bugfix: Auto-include grants and permissions on --select - #5852
Merged
Conversation
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 10:47 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 10:47 — with
GitHub Actions
Inactive
Contributor
This is not the reason, right? If we wanted to, we could support --select jobs.foo,jobs.foo.permissions We just think that common case is doing it together, so we simplifying that into --select jobs.foo |
Collaborator
Integration test reportCommit: 8bd2520
8 interesting tests: 4 RECOVERED, 4 SKIP
Top 5 slowest tests (at least 2 minutes):
|
denik
reviewed
Jul 8, 2026
Contributor
Author
|
@denik yes, primary reason is they should be deployed because users assume they will be (second sentence). Will update PR description to be more crisp |
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 12:33 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 12:33 — with
GitHub Actions
Inactive
…li into janniklasrose/schema-grants
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 12:38 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 12:38 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 16:21 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 16:21 — with
GitHub Actions
Inactive
…li into janniklasrose/schema-grants
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 18:02 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 8, 2026 18:02 — with
GitHub Actions
Inactive
pietern
approved these changes
Jul 9, 2026
janniklasrose
enabled auto-merge
July 9, 2026 08:02
janniklasrose
temporarily deployed
to
test-trigger-is
July 9, 2026 08:02 — with
GitHub Actions
Inactive
janniklasrose
temporarily deployed
to
test-trigger-is
July 9, 2026 08:02 — with
GitHub Actions
Inactive
deco-sdk-tagging Bot
added a commit
that referenced
this pull request
Jul 9, 2026
## Release v1.7.0 ### CLI * An explicitly selected profile (`--profile` or a bundle's `workspace.profile`) now takes precedence over auth environment variables (`DATABRICKS_HOST`, `DATABRICKS_TOKEN`, etc.) instead of being silently shadowed by them; env vars still fill auth fields the profile leaves empty ([#5096](#5096)). * Fix intermittent crashes when processing pages from API calls ([#5815](#5815)). ### Bundles * direct: add basic version of job_runs resource (experimental) ([#5603](#5603)). * Fix permissions added to a job or pipeline by a Python (PyDABs) mutator failing to deploy with "must have exactly one owner"; the deploying identity is now set as owner, matching resources whose permissions are declared in YAML ([#5821](#5821)). * Remove duplicate enum values for jsonschema.json ([#5839](#5839)). * direct: volumes: support `volume_path` property ([#5550](#5550)). * direct: Fix deploy bug when a `postgres_projects`, `postgres_branches`, or `postgres_endpoints` field is set to its zero value (e.g. `enable_pg_native_login: false`, `replace_existing: false`) ([#5782](#5782)). * `bundle run --only` help now documents the `+` modifier syntax: prefix a task key with `+` to also run its upstream tasks, or suffix it with `+` for downstream tasks ([#5760](#5760)). * direct: Recognize UC-managed catalog and schema property defaults to avoid unnecessary drift ([#5865](#5865) & [#5870](#5870)). * Fix `bundle deploy --select <resource>` skipping the resource's grants and permissions; they are now applied as part of the selected resource ([#5852](#5852)). * Support `purge_on_delete: true` on `postgres_branches` so bundles can hard-delete a Lakebase branch on destroy (skipping the soft-delete retention window) ([#5801](#5801)). * Support `replace_existing: true` on `postgres_databases` and `postgres_roles` so bundles can take over a database or role that already exists on a Lakebase branch instead of failing with `ALREADY_EXISTS` ([#5803](#5803)). ### Dependency updates * Bump databricks-sdk-go to v0.154.0 ([#5855](#5855)). * Bump terraform-provider to 1.121.0 ([#5857](#5857)). * Bump OpenTelemetry dependencies to v1.44.0 to address [CVE-2026-41178](GHSA-5wrp-cwcj-q835) ([#5873](#5873)).
Collaborator
Integration test reportCommit: 3a01ff0
31 interesting tests: 12 flaky, 11 FAIL, 5 RECOVERED, 2 SKIP, 1 KNOWN
Top 50 slowest tests (at least 2 minutes):
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Add
.grantsand.permissionsof resources to planWhy
Fixes #5794
.grantsand.permissionslive under their parents in the bundle, and most users will assume they are deployed as part of the--selected resource.Alternative: make them addressable via
--select <type>.<name>.{grants,permissions}. They already live as separate entities in plan, but this would be a separate improvement (if users only want to deploy those).Tests
New acceptance tests