Terraform Provider
Recent items mentioning Terraform Provider across the Databricks ecosystem — releases, news, videos, and community Q&A. Updated hourly.
The Databricks Terraform provider is expanding beyond core resource management into export/migration tooling: v1.129.0 added exporter support for six more resource types and fixed reference-resolution bugs 6, while v1.130.0 extended the exporter to Lakebase autoscaling resources and hardened databricks_repo with a 600-second timeout for large Git clones 4. Meanwhile v1.132.0 pushed new resource coverage (databricks_domain, databricks_sandbox, secret grants) and squashed a perpetual-diff bug in databricks_app git-source config 2, even as the CLI itself is quietly displacing Terraform as the default deployment engine, auto-migrating bundle state to a direct engine on clean deploys 5.
Generated daily from the 8 most recent items mentioning Terraform Provider. Click any [N] to jump to the source.
Direct deployment state version 3 is a breaking change requiring Databricks CLI v1.8.0 or later. New capabilities include Docker credential helpers for Databricks Artifact Registry, AI Gateway service support in bundles, file-change job run triggers, and bundle improvements for resource reference handling, deployment reporting, and state management.
Added databricks_domain and databricks_sandbox resources, plus secret securable support in databricks_grant. Fixed databricks_app resource to eliminate inconsistent result errors and perpetual diffs when managing git source configuration fields.
SSH sessions now automatically reattach and replay missed bytes when the tunnel connection drops temporarily, preventing session interruptions and eliminating manual reconnect workarounds. The CLI adds PyDABs secrets support, JSON output for aitools install with error categorization for CI automation, and displays bundle sync progress by default.
The databricks_repo resource now defaults to a 600-second HTTP timeout for inline Git operations to prevent failures when cloning or updating large repositories. Additionally, the resource exporter now supports Lakebase autoscaling resources.
Bundles automatically migrate from Terraform state to the direct engine on clean deploys (opt-out via engine: terraform), and SSH sessions stay connected during idle periods with automatic keepalives every 30 seconds. Direct engine bundle operations now correctly handle removed configuration fields, support cluster policies resources, and include a DATABRICKS_BUNDLE_RESOURCE_MAX_WAIT timeout setting.
The exporter now supports exporting six additional resource types including data classifications, secrets, endpoints, and workspace environments. The release also fixes exporter issues including skipping system-managed jobs during export, preserving zero values in settings, and properly resolving embedded references instead of hardcoding them.
Databricks Asset Bundles now report detailed resource action summaries and file sync counts during deploy and destroy operations, alongside fixes for workspace Git folder metadata and state migration. The CLI now enables FIPS 140-3 compliance by default for TLS connections, adds Goose support to aitools, and automatically resolves conflicting databricks-connect pins in local environment setups.
This release introduces v2 IAM resources and data sources at both account and workspace levels, covering management of groups, users, service principals, and workspace assignments. Documentation improvements include expanded Genie budget configuration guidance with shared versus per-user examples.
Added support for model_service, mcp_service, and model_provider_service securables in databricks_grant and databricks_grants resources. Fixed databricks_share to sync comment changes made outside Terraform instead of failing, with the comment attribute now optional and computed.
The CLI adds databricks environments setup-local to provision matched Python environments for Databricks compute targets and extends aitools install to support Gemini CLI and Pi. Bundles fix the ignored bundle.deployment.lock.force setting, add pipeline cascade_on_destroy control, improve experimental job_runs with idempotency tokens and completion waiting, and add UC secrets resource support.
Fixed an issue where config.DefaultHostMetadataResolverFactory wasn't being honored during provider configuration. Fixed perpetual plan diffs and null ID issues in databricks_share resources by properly restoring resource IDs on read and update operations.
The databricks_repo resource now supports an optional git_credential_id attribute to explicitly select credentials for repo operations. Workspace-level hosts now resolve workspace_id from host metadata instead of SCIM calls, preventing failures for service principals without /Me access and catching workspace_id mismatches at plan time rather than apply time.
The Terraform deployment engine is now deprecated; migrate to the direct deployment engine for continued support. AI runtime tasks now automatically package local directories into tarballs during deployment, and the direct engine fixes several convergence issues with empty grants, webhook notification ordering, pipeline configuration, and vector search index creation.
SSH connect now supports specifying serverless usage policies via --usage-policy-id, and bundle deploy/destroy are more robust against transient app states and full workspaces. Bundle validation is stricter for grants while empty field values are now dropped, fixing deployment failures and spurious permission drift.
Workspace ID validation for unified-provider resources shifted from plan time to apply time, reducing unnecessary API calls and eliminating false positives for restricted credentials and dynamic workspace IDs. The release adds a databricks_recipients data source for Delta Sharing, trace_location support for MLflow experiment traces in Unity Catalog, and fixes for VIEW column comment updates and access control rule set drift detection.
The databricks genie ask command is now stable (promoted from experimental), enabling practitioners to ask natural-language questions about their data directly from the CLI. Multiple reliability and usability improvements ship, including auth profile validation timeouts, fixes for GCS-backed UC Volumes deletion, bundle validation for sql_warehouse configurations, opt-in spark_python_task file downloads in bundle generation, and instance_pools resource support in Declarative Automation Bundles.
Adds resources and data sources for configuring Postgres change data capture in Databricks. Fixes a bug where column comment updates on views would fail with parse errors by using the correct COMMENT ON COLUMN syntax instead of ALTER VIEW.
The databricks_mws_ncc_private_endpoint_rule resource was refactored to enforce read-only attributes and poll for connection state at apply time, eliminating perpetual drift and surfacing provisioning failures immediately. AI search endpoint and index resources were added, databricks_cluster gained a flag to control cloud attribute removal, and job imports with over 100 tasks were fixed.
SSH connect adds --base-environment for custom base environments, and aitools install now uses plugins instead of raw skills. Bundle deployments fix drift on model serving endpoints and failed migrations on permissioned resources.
The provider adds Postgres data API resources and fixes permissions drift from user name casing mismatches and inability to disable OBO by setting empty user_api_scopes. Several SDKv2 fallback implementations are deprecated with warnings, slated for removal in the next major release.
Workspace exports now handle illegal filenames gracefully, and SSH sessions default to bash with workspace-home startup. Bundle deployments fix job URL access for non-admin users and prevent postgres roles from being recreated on each deploy.
Read-only workspace bindings documentation now clarifies they don't apply to non-catalog objects. This release contains no other user-facing changes.
The release introduces AI Search Endpoint and Index resources and fixes critical bugs affecting instance pools (infinite plan cycles), workspace configurations on GCP, MWS endpoint rules, and account-level entitlements. Individual job tasks can now be disabled in Terraform.
Databricks Asset Bundles now includes a select flag in the direct deployment engine to plan and deploy specific resource subsets, along with support for Terraform references and automatic transient HTTP retries. The experimental open command expands to support additional workspace resources such as volumes and vector search endpoints, while notebook task paths now correctly preserve Lakeflow Designer files.
The provider adds service principal Git credential management via principal_id on databricks_git_credential and enables permission management for Agent Bricks resources. Key fixes include metastore external_access_enabled now properly sent in PATCH requests, vector search index timeout increased to 75 minutes and made configurable, and workspace_id now accepting connection IDs alongside numeric workspace IDs.
This release introduces a breaking change that renames the min_qps configuration and CLI flag to target_qps for vector search endpoints, and it stops applying bundle name prefixes to these endpoints. Additionally, it improves the interactive authentication profile pickers, enhances OS keyring token storage behavior, and fixes bundle bugs related to nested notebook directory generation and multi-profile authentication propagation.
This release fixes state-decoding failures in databricks_library, databricks_share, and databricks_quality_monitor resources introduced in the previous version. It also resolves workspace resolution errors affecting multiple account-level data sources and settings, including service principals and MWS resources.
This release introduces new workspace-level services for supervisor agents and Unity Catalog secrets, along with an update method for tokens. Several existing API methods for data classification, environments, knowledge assistants, Postgres, and warehouses have breaking changes due to path modifications.
This release adds new resources for managing Postgres catalogs, synced tables, and workspace base environments. It also introduces an 'api' field for dual account/workspace resources to explicitly control API usage, supporting unified hosts.
Utility clusters created by resources like databricks_aws_s3_mount now default to SPOT_WITH_FALLBACK for improved reliability. Plaintext credential fields in databricks_model_serving and databricks_git_credential are now marked sensitive to prevent display in plan/apply output.
You can now manage Lakebase database project permissions using database_project_name in databricks_permissions and configure instance pool node type flexibility with a new block in databricks_instance_pool. A bug was fixed that previously caused errors during WorkspaceClient() creation in databricks_grant and databricks_grants resources.
This release adds new resources and data sources for managing Databricks Apps Space and Endpoints. It also updates the underlying Go SDK to version 0.108.0.
The databricks_workspace_file resource now supports payloads larger than 10MB, and databricks_mws_storage_configurations includes a role_arn field for S3 bucket sharing with Unity Catalog. Several bug fixes address issues with databricks_mws_ncc_private_endpoint_rule updates, databricks_secret_acl management, databricks_app resource reading, and databricks_users data source extra_attributes parameter.
SQL warehouses now support "5X-Large" cluster sizes and a higher maximum of 40 clusters. This release also fixes permanent drift for external model credentials in databricks_model_serving and improves dashboard file content change detection.
This release adds new resources for account user settings, default warehouse overrides, and fixes issues with importing databricks_share and creating databricks_dashboard resources. The exporter now supports additional network policy resources and rewrites cloud-specific attributes in cluster policies.
Get Tuesday's version of this
Tracking Terraform Provider? The Tuesday email carries what moved across the whole ecosystem, not just this topic. Free, one-click unsubscribe.




