Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .nextchanges/bundles/empty-grants-migrate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Fixed the direct deployment engine planning a spurious `create` for a resource's empty `grants: []` list. An empty grants list with no existing state entry is now a no-op, so `bundle plan` reports no actions after `bundle deployment migrate` (Terraform never records a grants resource for an empty list).
1 change: 1 addition & 0 deletions acceptance/bundle/invariant/migrate/out.test.toml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

11 changes: 0 additions & 11 deletions acceptance/bundle/invariant/migrate/test.toml
Original file line number Diff line number Diff line change
Expand Up @@ -26,17 +26,6 @@ EnvMatrixExclude.no_cross_resource_ref = ["INPUT_CONFIG=job_cross_resource_ref.y
# Grant cross-references require the EmbeddedSlice pattern not present in terraform mode.
EnvMatrixExclude.no_grant_ref = ["INPUT_CONFIG=schema_grant_ref.yml.tmpl"]

# An empty grants list plans a spurious create after migrate: Terraform records no
# databricks_grants resource for grants: [], so migrate leaves no state entry for the
# grants node, but the direct plan emits a "create" for it anyway. Found by fuzz testing.
# The plan check fails with:
# Unexpected action='create' for resources.schemas.foo.grants
# ...
# "resources.schemas.foo.grants": { "action": "create", ... }
# Exit code: 10
# Fixed by https://github.com/databricks/cli/pull/6039; re-enable once that lands.
EnvMatrixExclude.no_empty_grants = ["INPUT_CONFIG=schema_empty_grants.yml.tmpl"]

# SQL warehouses currently failing with migration with permanent drift. TODO: fix this.
EnvMatrixExclude.no_sql_warehouse = ["INPUT_CONFIG=sql_warehouse.yml.tmpl"]

Expand Down
8 changes: 8 additions & 0 deletions bundle/direct/bundle_plan.go
Original file line number Diff line number Diff line change
Expand Up @@ -961,6 +961,14 @@ func (b *DeploymentBundle) makePlan(ctx context.Context, configRoot *config.Root
if err != nil {
return nil, err
}
// Terraform writes no grants resource for an empty list, so migrate leaves
// no state entry. Skip the node here too; otherwise plan shows a spurious
// "create". Keep it when state exists so emptying grants still revokes.
if gs, ok := inputConfigStructVar.Value.(*dresources.GrantsState); ok && len(gs.EmbeddedSlice) == 0 {
if _, hasState := db.State[node]; !hasState {
continue
}
}
inputConfig = inputConfigStructVar.Value
baseRefs = inputConfigStructVar.Refs
}
Expand Down
Loading