Skip to content

Modify grants to use SDK types - #4666

Merged
denik merged 15 commits into
mainfrom
denik/simpler-grant
Mar 6, 2026
Merged

Modify grants to use SDK types#4666
denik merged 15 commits into
mainfrom
denik/simpler-grant

Conversation

@denik

@denikdenik commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

Changes

  • Replace five custom grant types (Grant, SchemaGrant, CatalogGrant, ExternalLocationGrant, VolumeGrant) and their associated per-resource privilege enums with catalog.PrivilegeAssignment from the Databricks SDK.
  • Simplifies PrepareGrantsInputConfig in bundle/direct/dresources/grants.go: removes the reflection-based conversion loop and replaces it with a direct type assertion, now that all grant slices share the same type.

Why

Maintaining custom types is manual process. This prevents us from moving to autogenerated resources. This also causes issues for users where definition in CLI lags behind. #3821#4008

@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 11:39 — with GitHub Actions Inactive
@denikdenik changed the title Denik/simpler grantModify grants to use SDK typesMar 5, 2026
@denik
denik marked this pull request as ready for review March 5, 2026 11:43
@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 11:43 — with GitHub Actions Inactive
@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Mar 5, 2026

Copy link
Copy Markdown
Collaborator

Commit: 8653aba

Run: 22763045535

Env🪲​BUG❌​FAIL🟨​KNOWN🔄​flaky💚​RECOVERED🙈​SKIP✅​pass🙈​skipTime
🟨​aws linux7172687807:48
🟨​aws windows7172707787:03
🔄​aws-ucws linux2773646959:26
🔄​aws-ucws windows2773666937:34
🪲​azure linux18119262778145:35
🪲​azure windows18119264776144:53
🪲​azure-ucws linux18129360691139:32
🪲​azure-ucws windows18129362689139:39
🪲​gcp linux18119258781144:52
🪲​gcp windows18119260779144:27
25 interesting tests: 8 FAIL, 7 KNOWN, 7 SKIP, 2 flaky, 1 BUG
Test Nameaws linuxaws windowsaws-ucws linuxaws-ucws windowsazure linuxazure windowsazure-ucws linuxazure-ucws windowsgcp linuxgcp windows
🟨​TestAccept🟨​K🟨​K🔄​f💚​R🟨​K🟨​K🟨​K🟨​K🟨​K🟨​K
🪲​TestAccept/bundle/deployment/bind/alert🙈​s🙈​s🙈​s🙈​s🪲​B🪲​B🪲​B🪲​B🪲​B🪲​B
❌​TestAccept/bundle/deployment/bind/alert/DATABRICKS_BUNDLE_ENGINE=direct❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/deployment/bind/alert/DATABRICKS_BUNDLE_ENGINE=terraform❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
🙈​TestAccept/bundle/resources/permissions🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions🟨​K🟨​K💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=direct🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=terraform🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions🟨​K🟨​K💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=direct🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=terraform🟨​K🟨​K💚​R💚​R
🙈​TestAccept/bundle/resources/postgres_branches/basic🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/postgres_branches/recreate🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/postgres_branches/update_protected🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/postgres_branches/without_branch_id🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/postgres_endpoints/recreate🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/synced_database_tables/basic🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🔄​TestAccept/ssh/connect-serverless-gpu🙈​s🙈​s🔄​f🔄​f🙈​s🙈​s🔄​f🔄​f🙈​s🙈​s
🔄​TestAccept/ssh/connection💚​R💚​R💚​R🔄​f💚​R💚​R🔄​f🔄​f💚​R💚​R
Top 20 slowest tests (at least 2 minutes):
durationenvtestname
3:43aws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:42gcp windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:33aws-ucws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:30aws-ucws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
3:27aws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
3:19aws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:15azure-ucws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:13aws-ucws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:10gcp linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
3:05gcp windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
3:03aws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:53aws-ucws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:35azure linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:32gcp linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:15azure-ucws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
2:14azure windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
2:12azure-ucws windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:11azure linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=terraform
2:04azure-ucws linuxTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct
2:04azure windowsTestAccept/bundle/resources/apps/inline_config/DATABRICKS_BUNDLE_ENGINE=direct

@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 12:08 — with GitHub Actions Inactive
@denik
denikforce-pushed the denik/simpler-grant branch from 750657c to 839ba96CompareMarch 5, 2026 13:18
@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 13:19 — with GitHub Actions Inactive
@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 13:26 — with GitHub Actions Inactive
@denik
deniktemporarily deployed to test-trigger-is March 5, 2026 13:42 — with GitHub Actions Inactive
@denik
denikforce-pushed the denik/simpler-grant branch from 1608e31 to d8d1d4aCompareMarch 5, 2026 16:43
@denik
denik enabled auto-merge March 5, 2026 16:51
denikand others added 9 commits March 6, 2026 09:59
Removes five custom grant types (Grant, SchemaGrant, CatalogGrant,
ExternalLocationGrant, VolumeGrant) and their associated per-resource
privilege enums. All resources now use catalog.PrivilegeAssignment
directly from the Databricks SDK.
Also removes the reflection-based conversion in PrepareGrantsInputConfig
replacing it with a simple type assertion, and removes the now-unnecessary
TestSchemaGrantPrivilegesExhaustive test that maintained the enum sync.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@denik
denikforce-pushed the denik/simpler-grant branch from d8d1d4a to 45c5cd4CompareMarch 6, 2026 08:59
@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 08:59 — with GitHub Actions Inactive
…rants
INSERT is not a valid Unity Catalog privilege. After switching from the
custom Grant type (which used []string for privileges) to catalog.PrivilegeAssignment
from the SDK, the privileges field is now enum-validated. MODIFY is the
appropriate UC privilege for write operations.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 09:21 — with GitHub Actions Inactive
CatalogGrant/SchemaGrant/VolumeGrant and their privilege enums were
replaced by the unified PrivilegeAssignment/Privilege types. Add
aliases in each namespace's __init__.py so existing code continues
to work without changes.
The generator now reads codegen/aliases_patch.py and emits
OldName = NewName assignments into each namespace's __init__.py,
including the old names in __all__.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 11:11 — with GitHub Actions Inactive
denikand others added 2 commits March 6, 2026 12:16
Validates that old per-resource grant aliases (SchemaGrant,
SchemaGrantPrivilege) and new unified types (PrivilegeAssignment,
Privilege) both work in bundle validate, producing identical output.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 11:17 — with GitHub Actions Inactive
@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 11:19 — with GitHub Actions Inactive

@kanterovkanterov left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

python/ - LGTM

@denik
deniktemporarily deployed to test-trigger-is March 6, 2026 12:15 — with GitHub Actions Inactive
"resources.apps.*.resources[*].uc_securable": {"permission", "securable_full_name", "securable_type"},

"resources.catalogs.*": {"name"},
"resources.catalogs.*.grants[*]": {"privileges", "principal"},

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it expected that now these fields are not required?

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes, omitempty annotation is different between SDK and our own types.

@denik

denik commented Mar 6, 2026

Copy link
Copy Markdown
ContributorAuthor

Alert integration tests timed out, does not seem related.

@denik
denik disabled auto-merge March 6, 2026 15:13
@denik
denik merged commit c779b91 into mainMar 6, 2026
23 of 24 checks passed
@denik
denik deleted the denik/simpler-grant branch March 6, 2026 15:14
@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Commit: c779b91

Run: 22769468491

Env🪲​BUG❌​FAIL🟨​KNOWN🔄​flaky💚​RECOVERED🙈​SKIP✅​pass🙈​skipTime
❌​aws linux1721749173467:26
❌​aws windows171746574258:50
🔄​aws-ucws linux6231757582106:25
🔄​aws-ucws windows224172359391:43
🪲​azure linux112119484732234:21
🪲​azure windows112119456740230:27
🪲​azure-ucws linux1111148727587268:28
🪲​azure-ucws windows111148691598258:34
🪲​gcp linux112119467740236:21
🪲​gcp windows112119439748236:34
45 interesting tests: 16 RECOVERED, 12 FAIL, 8 flaky, 7 KNOWN, 1 BUG, 1 SKIP
Test Nameaws linuxaws windowsaws-ucws linuxaws-ucws windowsazure linuxazure windowsazure-ucws linuxazure-ucws windowsgcp linuxgcp windows
🟨​TestAccept🟨​K🟨​K💚​R💚​R🟨​K🟨​K🟨​K🟨​K🟨​K🟨​K
❌​TestAccept/bundle/apps/job_permissions❌​F❌​F✅​p🔄​f❌​F❌​F✅​p✅​p❌​F❌​F
🪲​TestAccept/bundle/deployment/bind/alert🙈​s🙈​s🙈​s🙈​s🪲​B🪲​B🪲​B🪲​B🪲​B🪲​B
❌​TestAccept/bundle/deployment/bind/alert/DATABRICKS_BUNDLE_ENGINE=direct❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/deployment/bind/alert/DATABRICKS_BUNDLE_ENGINE=terraform❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/generate/alert/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
🔄​TestAccept/bundle/integration_whl/base🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🔄​TestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p✅​p
❌​TestAccept/bundle/resources/alerts/basic✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/basic/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/basic/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
❌​TestAccept/bundle/resources/alerts/with_file/DATABRICKS_BUNDLE_ENGINE=terraform✅​p✅​p✅​p✅​p❌​F❌​F❌​F❌​F❌​F❌​F
🙈​TestAccept/bundle/resources/permissions🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions🟨​K🟨​K💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=direct🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/with_permissions/DATABRICKS_BUNDLE_ENGINE=terraform🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions🟨​K🟨​K💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=direct🟨​K🟨​K💚​R💚​R
🟨​TestAccept/bundle/resources/permissions/jobs/destroy_without_mgmtperms/without_permissions/DATABRICKS_BUNDLE_ENGINE=terraform🟨​K🟨​K💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/basic🙈​S🙈​S💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/postgres_branches/basic/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/basic/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/recreate🙈​S🙈​S💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/postgres_branches/recreate/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/recreate/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/update_protected🙈​S🙈​S💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/postgres_branches/update_protected/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/update_protected/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/without_branch_id🙈​S🙈​S💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
💚​TestAccept/bundle/resources/postgres_branches/without_branch_id/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R
💚​TestAccept/bundle/resources/postgres_branches/without_branch_id/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R
💚​TestAccept/bundle/resources/postgres_endpoints/recreate🙈​S🙈​S💚​R💚​R🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🔄​TestAccept/bundle/resources/postgres_projects/basic🙈​s🙈​s🔄​f✅​p🙈​s🙈​s🙈​s🙈​s🙈​s🙈​s
🔄​TestAccept/bundle/resources/postgres_projects/basic/DATABRICKS_BUNDLE_ENGINE=direct🔄​f✅​p
💚​TestAccept/bundle/resources/synced_database_tables/basic🙈​S🙈​S💚​R💚​R🙈​S🙈​S💚​R💚​R🙈​S🙈​S
💚​TestAccept/bundle/resources/synced_database_tables/basic/DATABRICKS_BUNDLE_ENGINE=direct💚​R💚​R💚​R💚​R
💚​TestAccept/bundle/resources/synced_database_tables/basic/DATABRICKS_BUNDLE_ENGINE=terraform💚​R💚​R💚​R💚​R
🔄​TestAccept/bundle/run/app-with-job✅​p✅​p🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🔄​TestAccept/bundle/run/app-with-job/DATABRICKS_BUNDLE_ENGINE=direct✅​p✅​p🔄​f✅​p✅​p✅​p✅​p✅​p✅​p✅​p
🔄​TestAccept/ssh/connect-serverless-gpu🙈​s🙈​s🔄​f🔄​f🙈​s🙈​s🔄​f✅​p🙈​s🙈​s
🔄​TestAccept/ssh/connection💚​R💚​R🔄​f💚​R💚​R💚​R💚​R💚​R💚​R💚​R
Top 50 slowest tests (at least 2 minutes):
durationenvtestname
14:17gcp linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
14:02azure-ucws windowsTestAccept/bundle/resources/permissions/factcheck/DATABRICKS_BUNDLE_ENGINE=terraform
12:36aws-ucws windowsTestAccept/bundle/invariant/no_drift/DATABRICKS_BUNDLE_ENGINE=direct/INPUT_CONFIG=database_catalog.yml.tmpl
12:30aws windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
11:58azure-ucws linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
11:28aws-ucws windowsTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=terraform
11:00gcp linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
10:54aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
10:46azure-ucws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
10:41gcp windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
10:39aws-ucws windowsTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=direct
10:38aws-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=terraform
10:17aws linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
9:37aws-ucws linuxTestAccept/bundle/resources/model_serving_endpoints/running-endpoint/DATABRICKS_BUNDLE_ENGINE=direct
9:19azure windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
9:16gcp windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
8:59azure-ucws windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
8:52gcp windowsTestAccept/bundle/run/app-with-job/DATABRICKS_BUNDLE_ENGINE=direct
8:47azure-ucws linuxTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_15.4_LTS
8:33gcp linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=SINGLE_USER
8:30azure-ucws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=SINGLE_USER
8:25gcp windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
8:22aws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:21gcp linuxTestAccept/bundle/integration_whl/interactive_cluster/DATABRICKS_BUNDLE_ENGINE=direct
8:16aws-ucws linuxTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:11aws linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
8:05aws-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_14.3_LTS
8:05gcp windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=direct
8:03gcp windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:03aws linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
8:02aws windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
8:01aws-ucws windowsTestAccept/bundle/integration_whl/base/DATABRICKS_BUNDLE_ENGINE=terraform
7:57aws-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_13.3_LTS
7:55gcp linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
7:46azure linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
7:45gcp linuxTestAccept/bundle/integration_whl/interactive_cluster/DATABRICKS_BUNDLE_ENGINE=terraform
7:44aws-ucws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=USER_ISOLATION
7:43azure linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_14.3_LTS
7:41azure-ucws windowsTestSparkJarTaskDeployAndRunOnVolumes/Databricks_Runtime_14.3_LTS
7:40gcp windowsTestAccept/bundle/integration_whl/interactive_cluster/DATABRICKS_BUNDLE_ENGINE=direct
7:39gcp windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=direct
7:38gcp linuxTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=direct
7:37aws windowsTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_14.3_LTS
7:34azure-ucws windowsTestAccept/bundle/invariant/no_drift/DATABRICKS_BUNDLE_ENGINE=direct/INPUT_CONFIG=database_catalog.yml.tmpl
7:33gcp windowsTestAccept/bundle/integration_whl/interactive_single_user/DATABRICKS_BUNDLE_ENGINE=terraform
7:33azure linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_15.4_LTS
7:31gcp linuxTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=terraform/DATA_SECURITY_MODE=USER_ISOLATION
7:30aws linuxTestSparkJarTaskDeployAndRunOnWorkspace/Databricks_Runtime_14.3_LTS
7:28aws windowsTestAccept/bundle/integration_whl/interactive_cluster_dynamic_version/DATABRICKS_BUNDLE_ENGINE=direct/DATA_SECURITY_MODE=SINGLE_USER
7:27gcp linuxTestAccept/bundle/run/app-with-job/DATABRICKS_BUNDLE_ENGINE=direct

shreyas-goenka added a commit that referenced this pull request Mar 6, 2026
After rebase on main, adapt to #4666 which switched grants from custom
per-resource types to SDK catalog.PrivilegeAssignment. Remove stale
per-resource grant annotation entries (descriptions now come from
OpenAPI), regenerate schema and python codegen, and clean up .wsignore
references to deleted docsgen files.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
shreyas-goenka added a commit that referenced this pull request Mar 9, 2026
After rebase on main, adapt to #4666 which switched grants from custom
per-resource types to SDK catalog.PrivilegeAssignment. Remove stale
per-resource grant annotation entries (descriptions now come from
OpenAPI), regenerate schema and python codegen, and clean up .wsignore
references to deleted docsgen files.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
denik added a commit that referenced this pull request Mar 11, 2026
## Changes
Replace custom permission types (JobPermission, PipelinePermission,
AlertPermission, etc.) and their associated per-resource permission
level enums with a single generic-based permission type that embeds
Level type from SDK where it's available and iam.PermissionLevel where
it is not.
This affects enum validation, previously, our types (except for
AlertPermission) did not have associated list of values, which means
invalid values were not producing a warning.
Note, alerts, dashboards, database_instances do not have dedicated
permission level type, so their list of possible values includes all
valid values for levels for all resources.
## Why
Simplification. Supports autogeneration of resource, no need to manually
provide allowed levels.
Similar change for grants: #4666
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
deco-sdk-taggingBot added a commit that referenced this pull request Mar 12, 2026
## Release v0.294.0
### Bundles
* Modify grants to use SDK types ([#4666](#4666))
* Modify permissions to use SDK types where available. This makes DABs validate permission levels, producing a warning on the unknown ones ([#4686](#4686))
### Dependency updates
* Bump databricks-sdk-go from v0.112.0 to v0.119.0 ([#4631](#4631), [#4695](#4695))
rauchy pushed a commit that referenced this pull request Mar 17, 2026
## Changes
Replace custom permission types (JobPermission, PipelinePermission,
AlertPermission, etc.) and their associated per-resource permission
level enums with a single generic-based permission type that embeds
Level type from SDK where it's available and iam.PermissionLevel where
it is not.
This affects enum validation, previously, our types (except for
AlertPermission) did not have associated list of values, which means
invalid values were not producing a warning.
Note, alerts, dashboards, database_instances do not have dedicated
permission level type, so their list of possible values includes all
valid values for levels for all resources.
## Why
Simplification. Supports autogeneration of resource, no need to manually
provide allowed levels.
Similar change for grants: #4666
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
rauchy pushed a commit that referenced this pull request Mar 17, 2026
## Release v0.294.0
### Bundles
* Modify grants to use SDK types ([#4666](#4666))
* Modify permissions to use SDK types where available. This makes DABs validate permission levels, producing a warning on the unknown ones ([#4686](#4686))
### Dependency updates
* Bump databricks-sdk-go from v0.112.0 to v0.119.0 ([#4631](#4631), [#4695](#4695))
denik added a commit that referenced this pull request May 20, 2026
## Changes
- Replace five custom grant types (Grant, SchemaGrant, CatalogGrant,
ExternalLocationGrant, VolumeGrant) and their associated per-resource
privilege enums with catalog.PrivilegeAssignment from the Databricks
SDK.
- Simplifies PrepareGrantsInputConfig in
bundle/direct/dresources/grants.go: removes the reflection-based
conversion loop and replaces it with a direct type assertion, now that
all grant slices share the same type.
## Why
Maintaining custom types is manual process. This prevents us from moving
to autogenerated resources. This also causes issues for users where
definition in CLI lags behind.
#3821#4008
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
denik added a commit that referenced this pull request May 20, 2026
## Changes
Replace custom permission types (JobPermission, PipelinePermission,
AlertPermission, etc.) and their associated per-resource permission
level enums with a single generic-based permission type that embeds
Level type from SDK where it's available and iam.PermissionLevel where
it is not.
This affects enum validation, previously, our types (except for
AlertPermission) did not have associated list of values, which means
invalid values were not producing a warning.
Note, alerts, dashboards, database_instances do not have dedicated
permission level type, so their list of possible values includes all
valid values for levels for all resources.
## Why
Simplification. Supports autogeneration of resource, no need to manually
provide allowed levels.
Similar change for grants: #4666
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
denik pushed a commit that referenced this pull request May 20, 2026
## Release v0.294.0
### Bundles
* Modify grants to use SDK types ([#4666](#4666))
* Modify permissions to use SDK types where available. This makes DABs validate permission levels, producing a warning on the unknown ones ([#4686](#4686))
### Dependency updates
* Bump databricks-sdk-go from v0.112.0 to v0.119.0 ([#4631](#4631), [#4695](#4695))
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@denik@eng-dev-ecosystem-bot@pietern@kanterov@andrewnester@lennartkats-db