take a pass as this as well? |
shreyas-goenka
commented
Jul 22, 2024
Missed the ping, taking a look. |
shreyas-goenka
left a comment
There was a problem hiding this comment.
Does this work end to end? Can Bob collaborate on a DAB deployed by Alice if he has CAN_MANAGE?
I recall there being some validation on the Terraform provider side that would fail even if Bob has CAN_MANAGE permissions set.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
lennartkats-db
commented
Sep 9, 2024
@pietern Updated the PR, processing all the new comments. I'd really like to get this merged. |
This was working a bit better before 26c3b42
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
fbf3c9d to
bde209cCompare| if otherManagers.Size() > 0 { | ||
| assistance = fmt.Sprintf( | ||
| "For assistance, users or groups with appropriate permissions may include: %s.", | ||
| strings.Join(otherManagers.Values(), ", "), |
There was a problem hiding this comment.
This is not sorted and is the cause of the test assertion failure in the latest test run.
pietern
commented
Oct 10, 2024
I'll submit a separate PR to remove the remaining |
## Changes Leftover from #1386. ## Tests All tests pass (indicating it really wasn't used).
CLI: * Added JSON input validation for CLI commands ([#1771](#1771)). Bundles: * Support Git worktrees for `sync` ([#1831](#1831)). * Add `bundle summary` to display URLs for deployed resources ([#1731](#1731)). * Added a warning when incorrect permissions used for `/Workspace/Shared` bundle root ([#1821](#1821)). * Show actionable errors for collaborative deployment scenarios ([#1386](#1386)). * Fix path to repository-wide exclude file ([#1837](#1837)). * Fixed typo in converting cluster permissions ([#1826](#1826)). * Ignore metastore permission error during template generation ([#1819](#1819)). * Handle normalization of `dyn.KindTime` into an any type ([#1836](#1836)). * Added support for pip options in environment dependencies ([#1842](#1842)). * Fix race condition when restarting continuous jobs ([#1849](#1849)). * Fix pipeline in default-python template not working for certain workspaces ([#1854](#1854)). * Add "output" flag to the bundle sync command ([#1853](#1853)). Internal: * Move utility functions dealing with IAM to libs/iamutil ([#1820](#1820)). * Remove unused `IS_OWNER` constant ([#1823](#1823)). * Assert SDK version is consistent in the CLI generation process ([#1814](#1814)). * Fixed unmarshalling json input into `interface{}` type ([#1832](#1832)). * Fix `TestAccFsMkdirWhenFileExistsAtPath` in isolated Azure environments ([#1833](#1833)). * Add behavioral tests for examples from the YAML spec ([#1835](#1835)). * Remove Terraform conversion function that's no longer used ([#1840](#1840)). * Encode assumptions about the dashboards API in a test ([#1839](#1839)). * Add script to make testing of code on branches easier ([#1844](#1844)). API Changes: * Added `databricks disable-legacy-dbfs` command group. OpenAPI commit cf9c61453990df0f9453670f2fe68e1b128647a2 (2024-10-14) Dependency updates: * Upgrade TF provider to 1.54.0 ([#1852](#1852)). * Bump github.com/databricks/databricks-sdk-go from 0.48.0 to 0.49.0 ([#1843](#1843)).
CLI: * Added JSON input validation for CLI commands ([#1771](#1771)). * Support Git worktrees for `sync` ([#1831](#1831)). Bundles: * Add `bundle summary` to display URLs for deployed resources ([#1731](#1731)). * Added a warning when incorrect permissions used for `/Workspace/Shared` bundle root ([#1821](#1821)). * Show actionable errors for collaborative deployment scenarios ([#1386](#1386)). * Fix path to repository-wide exclude file ([#1837](#1837)). * Fixed typo in converting cluster permissions ([#1826](#1826)). * Ignore metastore permission error during template generation ([#1819](#1819)). * Handle normalization of `dyn.KindTime` into an any type ([#1836](#1836)). * Added support for pip options in environment dependencies ([#1842](#1842)). * Fix race condition when restarting continuous jobs ([#1849](#1849)). * Fix pipeline in default-python template not working for certain workspaces ([#1854](#1854)). * Add "output" flag to the bundle sync command ([#1853](#1853)). Internal: * Move utility functions dealing with IAM to libs/iamutil ([#1820](#1820)). * Remove unused `IS_OWNER` constant ([#1823](#1823)). * Assert SDK version is consistent in the CLI generation process ([#1814](#1814)). * Fixed unmarshalling json input into `interface{}` type ([#1832](#1832)). * Fix `TestAccFsMkdirWhenFileExistsAtPath` in isolated Azure environments ([#1833](#1833)). * Add behavioral tests for examples from the YAML spec ([#1835](#1835)). * Remove Terraform conversion function that's no longer used ([#1840](#1840)). * Encode assumptions about the dashboards API in a test ([#1839](#1839)). * Add script to make testing of code on branches easier ([#1844](#1844)). API Changes: * Added `databricks disable-legacy-dbfs` command group. OpenAPI commit cf9c61453990df0f9453670f2fe68e1b128647a2 (2024-10-14) Dependency updates: * Upgrade TF provider to 1.54.0 ([#1852](#1852)). * Bump github.com/databricks/databricks-sdk-go from 0.48.0 to 0.49.0 ([#1843](#1843)).
## Changes This updates the templates to include a `permissions` section. Having a permissions section is a best practice, is helpful to understand the notion of permissions, and helps diagnose permission errors (#1386). This is a cherry-pick from #1387. This change was verified to work both in dev and prod. Existing unit tests validate the validity of the templates in these modes.
## Changes This adds diagnostics for collaborative (production) deployment scenarios, including: - Bob deploys a bundle that is normally deployed by Alice, but this fails because Bob can't write to `/Users/Alice/.bundle`. - Charlie deploys a bundle that is normally deployed by Alice, but this fails because he can't create a new pipeline where Alice would be the owner. - Alice deploys a bundle where she didn't list herself as one of the CAN_MANAGE users in permissions. That can work, but is probably a mistake. ## Tests Unit tests, manual testing.
## Changes Leftover from #1386. ## Tests All tests pass (indicating it really wasn't used).
CLI: * Added JSON input validation for CLI commands ([#1771](#1771)). * Support Git worktrees for `sync` ([#1831](#1831)). Bundles: * Add `bundle summary` to display URLs for deployed resources ([#1731](#1731)). * Added a warning when incorrect permissions used for `/Workspace/Shared` bundle root ([#1821](#1821)). * Show actionable errors for collaborative deployment scenarios ([#1386](#1386)). * Fix path to repository-wide exclude file ([#1837](#1837)). * Fixed typo in converting cluster permissions ([#1826](#1826)). * Ignore metastore permission error during template generation ([#1819](#1819)). * Handle normalization of `dyn.KindTime` into an any type ([#1836](#1836)). * Added support for pip options in environment dependencies ([#1842](#1842)). * Fix race condition when restarting continuous jobs ([#1849](#1849)). * Fix pipeline in default-python template not working for certain workspaces ([#1854](#1854)). * Add "output" flag to the bundle sync command ([#1853](#1853)). Internal: * Move utility functions dealing with IAM to libs/iamutil ([#1820](#1820)). * Remove unused `IS_OWNER` constant ([#1823](#1823)). * Assert SDK version is consistent in the CLI generation process ([#1814](#1814)). * Fixed unmarshalling json input into `interface{}` type ([#1832](#1832)). * Fix `TestAccFsMkdirWhenFileExistsAtPath` in isolated Azure environments ([#1833](#1833)). * Add behavioral tests for examples from the YAML spec ([#1835](#1835)). * Remove Terraform conversion function that's no longer used ([#1840](#1840)). * Encode assumptions about the dashboards API in a test ([#1839](#1839)). * Add script to make testing of code on branches easier ([#1844](#1844)). API Changes: * Added `databricks disable-legacy-dbfs` command group. OpenAPI commit cf9c61453990df0f9453670f2fe68e1b128647a2 (2024-10-14) Dependency updates: * Upgrade TF provider to 1.54.0 ([#1852](#1852)). * Bump github.com/databricks/databricks-sdk-go from 0.48.0 to 0.49.0 ([#1843](#1843)).
Changes
This adds diagnostics for collaborative (production) deployment scenarios, including:
/Users/Alice/.bundle.Tests
Unit tests, manual testing.