One cluster policy.
Creates one cluster policy and, when permissions is not empty, one databricks_permissions block on it. The module encodes definition and policy_family_definition_overrides to JSON, so pass them as objects.
databricks_cluster_policy.thisdatabricks_permissions.this[0](count = 1 only whenpermissionsis not empty)
The resource addresses above are part of the DataTF import contract. Do not rename them.
module "cluster_policy" {
source = "536tech/cluster-policy/databricks"
version = "1.0.1"
name = "Team Policy"
description = "Pinned runtime for team clusters"
definition = {
spark_version = {
type = "fixed"
value = "15.4.x-scala2.12"
}
}
libraries = [{
pypi = {
package = "great-expectations==0.18.0"
}
}]
permissions = [{
permission_level = "CAN_USE"
group_name = "data-engineers"
}]
}Configure the Databricks provider in the calling root with a workspace endpoint. This resource module is also used by the workspace pattern module. Each repository has its own releases. Consumers select an exact tested module version.
The resource addresses match the original workspace submodule in version 0.1.1.
To migrate a direct submodule call, change its source and version. Keep the module block name.
Run terraform init and require a plan with no resource changes.
DataTF exports continue to use the workspace pattern module and its existing import addresses.
Use Terraform 1.7 or later for the mock tests. The module supports Terraform 1.5 or later.
prek install
terraform init -backend=false -lockfile=readonly
terraform validate
terraform test
tflint --recursive
prek run --all-filesCI tests the committed provider version and the minimum supported provider, 1.128.0. The workspace pattern module checks the complete DataTF contract and its integration behavior.
The module rejects blank required names and invalid access inputs during the plan. Cross-input preconditions preserve the Terraform 1.5 minimum and existing resource addresses. Provider and API checks still apply. These checks do not prove complete permission visibility.
Each permission needs exactly one nonblank principal and a supported resource-specific permission level.
databricks_permissions manages the object's permission set. Keep one state owner for that set.
Empty permissions omit the permission resource.
See provider permission semantics.
The following requirements are needed by this module:
-
terraform (>= 1.5.0)
-
databricks (>= 1.128.0, < 2.0.0)
The following providers are used by this module:
- databricks (>= 1.128.0, < 2.0.0)
The following resources are used by this module:
- databricks_cluster_policy.this (resource)
- databricks_permissions.this (resource)
The following input variables are required:
Description: Cluster policy name.
Type: string
The following input variables are optional (have default values):
Description: Policy definition as an object. The module encodes it to JSON.
Type: any
Default: null
Description: Cluster policy description.
Type: string
Default: null
Description: Libraries installed on every cluster that uses the policy. Each element sets one of
pypi, maven, cran, whl, jar, egg, or requirements.
Type: any
Default: []
Description: Maximum number of clusters one user can start with this policy.
Type: number
Default: null
Description: Direct permissions on the policy. Each element names exactly one principal.
Type:
list(object({
permission_level = string
group_name = optional(string)
user_name = optional(string)
service_principal_name = optional(string)
}))Default: []
Description: Overrides on the policy family, as an object. The module encodes it to JSON.
Type: any
Default: null
Description: Policy family to derive the policy from, for example job-cluster.
Type: string
Default: null
The following outputs are exported:
Description: Cluster policy id.
Description: Cluster policy name.