Repository navigation
feat(app): unified Studio installation permissions for DAB and Marketplace - #1577
Open
laurencewells wants to merge 44 commits into
Open
laurencewells wants to merge 44 commits into
laurencewells wants to merge 44 commits into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1577 +/- ##
===========================================
+ Coverage 79.39% 92.75% +13.36%
===========================================
Files 142 142
Lines 14210 14210
Branches 151 151
===========================================
+ Hits 11282 13181 +1899
+ Misses 2859 959 -1900
- Partials 69 70 +1
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Contributor
|
✅ 1097/1097 passed, 52 skipped, 5h5m49s total Running from acceptance #6135 |
Contributor
|
✅ 1/1 passed, 24m58s total Running from mcp #884 |
Contributor
|
✅ 195/195 passed, 1 skipped, 7h27m53s total Running from anomaly #2249 |
…it form Co-authored-by: Isaac <no-reply@databricks.com>
…se broad keyword Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
…l model Co-authored-by: Isaac <no-reply@databricks.com>
…prefix Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
… MANAGE Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
…ew grant The task-runner SP now reads OBO temporary views through SELECT on the <prefix>_tmp schema instead of a per-view GRANT SELECT. The app SP keeps its per-view MANAGE grant for cleanup. Setup checks, the bundle grant, tests and docs are updated accordingly. Co-authored-by: Isaac <no-reply@databricks.com>
…ncipal resolution Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
…n setup Warehouse swap: - Setup checks (startup and Verify again) now check the administrator's saved warehouse, falling back to the bound one, so audience CAN USE is re-granted on the warehouse Studio actually uses. - Settings retries saving a warehouse pick after Grant succeeds. Before, a pick rejected for missing app-SP CAN MANAGE was never saved, so the audience grant never ran. Setup warnings: - Replace the in-app warnings banner with a setup review screen: admins see unacknowledged warnings once before entering Studio and confirm with "I understand, continue to Studio". The acknowledgement is stored per warning code in the browser, so the app_sharing_unverified warning re-reported by unattended startup checks no longer reappears. Co-authored-by: Isaac <no-reply@databricks.com>
…dio install gaps The runner stages oversized configs in the Delta dq_run_configs table since #1564, so it needs no Lakebase role or grants; remove the remaining guidance. Also document prefix/audience bundle variables (CLI, make, PowerShell), broad mode via --var, admin verification and role assignment for the DAB route, prefix reuse on upgrade, and use <prefix> in Studio SQL examples. Co-authored-by: Isaac <no-reply@databricks.com>
laurencewells
force-pushed
the
feat/studio-marketplace-permissions
branch
from
October 8, 2026 21:39
f02abf8 to
5e2999c
Compare
…S docs Two review follow-ups: keep a sanitized diagnostic when the metadata dimension refresh fails (the fail-closed raise swallowed the only log line), and correct the DQX_USER_GROUPS description — a non-empty audience is required on the bundle path, while Marketplace installs collect the audience through the setup form. Co-authored-by: Isaac <no-reply@databricks.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
Rebased onto
mainafter #1564 ("Fix run config table integration", which moves oversized run-config staging from Lakebase to Delta). The task runner no longer needs a Lakebase role:postgres_roles.task_runner_sp/DQX_TASK_RUNNER_POSTGRES_ROLEare gone from the bundle and the docs.Warning
Breaking change, with no upgrade path. Existing DQX Studio installations (DAB or Marketplace) must be removed and reinstalled. See
app/DEPLOYMENT.md→ "Removing a previous installation".Changes
DAB deployment and Marketplace installation now share one verified permission model with minimal admin setup. Setup reports READY only when every required permission is verified.
Storage and configuration
dqx_studio):<catalog>.<prefix>(with thewheelsvolume inside it),<prefix>_tmp,<prefix>_genieand<prefix>_demo. The Lakebase schema stays independent of the prefix.CAN_MANAGE) and Lakebase. The volume binding is gone. A new admin setup form collects catalog, prefix and audience group. The choices are saved in Lakebase, can be edited until storage is provisioned, and are locked after that.make app-deploygainsSTUDIO_PREFIX=andSTUDIO_USER_GROUP=arguments.STUDIO_USER_GROUP=usersselects broad mode: the workspace ACLs useusersand the UC grants useaccount users. Broad mode is DAB-only.Setup orchestrator
_tmpUSE SCHEMA/CREATE TABLE,_genieUSE SCHEMAplusSELECTon exactly the 5 approved views and 2 metadata dimensions, and_demoUSE SCHEMA/SELECT. It also verifies configured Genie space and dashboard ACLs. Workspaceadminsis never a UC grantee.adminsorDQX_ADMIN_GROUPcan run setup. Authorization uses a fresh OBO lookup.Least privilege
dq_run_configstable, covered by its main-schema grants);USE CATALOG; main schemaUSE SCHEMA/SELECT/MODIFY;_tmpUSE SCHEMA+ schema-levelSELECT(the runner can read any view in_tmp; the per-view runnerGRANT SELECT ON VIEWis removed); wheelsREAD VOLUME; nothing on_genie/_demo.MANAGEon the Studio schemas. The bundle engine silently dropsMANAGEwhen it is combined withALL_PRIVILEGES, hence the explicit list. It also gets warehouseCAN_MANAGE.Docs
app/DEPLOYMENT.md,DEVELOPMENT.md,README.md,AGENTS.mdandCUSTOMER_QA.md, plus the Studio quickstart, permissions and installation pages.prefix/studio_user_groupvia CLI--var,makeand PowerShell-BundleVars; broad mode via--varneedsstudio_uc_principal; custom admin groupUSE CATALOG; admin verification and role-assignment steps; prefix reuse on upgrade. Studio SQL examples use<catalog>.<prefix>.Linked issues
Builds on #1564 (merged; this branch is rebased onto it).
Tests
Verification at head (after the rebase):
make lint(pylint 10/10),make app-check(tsc + basedpyright 0 errors + 957 UI tests),make app-test4974 passed (fewer than before the rebase because #1564 removed the Lakebase staging tests), roottests/unit/test_app_backend.py143 passed,make app-check-marketplace35 passed,make docs-buildpasses, all commits GPG-signed.Live DAB acceptance (fresh workspace, scoped audience group; run before the rebase onto #1564):
postgres_roles.app_sp, which isn't confirmed to hit the same race)MANAGE)USE CATALOGblocks with the exact GRANT; re-granting returns READYadminsacceptedLive testing found and fixed four issues:
MANAGEwhen it was combined withALL_PRIVILEGES.Not yet exercised:
Known limitations:
make.ps1has noSTUDIO_*arguments; the docs show the-BundleVarsequivalent.Documentation and Demos
This pull request and its description were written by Isaac.