Skip to content

direct: Add support for secret scopes - #3886

Merged
shreyas-goenka merged 62 commits into
mainfrom
direct-secret-scope
Dec 10, 2025
Merged

direct: Add support for secret scopes#3886
shreyas-goenka merged 62 commits into
mainfrom
direct-secret-scope

Conversation

@shreyas-goenka

@shreyas-goenkashreyas-goenka commented Nov 5, 2025

Copy link
Copy Markdown
Contributor

Changes

Adds direct deployment support for secret scopes.

Mock Server Fix

Fixed libs/testserver/secret_scopes.go to automatically grant MANAGE permission to the creator when a scope is created, matching real Databricks behavior.

Tests

New local and cloud acceptance tests.

@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Nov 7, 2025

Copy link
Copy Markdown
Collaborator

Commit: 7e1c917

Run: 20085396634

Env🔄​flaky💚​RECOVERED🙈​SKIP✅​pass🙈​skipTime
💚​aws linux7238063715:51
💚​aws windows7238263515:59
💚​aws-ucws linux7252352221:19
🔄​aws-ucws windows34252552020:17
🔄​azure linux3437963516:39
💚​azure windows1438363314:43
🔄​azure-ucws linux61451452027:30
💚​azure-ucws windows1452251820:31
💚​gcp linux1437064114:28
💚​gcp windows1437263914:21
17 interesting tests: 11 flaky, 4 RECOVERED, 2 SKIP
Test Nameaws linuxaws windowsaws-ucws linuxaws-ucws windowsazure linuxazure windowsazure-ucws linuxazure-ucws windowsgcp linuxgcp windows
🔄​TestAccept💚​R💚​R💚​R🔄​f🔄​f💚​R💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/deployment/bind/volume🙈​s🙈​s✅​p✅​p🙈​s🙈​s🔄​f✅​p🙈​s🙈​s
🔄​TestAccept/bundle/deployment/unbind/grants🙈​s🙈​s✅​p✅​p🙈​s🙈​s🔄​f✅​p🙈​s🙈​s
🔄​TestAccept/bundle/deployment/unbind/permissions✅​p✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p
🙈​TestAccept/bundle/resources/permissions🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🔄​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions💚​R💚​R💚​R🔄​f🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R🔄​f
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions💚​R💚​R💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/resources/secret_scopes/permissions✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p🙈​s🙈​s
🔄​TestAccept/bundle/resources/secret_scopes/permissions/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p
🔄​TestAccept/bundle/resources/synced_database_tables/basic🙈​s🙈​s✅​p✅​p🙈​s🙈​s🔄​f✅​p🙈​s🙈​s
🙈​TestAccept/bundle/run/app-with-job🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🔄​TestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_14.3_LTS✅​p✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p
🔄​TestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS✅​p✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p
Top 22 slowest tests (at least 2 minutes):
durationenvtestname
6:30aws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
6:25aws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
6:16aws-ucws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
5:55gcp linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
5:48aws-ucws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
5:46aws-ucws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
5:38aws-ucws windowsTestAccept/bundle/resources/synced_database_tables/basic
5:36gcp windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
5:21aws-ucws linuxTestAccept/bundle/resources/synced_database_tables/basic
5:17gcp linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
5:10aws-ucws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
5:09gcp windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
4:13azure linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
4:10azure-ucws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
4:02azure linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
4:01azure-ucws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
3:59azure-ucws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
3:41azure-ucws windowsTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform
3:27azure-ucws windowsTestAccept/bundle/resources/synced_database_tables/basic
3:11azure-ucws linuxTestAccept/bundle/resources/synced_database_tables/basic
2:49aws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=direct
2:40aws linuxTestAccept/bundle/resources/clusters/deploy/update-after-create/DATABRICKS_BUNDLE_ENGINE=terraform

@shreyas-goenkashreyas-goenka changed the title [WIP] direct: secret scopesdirect: Add support for secret scopesNov 7, 2025

@shreyas-goenkashreyas-goenkaNov 10, 2025

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Newly added tests give more than enough coverage for this. (see basic test)

Local = true
Cloud = false
RecordRequests = true
Local = false

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We only run it on cloud because there's ordering issues in the permissions returned by GET that are not worth dealing with (because of the different user names, there is no stable sort).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ordering issues can be addressed by recording requests in env-specific file:

> out.requests.$DATABRICKS_BUNDLE_ENGINE.json

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We would need to split them into local vs. cloud. The ordering issue here is the permissions being in a different order even after sorting.

It's doable but I'd rather skip it since the cloud coverage is the more important bit to ensure.

Comment threadbundle/config/mutator/resourcemutator/secret_scope_fixups.go
// setACLs reconciles the desired ACLs with the current state
func (r *ResourceSecretScopeAcls) setACLs(ctx context.Context, scopeName string, desiredAcls []workspace.AclItem) (string, error) {
// Get current ACLs
currentAcls, err := r.client.Secrets.ListAclsAll(ctx, workspace.ListAclsRequest{

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree, could be a follow up. a comment TODO would be nice to have here.

@shreyas-goenka
shreyas-goenka merged commit a4ab082 into mainDec 10, 2025
18 of 19 checks passed
@shreyas-goenka
shreyas-goenka deleted the direct-secret-scope branch December 10, 2025 02:59
@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Commit: a4ab082

Run: 20085809746

Env🔄​flaky💚​RECOVERED🙈​SKIP✅​pass🙈​skipTime
🔄​aws linux410140962452:06
💚​aws windows10141562254:43
💚​aws-ucws linux10157450365:21
💚​aws-ucws windows10157650165:05
💚​azure linux4341462246:30
🔄​azure windows23341562054:24
🔄​azure-ucws linux31357150160:44
💚​azure-ucws windows4357349959:43
💚​gcp linux4339463148:15
💚​gcp windows4339662942:51
16 interesting tests: 8 flaky, 7 RECOVERED, 1 SKIP
Test Nameaws linuxaws windowsaws-ucws linuxaws-ucws windowsazure linuxazure windowsazure-ucws linuxazure-ucws windowsgcp linuxgcp windows
🔄​TestAccept💚​R💚​R💚​R💚​R💚​R🔄​f🔄​f💚​R💚​R💚​R
🔄​TestAccept/bundle/generate/auto-bind✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p✅​p✅​p
🔄​TestAccept/bundle/integration_whl/base🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🔄​TestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🙈​TestAccept/bundle/resources/permissions🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions💚​R💚​R💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R💚​R
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions💚​R💚​R💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R
💚​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/resources/secret_scopes/permissions🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p🙈​s🙈​s
🔄​TestAccept/bundle/resources/secret_scopes/permissions/DATABRICKS_BUNDLE_ENGINE=terraform🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🔄​TestAccept/bundle/run/app-with-job💚​R💚​R💚​R💚​R💚​R💚​R🔄​f💚​R💚​R💚​R
💚​TestAccept/bundle/run/app-with-job/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/run/app-with-job/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R💚​R💚​R💚​R🔄​f💚​R💚​R💚​R
Top 50 slowest tests (at least 2 minutes):
durationenvtestname
16:50azure windowsTestAccept/bundle/resources/permissions/factcheck/DATABRICKS_BUNDLE_ENGINE=terraform
13:51gcp linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
13:38azure windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
13:26gcp linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
12:46azure-ucws windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
12:43gcp windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
12:06aws windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
11:34aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
11:22aws-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=terraform
11:07aws-ucws linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
10:56aws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
10:51aws-ucws windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
10:37aws windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
10:37aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=SINGLE_USER
10:36azure-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=terraform
10:31gcp windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
10:21aws-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=direct
10:19aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
9:33azure linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
9:08aws-ucws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
9:01azure-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_15.4_LTS
8:58azure-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_13.3_LTS
8:53azure-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=direct
8:51aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
8:49azure-ucws windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:41gcp linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:35azure-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_14.3_LTS
8:33gcp linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
8:33aws-ucws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:31gcp windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
8:30aws linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:25azure-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_15.4_LTS
8:24aws linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
8:23azure windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:22azure-ucws windowsTestAccept/bundle/integration_whl/custom_params/DATABRICKS_BUNDLE_ENGINE=terraform
8:18azure-ucws windowsTestAccept/bundle/integration_whl/custom_params/DATABRICKS_BUNDLE_ENGINE=direct
8:16aws-ucws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
8:15gcp windowsTestAccept/bundle/integration_whl/interactive_cluster/DATABRICKS_BUNDLE_ENGINE=terraform
8:14aws-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_15.4_LTS
8:14azure-ucws windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
8:11azure-ucws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
8:10aws windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:07azure linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:05aws-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_14.3_LTS
8:01azure windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_14.3_LTS
7:58aws linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
7:58azure windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
7:56aws-ucws linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
7:55azure-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_14.3_LTS
7:54azure-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_13.3_LTS

pietern added a commit that referenced this pull request Jan 12, 2026
…moval
The secret scope permissions test fails ~33% of the time when using
the Terraform bundle engine. The root cause is a backend API race
condition where parallel ACL modifications return inconsistent results.
The direct bundle engine already works around this by sequentializing
ACL operations (see #3886):
// Set ACLs. The service returns inconsistent results for parallel
// API calls. That's why we do them sequentially here to maintain
// correctness.
The Terraform provider has a similar workaround for creates via
robustPutACL with retry/verification (terraform-provider-databricks#4885,
issue #4195), but deletions have no such protection.
This change adds a depends_on chain between ACL resources, forcing
Terraform to execute them sequentially:
ACL_0 → depends_on: [scope]
ACL_1 → depends_on: [scope, ACL_0]
ACL_2 → depends_on: [scope, ACL_1]
This avoids triggering the backend race condition without requiring
changes to the Terraform provider.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
pietern added a commit that referenced this pull request Jan 12, 2026
…removal (#4258)
## Changes
This change adds a depends_on chain between ACL resources, forcing
Terraform to execute them sequentially:
```
ACL_0 → depends_on: [scope]
ACL_1 → depends_on: [scope, ACL_0]
ACL_2 → depends_on: [scope, ACL_1]
```
## Why
The secret scope permissions test fails ~33% of the time when using the
Terraform deployment engine. The root cause is a backend API race
condition where parallel ACL modifications return inconsistent results.
The direct bundle engine already works around this by sequentializing
ACL operations (see #3886):
```
// Set ACLs. The service returns inconsistent results for parallel
// API calls. That's why we do them sequentially here to maintain
// correctness.
```
The Terraform provider has a similar workaround for creates via
robustPutACL with retry/verification
(databricks/terraform-provider-databricks#4885, issue
databricks/terraform-provider-databricks#4195), but deletions have no
such protection.
This avoids triggering the backend race condition without requiring
changes to the Terraform provider.
## Tests
Manually ran the failing test 10 times and confirmed it no longer fails.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
denik pushed a commit that referenced this pull request May 20, 2026
## Summary
Field triggers apply to the state type, since they are applied after
`PrepareState`. They do not apply on the input config schema. This was
not a problem until now because both state and config were the same.
That's not the case, however, for secret scopes. Created a separate PR
because of the prompt in:
#3886 (comment)
---------
Co-authored-by: Claude <noreply@anthropic.com>
denik pushed a commit that referenced this pull request May 20, 2026
## Changes
Adds direct deployment support for secret scopes.
### Mock Server Fix
Fixed `libs/testserver/secret_scopes.go` to automatically grant MANAGE
permission to the creator when a scope is created, matching real
Databricks behavior.
## Tests
New local and cloud acceptance tests.
denik pushed a commit that referenced this pull request May 20, 2026
…removal (#4258)
## Changes
This change adds a depends_on chain between ACL resources, forcing
Terraform to execute them sequentially:
```
ACL_0 → depends_on: [scope]
ACL_1 → depends_on: [scope, ACL_0]
ACL_2 → depends_on: [scope, ACL_1]
```
## Why
The secret scope permissions test fails ~33% of the time when using the
Terraform deployment engine. The root cause is a backend API race
condition where parallel ACL modifications return inconsistent results.
The direct bundle engine already works around this by sequentializing
ACL operations (see #3886):
```
// Set ACLs. The service returns inconsistent results for parallel
// API calls. That's why we do them sequentially here to maintain
// correctness.
```
The Terraform provider has a similar workaround for creates via
robustPutACL with retry/verification
(databricks/terraform-provider-databricks#4885, issue
databricks/terraform-provider-databricks#4195), but deletions have no
such protection.
This avoids triggering the backend race condition without requiring
changes to the Terraform provider.
## Tests
Manually ran the failing test 10 times and confirmed it no longer fails.
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@shreyas-goenka@eng-dev-ecosystem-bot@pietern@denik@andrewnester