Reference
databricks Dialect
See which types this Dialect interprets and which architectural facts its Rules can establish.
On this pageOverview
Version and compatibility
Version: 0.1.0.
Provider bindings and declared compatibility
databricks/databricks:= 1.129.0.
Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.
databricks.concept.ai-gateway-serviceSource-
A governed Mosaic AI Gateway service for models, model providers, or MCP tools.
-
Used by
ai-gateway-mcp-service,ai-gateway-model-provider-service,ai-gateway-model-service. databricks.concept.ai-inference-endpointSource-
A managed endpoint that serves model inference requests.
-
Used by
model-serving,model-serving-provisioned-throughput. databricks.concept.ai-search-endpointSource-
A Mosaic AI Search endpoint providing managed search capacity.
-
Used by
ai-search-endpoint,ai-search-index. databricks.concept.ai-search-indexSource-
A governed Mosaic AI Search index.
-
Used by
ai-search-index. databricks.concept.analytics-artifactSource-
A dashboard, query, alert, visualization, or widget presented through Databricks analytics.
-
Used by 9 Rules
databricks.concept.application-configurationSource-
A template, embedding, or deployment configuration supporting Databricks applications.
-
Used by
apps-custom-template,dashboard-embedding-access-policy,dashboard-embedding-approved-domains. databricks.concept.compute-clusterSource-
A Databricks compute cluster running data, analytics, or machine-learning workloads.
-
Used by
cluster-library,compute-cluster,lakeflow-job. databricks.concept.compute-configurationSource-
A policy, library, environment, identity registration, or setting supporting Databricks compute.
databricks.concept.database-configurationSource-
A database, role, synchronization, catalog, or change-data configuration supporting Lakebase.
-
A governed collection of data assets shared through Delta Sharing.
-
Used by
delta-share,unity-catalog-catalog. databricks.concept.delta-sharing-providerSource-
An external organization providing data through Delta Sharing.
-
Used by
delta-sharing-provider,unity-catalog-catalog. databricks.concept.external-locationSource-
A Unity Catalog external location pairing a cloud storage path with a storage credential.
-
Used by
external-location. databricks.concept.identity-access-configurationSource-
A membership, role, assignment, entitlement, permission, or federation configuration in Databricks.
-
Used by 21 Rules
access-control-rule-setaccount-federation-policyaccount-group-memberaccount-workspace-assignmententitlementsgrantgrantsgroup-instance-profilegroup-membergroup-rolemws-permission-assignmentpermission-assignmentpermissionsrfa-access-request-destinationsservice-principal-federation-policyservice-principal-roleuser-instance-profileuser-roleworkspace-group-memberworkspace-identity-assignmentworkspace-identity-detail
databricks.concept.identity-groupSource-
A managed group principal used to assign access collectively.
-
Used by
account-identity-group,identity-group,workspace-identity-group. databricks.concept.instance-poolSource-
A shared pool of cloud instances used to reduce Databricks cluster start time.
-
Used by
compute-cluster,instance-pool. databricks.concept.knowledge-assistantSource-
A Databricks Knowledge Assistant grounded in governed enterprise knowledge.
databricks.concept.lakebase-branchSource-
An isolated Lakebase database environment sharing project storage through copy-on-write.
-
Used by
lakebase-branch,lakebase-database,lakebase-endpoint. databricks.concept.lakebase-data-apiSource-
A Lakebase Data API exposing governed database access.
-
Used by
lakebase-data-api. databricks.concept.lakebase-databaseSource-
A logical Postgres database contained by a Lakebase branch.
-
Used by
lakebase-database. databricks.concept.lakebase-endpointSource-
A Lakebase Postgres compute endpoint providing read-write or read-only database access.
-
Used by
lakebase-endpoint. databricks.concept.lakebase-projectSource-
A Lakebase Autoscaling project containing branches, Postgres compute endpoints, and databases.
-
Used by
lakebase-branch,lakebase-data-api,lakebase-project. databricks.concept.lakeflow-pipelineSource-
A Lakeflow pipeline running declarative batch or streaming data processing.
-
Used by
lakeflow-pipeline,online-table. databricks.concept.lakehouse-federation-connectionSource-
A Unity Catalog connection to an external data system for Lakehouse Federation.
-
Used by
lakehouse-federation-connection,unity-catalog-catalog. databricks.concept.legacy-storage-mountSource-
A legacy DBFS mount configuration linking Databricks to cloud object storage.
-
Used by 5 Rules
databricks.concept.log-deliverySource-
A Databricks account or workspace log-delivery configuration.
-
Used by
log-delivery. databricks.concept.ml-platform-detailSource-
An experiment, model version, agent tool, feature, or ML configuration supporting Databricks AI and ML.
databricks.concept.network-bindingSource-
A binding attaching Databricks serverless network configuration to a workspace.
-
Used by
network-connectivity-binding. databricks.concept.network-connectivity-configurationSource-
A regional Databricks network connectivity configuration for serverless workloads.
databricks.concept.network-security-configurationSource-
Network policy or access configuration supporting Databricks connectivity.
-
Used by
account-network-policy,ip-access-list. databricks.concept.online-serving-configurationSource-
An online table or feature-serving configuration supporting Databricks online serving.
-
Used by
online-table. databricks.concept.orchestration-configurationSource-
A task, query, repository, or environment artifact supporting Databricks orchestration.
-
No Rule in this Dialect uses this definition.
databricks.concept.private-access-settingsSource-
Databricks private access settings controlling private workspace ingress.
-
Used by
private-access-settings,workspace. databricks.concept.private-endpoint-registrationSource-
A Databricks registration of a cloud private connectivity endpoint.
databricks.concept.private-endpoint-ruleSource-
A Databricks rule provisioning private connectivity from serverless compute to a cloud resource.
-
Used by
private-endpoint-rule. databricks.concept.quality-monitorSource-
A Databricks monitor evaluating data or model quality over time.
-
Used by 4 Rules
databricks.concept.registered-modelSource-
A governed machine-learning model registered in Unity Catalog.
-
Used by
registered-model. databricks.concept.secret-configurationSource-
A secret identity or access configuration whose value remains outside architecture output.
-
Used by 4 Rules
databricks.concept.secret-scopeSource-
A Databricks secret scope grouping sensitive configuration without exposing secret values.
-
Used by
secret,secret-acl,secret-scope. databricks.concept.service-credentialSource-
A Unity Catalog credential authorizing access to a cloud service.
-
Used by
service-credential. databricks.concept.sharing-configurationSource-
A sharing, provider, recipient, or catalog integration configuration.
-
No Rule in this Dialect uses this definition.
databricks.concept.sql-configurationSource-
Configuration or access control supporting Databricks SQL.
-
Used by
sql-global-config,sql-permissions. databricks.concept.storage-credentialSource-
A Unity Catalog credential authorizing access to cloud storage.
-
Used by
external-location,metastore-data-access,storage-credential. databricks.concept.supervisor-agentSource-
A Databricks supervisor agent coordinating governed tools and specialist agents.
-
Used by
supervisor-agent,supervisor-agent-tool. databricks.concept.unity-catalog-access-detailSource-
An assignment, binding, or access configuration supporting Unity Catalog.
databricks.concept.unity-catalog-catalogSource-
A Unity Catalog catalog organizing governed data and AI assets.
-
Used by
lakeflow-pipeline,unity-catalog-catalog,unity-catalog-schema. databricks.concept.unity-catalog-data-detailSource-
A governed data object or configuration within Unity Catalog.
databricks.concept.unity-catalog-metastoreSource-
A regional Unity Catalog metastore governing Databricks data and AI assets.
databricks.concept.unity-catalog-schemaSource-
A Unity Catalog schema organizing tables, volumes, models, and functions within a catalog.
-
Used by 4 Rules
databricks.concept.unity-catalog-volumeSource-
A Unity Catalog volume governing file storage for non-tabular data.
-
Used by
unity-catalog-volume. databricks.concept.vector-search-endpointSource-
A Mosaic AI Vector Search endpoint providing compute for vector indexes.
-
Used by
vector-search-endpoint,vector-search-index. databricks.concept.vector-search-indexSource-
A governed vector index served through Mosaic AI Vector Search.
-
Used by
vector-search-index. databricks.concept.workflowSource-
A managed workflow coordinating steps and service calls.
-
Used by
lakeflow-job. databricks.concept.workspaceSource-
A Databricks workspace providing an isolated environment for data, analytics, and AI workloads.
-
Used by
metastore-assignment,network-connectivity-binding,workspace. databricks.concept.workspace-configurationSource-
Configuration, assignment, or setting supporting a Databricks workspace.
-
Used by 15 Rules
account-settingautomatic-cluster-update-settingcompliance-security-profile-settingdefault-namespace-settingdisable-legacy-access-settingdisable-legacy-dbfs-settingdisable-legacy-features-settingdisaster-recovery-stable-urlenhanced-security-monitoring-settingrestrict-workspace-admins-settingwarehouses-default-warehouse-overrideworkspace-bindingworkspace-configurationworkspace-network-optionworkspace-setting
databricks.concept.workspace-deployment-credentialSource-
A cloud identity registration used to deploy Databricks workspace resources.
-
Used by
log-delivery,workspace,workspace-deployment-credential. databricks.concept.workspace-network-configurationSource-
A Databricks registration of customer-managed workspace network infrastructure.
-
Used by
workspace,workspace-network-configuration. databricks.concept.workspace-root-storageSource-
A cloud storage registration used as root storage by Databricks workspaces.
-
Used by
log-delivery,workspace,workspace-root-storage.
databricks.relation.branched-fromSource-
Introduced by a labeled emission. Used by
lakebase-branch,lakebase-provisioned-instance. databricks.relation.connects-to-storageSource-
Introduced by a labeled emission. Used by
private-endpoint-rule. databricks.relation.delivers-toSource-
Introduced by a labeled emission. Used by
log-delivery. databricks.relation.federates-throughSource-
Introduced by a labeled emission. Used by
unity-catalog-catalog. databricks.relation.imports-from-providerSource-
Introduced by a labeled emission. Used by
unity-catalog-catalog. -
Introduced by a labeled emission. Used by
unity-catalog-catalog. databricks.relation.publishes-to-catalogSource-
Introduced by a labeled emission. Used by
lakeflow-pipeline. databricks.relation.publishes-to-schemaSource-
Introduced by a labeled emission. Used by
lakeflow-pipeline. databricks.relation.runs-onSource-
Introduced by a labeled emission. Used by
lakeflow-job. databricks.relation.served-bySource-
Introduced by a labeled emission. Used by
ai-search-index,vector-search-index. databricks.relation.stores-inSource-
Introduced by a labeled emission.
databricks.relation.uses-cloud-identitySource-
Introduced by a labeled emission.
Used by 4 Rules
databricks.relation.uses-cloud-networkSource-
Introduced by a labeled emission. Used by
workspace-network-configuration. databricks.relation.uses-credentialSource-
Introduced by a labeled emission. Used by
external-location. databricks.relation.uses-deployment-credentialSource-
Introduced by a labeled emission. Used by
log-delivery,workspace. databricks.relation.uses-driver-poolSource-
Introduced by a labeled emission. Used by
compute-cluster. databricks.relation.uses-poolSource-
Introduced by a labeled emission. Used by
compute-cluster.
rf.concept.managed-databaserf.concept.object-storage-containerrf.concept.service-identityrf.concept.virtual-networkrf.context.networkrf.context.runtime
Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.
databricks.rule.access-control-rule-set Source
Matches resource instances of databricks_access_control_rule_set.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.account-federation-policy Source
Matches resource instances of databricks_account_federation_policy.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.account-group-member Source
Matches resource instances of databricks_account_iam_direct_group_member_v2.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.account-identity-group Source
Matches resource instances of databricks_account_iam_group_v2.
Classification: databricks.concept.identity-group.
databricks.rule.account-service-principal Source
Matches resource instances of databricks_account_iam_service_principal_v2.
Classification: rf.concept.service-identity.
Conditions, identity and resolution
Identity
attributes:["application_id", "service_principal_id"]scope:"provider"
Endpoint
attributes:["application_id", "service_principal_id"]
databricks.rule.account-workspace-assignment Source
Matches resource instances of databricks_account_iam_workspace_assignment_v2.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.account-network-policy Source
Matches resource instances of databricks_account_network_policy.
Classification: databricks.concept.network-security-configuration.
databricks.rule.account-setting Source
Matches resource instances of databricks_account_setting_v2.
Classification: databricks.concept.workspace-configuration.
databricks.rule.ai-gateway-mcp-service Source
Matches resource instances of databricks_ai_gateway_mcp_service.
Classification: databricks.concept.ai-gateway-service.
databricks.rule.ai-gateway-model-provider-service Source
Matches resource instances of databricks_ai_gateway_model_provider_service.
Classification: databricks.concept.ai-gateway-service.
databricks.rule.ai-gateway-model-service Source
Matches resource instances of databricks_ai_gateway_model_service.
Classification: databricks.concept.ai-gateway-service.
databricks.rule.ai-search-endpoint Source
Matches resource instances of databricks_ai_search_endpoint.
Classification: databricks.concept.ai-search-endpoint.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
databricks.rule.ai-search-index Source
Matches resource instances of databricks_ai_search_index.
Classification: databricks.concept.ai-search-index.
Relations
databricks.relation.served-by: targetsdatabricks.concept.ai-search-endpointthroughsource.endpoint.
Conditions, identity and resolution
Relation through source.endpoint
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.dashboard-embedding-access-policy Source
Matches resource instances of databricks_aibi_dashboard_embedding_access_policy_setting.
Classification: databricks.concept.application-configuration.
databricks.rule.dashboard-embedding-approved-domains Source
Matches resource instances of databricks_aibi_dashboard_embedding_approved_domains_setting.
Classification: databricks.concept.application-configuration.
databricks.rule.alert-v2 Source
Matches resource instances of databricks_alert_v2.
Classification: databricks.concept.analytics-artifact.
databricks.rule.alert Source
Matches resource instances of databricks_alert.
Classification: databricks.concept.analytics-artifact.
databricks.rule.apps-custom-template Source
Matches resource instances of databricks_apps_settings_custom_template.
Classification: databricks.concept.application-configuration.
databricks.rule.artifact-allowlist Source
Matches resource instances of databricks_artifact_allowlist.
Classification: databricks.concept.compute-configuration.
databricks.rule.automatic-cluster-update-setting Source
Matches resource instances of databricks_automatic_cluster_update_workspace_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.aws-s3-mount Source
Matches resource instances of databricks_aws_s3_mount.
Classification: databricks.concept.legacy-storage-mount.
databricks.rule.azure-adls-gen1-mount Source
Matches resource instances of databricks_azure_adls_gen1_mount.
Classification: databricks.concept.legacy-storage-mount.
databricks.rule.azure-adls-gen2-mount Source
Matches resource instances of databricks_azure_adls_gen2_mount.
Classification: databricks.concept.legacy-storage-mount.
databricks.rule.azure-blob-mount Source
Matches resource instances of databricks_azure_blob_mount.
Classification: databricks.concept.legacy-storage-mount.
databricks.rule.catalog-workspace-binding Source
Matches resource instances of databricks_catalog_workspace_binding.
Classification: databricks.concept.unity-catalog-access-detail.
databricks.rule.unity-catalog-catalog Source
Matches resource instances of databricks_catalog.
Classification: databricks.concept.unity-catalog-catalog.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Relations
databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.storage_root.databricks.relation.federates-through: targetsdatabricks.concept.lakehouse-federation-connectionthroughsource.connection_name.databricks.relation.imports-from-provider: targetsdatabricks.concept.delta-sharing-providerthroughsource.provider_name.databricks.relation.imports-share: targetsdatabricks.concept.delta-sharethroughsource.share_name.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.storage_root
on_null:"absent"on_empty:"absent"
Relation through source.connection_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.provider_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.share_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.cluster-policy Source
Matches resource instances of databricks_cluster_policy.
Classification: databricks.concept.compute-configuration.
databricks.rule.compute-cluster Source
Matches resource instances of databricks_cluster.
Classification: databricks.concept.compute-cluster.
Relations
databricks.relation.uses-pool: targetsdatabricks.concept.instance-poolthroughsource.instance_pool_id.databricks.relation.uses-driver-pool: targetsdatabricks.concept.instance-poolthroughsource.driver_instance_pool_id.databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_attributes[0].google_service_account.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Relation through source.instance_pool_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.driver_instance_pool_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.gcp_attributes[0].google_service_account
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
databricks.rule.compliance-security-profile-setting Source
Matches resource instances of databricks_compliance_security_profile_workspace_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.lakehouse-federation-connection Source
Matches resource instances of databricks_connection.
Classification: databricks.concept.lakehouse-federation-connection.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.service-credential Source
Matches resource instances of databricks_credential.
Classification: databricks.concept.service-credential.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Relations
databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.azure_managed_identity[0].managed_identity_id.
Conditions, identity and resolution
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.azure_managed_identity[0].managed_identity_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
databricks.rule.dashboard Source
Matches resource instances of databricks_dashboard.
Classification: databricks.concept.analytics-artifact.
databricks.rule.data-classification-catalog-config Source
Matches resource instances of databricks_data_classification_catalog_config.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.data-quality-monitor Source
Matches resource instances of databricks_data_quality_monitor.
Classification: databricks.concept.quality-monitor.
databricks.rule.lakebase-provisioned-catalog Source
Matches resource instances of databricks_database_database_catalog.
Classification: databricks.concept.database-configuration.
databricks.rule.lakebase-provisioned-instance Source
Matches resource instances of databricks_database_instance.
Classification: rf.concept.managed-database.
Relations
databricks.relation.branched-from: targetsrf.concept.managed-databasethroughsource.parent_instance_ref.name.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "uid"]
Relation through source.parent_instance_ref.name
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.namematch.strategy:"exact"
databricks.rule.lakebase-provisioned-synced-table Source
Matches resource instances of databricks_database_synced_database_table.
Classification: databricks.concept.database-configuration.
databricks.rule.default-namespace-setting Source
Matches resource instances of databricks_default_namespace_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.disable-legacy-access-setting Source
Matches resource instances of databricks_disable_legacy_access_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.disable-legacy-dbfs-setting Source
Matches resource instances of databricks_disable_legacy_dbfs_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.disable-legacy-features-setting Source
Matches resource instances of databricks_disable_legacy_features_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.disaster-recovery-stable-url Source
Matches resource instances of databricks_disaster_recovery_stable_url.
Classification: databricks.concept.workspace-configuration.
databricks.rule.service-direct-endpoint Source
Matches resource instances of databricks_endpoint.
Classification: databricks.concept.private-endpoint-registration.
databricks.rule.enhanced-security-monitoring-setting Source
Matches resource instances of databricks_enhanced_security_monitoring_workspace_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.entitlements Source
Matches resource instances of databricks_entitlements.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.entity-tag-assignment Source
Matches resource instances of databricks_entity_tag_assignment.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.default-workspace-base-environment Source
Matches resource instances of databricks_environments_default_workspace_base_environment.
Classification: databricks.concept.compute-configuration.
databricks.rule.workspace-base-environment Source
Matches resource instances of databricks_environments_workspace_base_environment.
Classification: databricks.concept.compute-configuration.
databricks.rule.external-location Source
Matches resource instances of databricks_external_location.
Classification: databricks.concept.external-location.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Relations
databricks.relation.uses-credential: targetsdatabricks.concept.storage-credentialthroughsource.credential_name.databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.url.
Conditions, identity and resolution
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.credential_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.url
on_null:"absent"on_empty:"absent"
databricks.rule.external-metadata Source
Matches resource instances of databricks_external_metadata.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.feature-engineering-feature Source
Matches resource instances of databricks_feature_engineering_feature.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.feature-engineering-kafka-config Source
Matches resource instances of databricks_feature_engineering_kafka_config.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.feature-engineering-materialized-feature Source
Matches resource instances of databricks_feature_engineering_materialized_feature.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.global-init-script Source
Matches resource instances of databricks_global_init_script.
Classification: databricks.concept.compute-configuration.
databricks.rule.grant Source
Matches resource instances of databricks_grant.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.grants Source
Matches resource instances of databricks_grants.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.group-instance-profile Source
Matches resource instances of databricks_group_instance_profile.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.group-member Source
Matches resource instances of databricks_group_member.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.group-role Source
Matches resource instances of databricks_group_role.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.identity-group Source
Matches resource instances of databricks_group.
Classification: databricks.concept.identity-group.
databricks.rule.instance-pool Source
Matches resource instances of databricks_instance_pool.
Classification: databricks.concept.instance-pool.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
databricks.rule.instance-profile Source
Matches resource instances of databricks_instance_profile.
Classification: databricks.concept.compute-configuration.
databricks.rule.ip-access-list Source
Matches resource instances of databricks_ip_access_list.
Classification: databricks.concept.network-security-configuration.
databricks.rule.lakeflow-job Source
Matches resource instances of databricks_job.
Classification: databricks.concept.workflow.
Relations
databricks.relation.runs-on: targetsdatabricks.concept.compute-clusterthroughsource.existing_cluster_id.
Conditions, identity and resolution
Relation through source.existing_cluster_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.knowledge-assistant-source Source
Matches resource instances of databricks_knowledge_assistant_knowledge_source.
Classification: databricks.concept.ml-platform-detail.
Contributions
- targets
databricks.concept.knowledge-assistantthroughsource.parent.
Conditions, identity and resolution
Contribution through source.parent
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.knowledge-assistant Source
Matches resource instances of databricks_knowledge_assistant.
Classification: databricks.concept.knowledge-assistant.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
databricks.rule.lakehouse-monitor Source
Matches resource instances of databricks_lakehouse_monitor.
Classification: databricks.concept.quality-monitor.
databricks.rule.cluster-library Source
Matches resource instances of databricks_library.
Classification: databricks.concept.compute-configuration.
Contributions
- targets
databricks.concept.compute-clusterthroughsource.cluster_id.
Conditions, identity and resolution
Contribution through source.cluster_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.materialized-feature-tag Source
Matches resource instances of databricks_materialized_features_feature_tag.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.metastore-assignment Source
Matches resource instances of databricks_metastore_assignment.
Classification: databricks.concept.unity-catalog-access-detail.
Contributions
- targets
databricks.concept.unity-catalog-metastorethroughsource.metastore_id. - targets
databricks.concept.workspacethroughsource.workspace_id.
Conditions, identity and resolution
Contribution through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Contribution through source.workspace_id
on_null:"absent"on_empty:"absent"match.by:target.workspace_idmatch.strategy:"exact"
databricks.rule.metastore-data-access Source
Matches resource instances of databricks_metastore_data_access.
Classification: databricks.concept.storage-credential.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Relations
databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.azure_managed_identity[0].managed_identity_id.databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_service_account_key[0].email.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.azure_managed_identity[0].managed_identity_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.gcp_service_account_key[0].email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
databricks.rule.unity-catalog-metastore Source
Matches resource instances of databricks_metastore.
Classification: databricks.concept.unity-catalog-metastore.
Relations
databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.storage_root.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Relation through source.storage_root
on_null:"absent"on_empty:"absent"
databricks.rule.mlflow-experiment Source
Matches resource instances of databricks_mlflow_experiment.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.mlflow-model Source
Matches resource instances of databricks_mlflow_model.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.mlflow-webhook Source
Matches resource instances of databricks_mlflow_webhook.
Classification: databricks.concept.ml-platform-detail.
databricks.rule.model-serving-provisioned-throughput Source
Matches resource instances of databricks_model_serving_provisioned_throughput.
Classification: databricks.concept.ai-inference-endpoint.
databricks.rule.model-serving Source
Matches resource instances of databricks_model_serving.
Classification: databricks.concept.ai-inference-endpoint.
databricks.rule.mount Source
Matches resource instances of databricks_mount.
Classification: databricks.concept.legacy-storage-mount.
databricks.rule.workspace-deployment-credential Source
Matches resource instances of databricks_mws_credentials.
Classification: databricks.concept.workspace-deployment-credential.
Conditions, identity and resolution
Identity
attributes:["id", "credentials_id"]scope:"provider"
Endpoint
attributes:["id", "credentials_id"]
databricks.rule.log-delivery Source
Matches resource instances of databricks_mws_log_delivery.
Classification: databricks.concept.log-delivery.
Relations
databricks.relation.delivers-to: targetsdatabricks.concept.workspace-root-storagethroughsource.storage_configuration_id.databricks.relation.uses-deployment-credential: targetsdatabricks.concept.workspace-deployment-credentialthroughsource.credentials_id.
Conditions, identity and resolution
Relation through source.storage_configuration_id
on_null:"absent"on_empty:"absent"match.by:target.storage_configuration_idmatch.strategy:"exact"
Relation through source.credentials_id
on_null:"absent"on_empty:"absent"match.by:target.credentials_idmatch.strategy:"exact"
databricks.rule.network-connectivity-binding Source
Matches resource instances of databricks_mws_ncc_binding.
Classification: databricks.concept.network-binding.
Contributions
- targets
databricks.concept.network-connectivity-configurationthroughsource.network_connectivity_config_id. - targets
databricks.concept.workspacethroughsource.workspace_id.
Conditions, identity and resolution
Contribution through source.network_connectivity_config_id
on_null:"absent"on_empty:"absent"match.by:target.network_connectivity_config_idmatch.strategy:"exact"
Contribution through source.workspace_id
on_null:"absent"on_empty:"absent"match.by:target.workspace_idmatch.strategy:"exact"
databricks.rule.private-endpoint-rule Source
Matches resource instances of databricks_mws_ncc_private_endpoint_rule.
Classification: databricks.concept.private-endpoint-rule.
Contexts
rf.context.network: targetsdatabricks.concept.network-connectivity-configurationthroughsource.network_connectivity_config_id.
Relations
databricks.relation.connects-to-storage: targetsrf.concept.object-storage-containerthroughsource.resource_id.
Conditions, identity and resolution
Context through source.network_connectivity_config_id
on_null:"absent"on_empty:"absent"match.by:target.network_connectivity_config_idmatch.strategy:"exact"
Relation through source.resource_id
on_null:"absent"on_empty:"absent"
databricks.rule.network-connectivity-configuration Source
Matches resource instances of databricks_mws_network_connectivity_config.
Classification: databricks.concept.network-connectivity-configuration.
Conditions, identity and resolution
Identity
attributes:["id", "network_connectivity_config_id"]scope:"provider"
Endpoint
attributes:["id", "network_connectivity_config_id"]
databricks.rule.workspace-network-configuration Source
Matches resource instances of databricks_mws_networks.
Classification: databricks.concept.workspace-network-configuration.
Relations
databricks.relation.uses-cloud-network: targetsrf.concept.virtual-networkthroughsource.vpc_id.databricks.relation.uses-cloud-network: targetsrf.concept.virtual-networkthroughsource.gcp_network_info[0].vpc_id.
Conditions, identity and resolution
Identity
attributes:["id", "network_id"]scope:"provider"
Endpoint
attributes:["id", "network_id"]
Relation through source.vpc_id
on_null:"absent"on_empty:"absent"
Relation through source.gcp_network_info[0].vpc_id
on_null:"absent"on_empty:"absent"
databricks.rule.mws-permission-assignment Source
Matches resource instances of databricks_mws_permission_assignment.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.private-access-settings Source
Matches resource instances of databricks_mws_private_access_settings.
Classification: databricks.concept.private-access-settings.
Conditions, identity and resolution
Identity
attributes:["id", "private_access_settings_id"]scope:"provider"
Endpoint
attributes:["id", "private_access_settings_id"]
databricks.rule.workspace-root-storage Source
Matches resource instances of databricks_mws_storage_configurations.
Classification: databricks.concept.workspace-root-storage.
Relations
databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.bucket_name.
Conditions, identity and resolution
Identity
attributes:["id", "storage_configuration_id"]scope:"provider"
Endpoint
attributes:["id", "storage_configuration_id"]
Relation through source.bucket_name
on_null:"absent"on_empty:"absent"
databricks.rule.vpc-endpoint-registration Source
Matches resource instances of databricks_mws_vpc_endpoint.
Classification: databricks.concept.private-endpoint-registration.
databricks.rule.workspace Source
Matches resource instances of databricks_mws_workspaces.
Classification: databricks.concept.workspace.
Relations
databricks.relation.uses-network: targetsdatabricks.concept.workspace-network-configurationthroughsource.network_id.databricks.relation.uses-root-storage: targetsdatabricks.concept.workspace-root-storagethroughsource.storage_configuration_id.databricks.relation.uses-deployment-credential: targetsdatabricks.concept.workspace-deployment-credentialthroughsource.credentials_id.databricks.relation.uses-private-access: targetsdatabricks.concept.private-access-settingsthroughsource.private_access_settings_id.databricks.relation.uses-serverless-network: targetsdatabricks.concept.network-connectivity-configurationthroughsource.network_connectivity_config_id.
Conditions, identity and resolution
Identity
attributes:["id", "workspace_id"]scope:"provider"
Endpoint
attributes:["id", "workspace_id"]
Relation through source.network_id
on_null:"absent"on_empty:"absent"match.by:target.network_idmatch.strategy:"exact"
Relation through source.storage_configuration_id
on_null:"absent"on_empty:"absent"match.by:target.storage_configuration_idmatch.strategy:"exact"
Relation through source.credentials_id
on_null:"absent"on_empty:"absent"match.by:target.credentials_idmatch.strategy:"exact"
Relation through source.private_access_settings_id
on_null:"absent"on_empty:"absent"match.by:target.private_access_settings_idmatch.strategy:"exact"
Relation through source.network_connectivity_config_id
on_null:"absent"on_empty:"absent"match.by:target.network_connectivity_config_idmatch.strategy:"exact"
databricks.rule.online-table Source
Matches resource instances of databricks_online_table.
Classification: databricks.concept.online-serving-configuration.
Contributions
- targets
databricks.concept.lakeflow-pipelinethroughsource.spec[0].pipeline_id.
Conditions, identity and resolution
Contribution through source.spec[0].pipeline_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.permission-assignment Source
Matches resource instances of databricks_permission_assignment.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.permissions Source
Matches resource instances of databricks_permissions.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.lakeflow-pipeline Source
Matches resource instances of databricks_pipeline.
Classification: databricks.concept.lakeflow-pipeline.
Relations
databricks.relation.publishes-to-catalog: targetsdatabricks.concept.unity-catalog-catalogthroughsource.catalog.databricks.relation.publishes-to-schema: targetsdatabricks.concept.unity-catalog-schemathroughsource.target.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
Relation through source.catalog
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.target
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.policy-info Source
Matches resource instances of databricks_policy_info.
Classification: databricks.concept.compute-configuration.
databricks.rule.lakebase-branch Source
Matches resource instances of databricks_postgres_branch.
Classification: databricks.concept.lakebase-branch.
Contexts
databricks.context.ownership: targetsdatabricks.concept.lakebase-projectthroughsource.parent.
Relations
databricks.relation.branched-from: targetsdatabricks.concept.lakebase-branchthroughsource.spec.source_branch.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "uid"]
Context through source.parent
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.spec.source_branch
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.lakebase-postgres-catalog Source
Matches resource instances of databricks_postgres_catalog.
Classification: databricks.concept.database-configuration.
databricks.rule.lakebase-postgres-cdf-config Source
Matches resource instances of databricks_postgres_cdf_config.
Classification: databricks.concept.database-configuration.
databricks.rule.lakebase-data-api Source
Matches resource instances of databricks_postgres_data_api.
Classification: databricks.concept.lakebase-data-api.
Contexts
rf.context.runtime: targetsdatabricks.concept.lakebase-projectthroughsource.parent.
Conditions, identity and resolution
Context through source.parent
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.lakebase-database Source
Matches resource instances of databricks_postgres_database.
Classification: databricks.concept.lakebase-database.
Contexts
databricks.context.ownership: targetsdatabricks.concept.lakebase-branchthroughsource.parent.
Conditions, identity and resolution
Context through source.parent
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.lakebase-endpoint Source
Matches resource instances of databricks_postgres_endpoint.
Classification: databricks.concept.lakebase-endpoint.
Contexts
rf.context.runtime: targetsdatabricks.concept.lakebase-branchthroughsource.parent.
Conditions, identity and resolution
Context through source.parent
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.lakebase-project Source
Matches resource instances of databricks_postgres_project.
Classification: databricks.concept.lakebase-project.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["name", "uid"]
databricks.rule.lakebase-postgres-role Source
Matches resource instances of databricks_postgres_role.
Classification: databricks.concept.database-configuration.
databricks.rule.lakebase-postgres-synced-table Source
Matches resource instances of databricks_postgres_synced_table.
Classification: databricks.concept.database-configuration.
databricks.rule.delta-sharing-provider Source
Matches resource instances of databricks_provider.
Classification: databricks.concept.delta-sharing-provider.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
databricks.rule.quality-monitor-v2 Source
Matches resource instances of databricks_quality_monitor_v2.
Classification: databricks.concept.quality-monitor.
databricks.rule.quality-monitor Source
Matches resource instances of databricks_quality_monitor.
Classification: databricks.concept.quality-monitor.
databricks.rule.query Source
Matches resource instances of databricks_query.
Classification: databricks.concept.analytics-artifact.
databricks.rule.registered-model Source
Matches resource instances of databricks_registered_model.
Classification: databricks.concept.registered-model.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-schemathroughsource.schema_name.
Conditions, identity and resolution
Context through source.schema_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.restrict-workspace-admins-setting Source
Matches resource instances of databricks_restrict_workspace_admins_setting.
Classification: databricks.concept.workspace-configuration.
databricks.rule.rfa-access-request-destinations Source
Matches resource instances of databricks_rfa_access_request_destinations.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.unity-catalog-schema Source
Matches resource instances of databricks_schema.
Classification: databricks.concept.unity-catalog-schema.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-catalogthroughsource.catalog_name.
Relations
databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.storage_root.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.catalog_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.storage_root
on_null:"absent"on_empty:"absent"
databricks.rule.secret-acl Source
Matches resource instances of databricks_secret_acl.
Classification: databricks.concept.secret-configuration.
Contributions
- targets
databricks.concept.secret-scopethroughsource.scope.
Conditions, identity and resolution
Contribution through source.scope
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.secret-scope Source
Matches resource instances of databricks_secret_scope.
Classification: databricks.concept.secret-scope.
Conditions, identity and resolution
Identity
attributes:["id", "name"]scope:"provider"
Endpoint
attributes:["id", "name"]
databricks.rule.unity-catalog-secret Source
Matches resource instances of databricks_secret_uc.
Classification: databricks.concept.secret-configuration.
databricks.rule.secret Source
Matches resource instances of databricks_secret.
Classification: databricks.concept.secret-configuration.
Contributions
- targets
databricks.concept.secret-scopethroughsource.scope.
Conditions, identity and resolution
Contribution through source.scope
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.service-principal-federation-policy Source
Matches resource instances of databricks_service_principal_federation_policy.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.service-principal-role Source
Matches resource instances of databricks_service_principal_role.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.service-principal-secret Source
Matches resource instances of databricks_service_principal_secret.
Classification: databricks.concept.secret-configuration.
databricks.rule.service-principal Source
Matches resource instances of databricks_service_principal.
Classification: rf.concept.service-identity.
Conditions, identity and resolution
Identity
attributes:["application_id", "id"]scope:"provider"
Endpoint
attributes:["application_id", "id", "acl_principal_id"]
databricks.rule.delta-share Source
Matches resource instances of databricks_share.
Classification: databricks.concept.delta-share.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
databricks.rule.sql-alert Source
Matches resource instances of databricks_sql_alert.
Classification: databricks.concept.analytics-artifact.
databricks.rule.sql-dashboard Source
Matches resource instances of databricks_sql_dashboard.
Classification: databricks.concept.analytics-artifact.
databricks.rule.sql-global-config Source
Matches resource instances of databricks_sql_global_config.
Classification: databricks.concept.sql-configuration.
databricks.rule.sql-permissions Source
Matches resource instances of databricks_sql_permissions.
Classification: databricks.concept.sql-configuration.
databricks.rule.sql-query Source
Matches resource instances of databricks_sql_query.
Classification: databricks.concept.analytics-artifact.
databricks.rule.sql-table Source
Matches resource instances of databricks_sql_table.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.sql-visualization Source
Matches resource instances of databricks_sql_visualization.
Classification: databricks.concept.analytics-artifact.
databricks.rule.sql-widget Source
Matches resource instances of databricks_sql_widget.
Classification: databricks.concept.analytics-artifact.
databricks.rule.storage-credential Source
Matches resource instances of databricks_storage_credential.
Classification: databricks.concept.storage-credential.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-metastorethroughsource.metastore_id.
Relations
databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.azure_managed_identity[0].managed_identity_id.databricks.relation.uses-cloud-identity: targetsrf.concept.service-identitythroughsource.gcp_service_account_key[0].email.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
Context through source.metastore_id
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
Relation through source.azure_managed_identity[0].managed_identity_id
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.idmatch.strategy:"exact"
Relation through source.gcp_service_account_key[0].email
on_null:"absent"on_empty:"absent"external:"allow"match.by:target.emailmatch.strategy:"exact"
databricks.rule.supervisor-agent-tool Source
Matches resource instances of databricks_supervisor_agent_tool.
Classification: databricks.concept.ml-platform-detail.
Contributions
- targets
databricks.concept.supervisor-agentthroughsource.parent.
Conditions, identity and resolution
Contribution through source.parent
on_null:"absent"on_empty:"absent"match.by:target.idmatch.strategy:"exact"
databricks.rule.supervisor-agent Source
Matches resource instances of databricks_supervisor_agent.
Classification: databricks.concept.supervisor-agent.
Conditions, identity and resolution
Identity
attributes:["id"]scope:"provider"
Endpoint
attributes:["id"]
databricks.rule.system-schema Source
Matches resource instances of databricks_system_schema.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.unity-catalog-table Source
Matches resource instances of databricks_table.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.tag-policy Source
Matches resource instances of databricks_tag_policy.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.user-instance-profile Source
Matches resource instances of databricks_user_instance_profile.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.user-role Source
Matches resource instances of databricks_user_role.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.vector-search-endpoint Source
Matches resource instances of databricks_vector_search_endpoint.
Classification: databricks.concept.vector-search-endpoint.
Conditions, identity and resolution
Identity
attributes:["name"]scope:"provider"
Endpoint
attributes:["id", "name"]
databricks.rule.vector-search-index Source
Matches resource instances of databricks_vector_search_index.
Classification: databricks.concept.vector-search-index.
Relations
databricks.relation.served-by: targetsdatabricks.concept.vector-search-endpointthroughsource.endpoint_name.
Conditions, identity and resolution
Relation through source.endpoint_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
databricks.rule.unity-catalog-volume Source
Matches resource instances of databricks_volume.
Classification: databricks.concept.unity-catalog-volume.
Contexts
databricks.context.ownership: targetsdatabricks.concept.unity-catalog-schemathroughsource.schema_name.
Relations
databricks.relation.stores-in: targetsrf.concept.object-storage-containerthroughsource.storage_location.
Conditions, identity and resolution
Context through source.schema_name
on_null:"absent"on_empty:"absent"match.by:target.namematch.strategy:"exact"
Relation through source.storage_location
on_null:"absent"on_empty:"absent"
databricks.rule.warehouses-default-warehouse-override Source
Matches resource instances of databricks_warehouses_default_warehouse_override.
Classification: databricks.concept.workspace-configuration.
databricks.rule.workspace-binding Source
Matches resource instances of databricks_workspace_binding.
Classification: databricks.concept.workspace-configuration.
databricks.rule.workspace-configuration Source
Matches resource instances of databricks_workspace_conf.
Classification: databricks.concept.workspace-configuration.
databricks.rule.workspace-entity-tag-assignment Source
Matches resource instances of databricks_workspace_entity_tag_assignment.
Classification: databricks.concept.unity-catalog-data-detail.
databricks.rule.workspace-group-member Source
Matches resource instances of databricks_workspace_iam_direct_group_member_v2.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.workspace-identity-group Source
Matches resource instances of databricks_workspace_iam_group_v2.
Classification: databricks.concept.identity-group.
databricks.rule.workspace-service-principal Source
Matches resource instances of databricks_workspace_iam_service_principal_v2.
Classification: rf.concept.service-identity.
Conditions, identity and resolution
Identity
attributes:["application_id", "service_principal_id"]scope:"provider"
Endpoint
attributes:["application_id", "service_principal_id"]
databricks.rule.workspace-identity-assignment Source
Matches resource instances of databricks_workspace_iam_workspace_assignment_v2.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.workspace-identity-detail Source
Matches resource instances of databricks_workspace_iam_workspace_identity_detail_v2.
Classification: databricks.concept.identity-access-configuration.
databricks.rule.workspace-network-option Source
Matches resource instances of databricks_workspace_network_option.
Classification: databricks.concept.workspace-configuration.
databricks.rule.workspace-setting Source
Matches resource instances of databricks_workspace_setting_v2.
Classification: databricks.concept.workspace-configuration.