Skip to content

auth: bound per-profile validation with a 10s timeout - #5928

Merged
janniklasrose merged 3 commits into
mainfrom
janniklasrose/auth-profile-timeout
Jul 21, 2026
Merged

auth: bound per-profile validation with a 10s timeout#5928
janniklasrose merged 3 commits into
mainfrom
janniklasrose/auth-profile-timeout

Conversation

@janniklasrose

Copy link
Copy Markdown
Contributor

Changes

Bound each per-profile validation in databricks auth profiles with a 10s timeout.

auth profiles validates every profile with a live API call (Workspaces.List for account configs, CurrentUser.Me for workspace configs). The SDK retries transient network failures — connection refused, connect/TLS timeout, retriable 5xx — for its default RetryTimeoutSeconds (~5 minutes). So a single unreachable-but-retriable workspace stalls the entire listing for minutes.

  • Wrap each validation call in a context.WithTimeout(ctx, 10s).
  • Set the same value on cfg.HTTPTimeoutSeconds / cfg.RetryTimeoutSeconds, because the host-metadata fetch in EnsureResolved runs on context.Background internally and so can't be reached by the validation call's context — without these it would still retry for ~5 minutes.

Hosts that fail DNS (e.g. a typo'd or reserved hostname) are not retriable and already fail fast; this only bounds the retriable cases.

Why

Users with a decommissioned, firewalled, or otherwise unresponsive workspace in ~/.databrickscfg see auth profiles hang for minutes on that one entry, blocking the whole list. Bounding each validation keeps the command responsive.

Tests

  • TestProfileLoadTimesOutOnUnresponsiveHost (cmd/auth/profiles_test.go) — points a profile at an httptest server that hangs every request until the client cancels, and asserts Load returns bounded rather than retrying to the SDK default. The handler waits on the request context so server.Close doesn't block on a leaked connection. profileValidationTimeout is a var so the test shrinks it (kept ≥1s, since Load derives the SDK's integer-second budgets from it and a sub-second value floors to 0 = "use default").
  • Full cmd/auth package and ./task lint-q pass.

This pull request and its description were written by Isaac, an AI coding agent.

`databricks auth profiles` validates each profile with a live API call
(Workspaces.List or CurrentUser.Me). The SDK retries transient network
failures — connection refused, connect/TLS timeout, retriable 5xx — for
its default RetryTimeoutSeconds (~5 minutes), so a single unreachable
workspace stalls the entire listing. (Hosts that fail DNS are not
retriable and already fail fast; those never stalled.)
Bound each validation with a 10s context timeout, and set the same value
on HTTPTimeoutSeconds/RetryTimeoutSeconds so the host-metadata fetch in
EnsureResolved is bounded too — it runs on context.Background internally,
so the context.WithTimeout on the validation call cannot reach it.
Adds a regression test that points a profile at a server which hangs
until the client cancels and asserts Load returns bounded rather than
retrying to the SDK default. profileValidationTimeout is a var so the
test can shrink it.
Co-authored-by: Isaac
@janniklasrosejanniklasrose changed the title auth profiles: bound per-profile validation with a 10s timeoutauth: bound per-profile validation with a 10s timeoutJul 15, 2026
Comment threadcmd/auth/profiles.go Outdated
Comment threadcmd/auth/profiles.go Outdated
@janniklasrose
janniklasrose added this pull request to the merge queueJul 21, 2026
@eng-dev-ecosystem-bot

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: d202457

Run: 29821925271

Env🔄​flaky💚​RECOVERED🙈​SKIP✅​pass🙈​skipTime
💚​aws linux4422711273:05
💚​aws windows4422911253:06
💚​aws-ucws linux4431410446:22
💚​aws-ucws windows4431610424:50
💚​azure linux4422711263:24
💚​azure windows4422911242:38
💚​azure-ucws linux4431610416:02
🔄​azure-ucws windows24431610394:31
💚​gcp linux4422611282:59
💚​gcp windows4422811262:52
10 interesting tests: 4 RECOVERED, 4 SKIP, 2 flaky
Test Nameaws linuxaws windowsaws-ucws linuxaws-ucws windowsazure linuxazure windowsazure-ucws linuxazure-ucws windowsgcp linuxgcp windows
💚​TestAccept💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R
🙈​TestAccept/bundle/invariant/no_drift🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/vector_search_endpoints/drift/recreated_same_name🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/bundle/resources/vector_search_indexes/recreate/embedding_dimension🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🙈​TestAccept/ssh/connection🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S🙈​S
🔄​TestFilerWorkspaceNotebook✅​p✅​p✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p
🔄​TestFilerWorkspaceNotebook/rJupyterNb.ipynb✅​p✅​p✅​p✅​p✅​p✅​p✅​p🔄​f✅​p✅​p
💚​TestFetchRepositoryInfoAPI_FromRepo💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R
💚​TestFetchRepositoryInfoAPI_FromRepo/root💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R
💚​TestFetchRepositoryInfoAPI_FromRepo/subdir💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R💚​R

Merged via the queue into main with commit b240ea8Jul 21, 2026
24 checks passed
@janniklasrose
janniklasrose deleted the janniklasrose/auth-profile-timeout branch July 21, 2026 10:58
@@ -0,0 +1 @@
* `databricks auth profiles` no longer stalls on an unreachable workspace. Each profile is now validated with a 10s timeout (also applied to the host-metadata fetch in `EnsureResolved`), so a host the SDK would otherwise retry — connection refused, connect/TLS timeout, or a retriable 5xx — can't block the whole listing for the SDK's default ~5-minute retry budget.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: outdated changelog with 5s change.

yansonggao-db pushed a commit to yansonggao-db/cli that referenced this pull request Jul 21, 2026
databricks#5928 follow-up
- forgot PR link
- AI text too verbose
deco-sdk-taggingBot added a commit that referenced this pull request Jul 22, 2026
## Release v1.9.0
### CLI
* `databricks auth profiles` no longer stalls on an unreachable workspace and instead fails validation after 5 seconds per host ([#5928](#5928)).
* Fixed `databricks fs rm -r` failing on UC Volumes backed by GCS when a directory becomes empty during recursive deletion ([#5958](#5958)).
* You can now ask questions about your data directly from the CLI with `databricks genie ask "..."`. Genie answers natural-language questions ("what were total sales last month?", "which tables are in the sales catalog?"), runs the query inside Databricks, and renders the answer in the terminal. This promotes the former `databricks experimental genie ask` command; the experimental alias still works but is deprecated and will be removed in a future release ([#6010](#6010)).
### Bundles
* `bundle validate` now reports a clear error when a `sql_warehouse` is missing a `name` (including whitespace-only names), and a warning when a grant is missing a `principal` ([#5818](#5818)).
* Bundle templates now scaffold an `AGENTS.md` that points coding agents at Databricks AI Tools, alongside a minimal `CLAUDE.md` that includes it via `@AGENTS.md` ([#5996](#5996)).
* `bundle generate job` can now download workspace files referenced by `spark_python_task`, rewriting them to a relative path like it already does for notebooks. This is opt-in via the `--download-spark-python-files` flag ([#5799](#5799)).
* Simplified the `default-minimal` bundle template and added an alias `databricks bundle init empty` ([#5899](#5899)).
* Add support for the `instance_pools` resource type in Declarative Automation Bundles. Instance pools are only supported in direct deployment mode.
* Do not emit "unknown field" warnings for YAML anchors grouped in a list or map, matching the existing suppression for standalone anchors ([#5975](#5975)).
* Provide an actionable error message if databricks.yml is missing or DATABRICKS_BUNDLE_ROOT is invalid ([#5953](#5953)).
### Dependency Updates
* Bump `github.com/databricks/databricks-sdk-go` from v0.154.0 to v0.160.0 ([#5982](#5982)).
* Bump Terraform provider from v1.121.0 to v1.122.0 ([#5977](#5977)).
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@janniklasrose@eng-dev-ecosystem-bot@pietern@andrewnester