Skip to content
Version and compatibility

Version: 0.1.0.

Provider bindings and declared compatibility

  • databricks/databricks: = 1.129.0.

All official Dialects

Interpreted types

Each row identifies a type and instance kind. Conditional Rules retain their individual conditions in the details below.

Terraform typeKindClassificationRules
databricks_access_control_rule_setresourceidentity-access-configurationaccess-control-rule-set
databricks_account_federation_policyresourceidentity-access-configurationaccount-federation-policy
databricks_account_iam_direct_group_member_v2resourceidentity-access-configurationaccount-group-member
databricks_account_iam_group_v2resourceidentity-groupaccount-identity-group
databricks_account_iam_service_principal_v2resourceservice-identityaccount-service-principal
databricks_account_iam_workspace_assignment_v2resourceidentity-access-configurationaccount-workspace-assignment
databricks_account_network_policyresourcenetwork-security-configurationaccount-network-policy
databricks_account_setting_v2resourceworkspace-configurationaccount-setting
databricks_ai_gateway_mcp_serviceresourceai-gateway-serviceai-gateway-mcp-service
databricks_ai_gateway_model_provider_serviceresourceai-gateway-serviceai-gateway-model-provider-service
databricks_ai_gateway_model_serviceresourceai-gateway-serviceai-gateway-model-service
databricks_ai_search_endpointresourceai-search-endpointai-search-endpoint
databricks_ai_search_indexresourceai-search-indexai-search-index
databricks_aibi_dashboard_embedding_access_policy_settingresourceapplication-configurationdashboard-embedding-access-policy
databricks_aibi_dashboard_embedding_approved_domains_settingresourceapplication-configurationdashboard-embedding-approved-domains
databricks_alert_v2resourceanalytics-artifactalert-v2
databricks_alertresourceanalytics-artifactalert
databricks_apps_settings_custom_templateresourceapplication-configurationapps-custom-template
databricks_artifact_allowlistresourcecompute-configurationartifact-allowlist
databricks_automatic_cluster_update_workspace_settingresourceworkspace-configurationautomatic-cluster-update-setting
databricks_aws_s3_mountresourcelegacy-storage-mountaws-s3-mount
databricks_azure_adls_gen1_mountresourcelegacy-storage-mountazure-adls-gen1-mount
databricks_azure_adls_gen2_mountresourcelegacy-storage-mountazure-adls-gen2-mount
databricks_azure_blob_mountresourcelegacy-storage-mountazure-blob-mount
databricks_catalog_workspace_bindingresourceunity-catalog-access-detailcatalog-workspace-binding
databricks_catalogresourceunity-catalog-catalogunity-catalog-catalog
databricks_cluster_policyresourcecompute-configurationcluster-policy
databricks_clusterresourcecompute-clustercompute-cluster
databricks_compliance_security_profile_workspace_settingresourceworkspace-configurationcompliance-security-profile-setting
databricks_connectionresourcelakehouse-federation-connectionlakehouse-federation-connection
databricks_credentialresourceservice-credentialservice-credential
databricks_dashboardresourceanalytics-artifactdashboard
databricks_data_classification_catalog_configresourceunity-catalog-data-detaildata-classification-catalog-config
databricks_data_quality_monitorresourcequality-monitordata-quality-monitor
databricks_database_database_catalogresourcedatabase-configurationlakebase-provisioned-catalog
databricks_database_instanceresourcemanaged-databaselakebase-provisioned-instance
databricks_database_synced_database_tableresourcedatabase-configurationlakebase-provisioned-synced-table
databricks_default_namespace_settingresourceworkspace-configurationdefault-namespace-setting
databricks_disable_legacy_access_settingresourceworkspace-configurationdisable-legacy-access-setting
databricks_disable_legacy_dbfs_settingresourceworkspace-configurationdisable-legacy-dbfs-setting
databricks_disable_legacy_features_settingresourceworkspace-configurationdisable-legacy-features-setting
databricks_disaster_recovery_stable_urlresourceworkspace-configurationdisaster-recovery-stable-url
databricks_endpointresourceprivate-endpoint-registrationservice-direct-endpoint
databricks_enhanced_security_monitoring_workspace_settingresourceworkspace-configurationenhanced-security-monitoring-setting
databricks_entitlementsresourceidentity-access-configurationentitlements
databricks_entity_tag_assignmentresourceunity-catalog-data-detailentity-tag-assignment
databricks_environments_default_workspace_base_environmentresourcecompute-configurationdefault-workspace-base-environment
databricks_environments_workspace_base_environmentresourcecompute-configurationworkspace-base-environment
databricks_external_locationresourceexternal-locationexternal-location
databricks_external_metadataresourceunity-catalog-data-detailexternal-metadata
databricks_feature_engineering_featureresourceml-platform-detailfeature-engineering-feature
databricks_feature_engineering_kafka_configresourceml-platform-detailfeature-engineering-kafka-config
databricks_feature_engineering_materialized_featureresourceml-platform-detailfeature-engineering-materialized-feature
databricks_global_init_scriptresourcecompute-configurationglobal-init-script
databricks_grantresourceidentity-access-configurationgrant
databricks_grantsresourceidentity-access-configurationgrants
databricks_group_instance_profileresourceidentity-access-configurationgroup-instance-profile
databricks_group_memberresourceidentity-access-configurationgroup-member
databricks_group_roleresourceidentity-access-configurationgroup-role
databricks_groupresourceidentity-groupidentity-group
databricks_instance_poolresourceinstance-poolinstance-pool
databricks_instance_profileresourcecompute-configurationinstance-profile
databricks_ip_access_listresourcenetwork-security-configurationip-access-list
databricks_jobresourceworkflowlakeflow-job
databricks_knowledge_assistant_knowledge_sourceresourceml-platform-detailknowledge-assistant-source
databricks_knowledge_assistantresourceknowledge-assistantknowledge-assistant
databricks_lakehouse_monitorresourcequality-monitorlakehouse-monitor
databricks_libraryresourcecompute-configurationcluster-library
databricks_materialized_features_feature_tagresourceml-platform-detailmaterialized-feature-tag
databricks_metastore_assignmentresourceunity-catalog-access-detailmetastore-assignment
databricks_metastore_data_accessresourcestorage-credentialmetastore-data-access
databricks_metastoreresourceunity-catalog-metastoreunity-catalog-metastore
databricks_mlflow_experimentresourceml-platform-detailmlflow-experiment
databricks_mlflow_modelresourceml-platform-detailmlflow-model
databricks_mlflow_webhookresourceml-platform-detailmlflow-webhook
databricks_model_serving_provisioned_throughputresourceai-inference-endpointmodel-serving-provisioned-throughput
databricks_model_servingresourceai-inference-endpointmodel-serving
databricks_mountresourcelegacy-storage-mountmount
databricks_mws_credentialsresourceworkspace-deployment-credentialworkspace-deployment-credential
databricks_mws_log_deliveryresourcelog-deliverylog-delivery
databricks_mws_ncc_bindingresourcenetwork-bindingnetwork-connectivity-binding
databricks_mws_ncc_private_endpoint_ruleresourceprivate-endpoint-ruleprivate-endpoint-rule
databricks_mws_network_connectivity_configresourcenetwork-connectivity-configurationnetwork-connectivity-configuration
databricks_mws_networksresourceworkspace-network-configurationworkspace-network-configuration
databricks_mws_permission_assignmentresourceidentity-access-configurationmws-permission-assignment
databricks_mws_private_access_settingsresourceprivate-access-settingsprivate-access-settings
databricks_mws_storage_configurationsresourceworkspace-root-storageworkspace-root-storage
databricks_mws_vpc_endpointresourceprivate-endpoint-registrationvpc-endpoint-registration
databricks_mws_workspacesresourceworkspaceworkspace
databricks_online_tableresourceonline-serving-configurationonline-table
databricks_permission_assignmentresourceidentity-access-configurationpermission-assignment
databricks_permissionsresourceidentity-access-configurationpermissions
databricks_pipelineresourcelakeflow-pipelinelakeflow-pipeline
databricks_policy_inforesourcecompute-configurationpolicy-info
databricks_postgres_branchresourcelakebase-branchlakebase-branch
databricks_postgres_catalogresourcedatabase-configurationlakebase-postgres-catalog
databricks_postgres_cdf_configresourcedatabase-configurationlakebase-postgres-cdf-config
databricks_postgres_data_apiresourcelakebase-data-apilakebase-data-api
databricks_postgres_databaseresourcelakebase-databaselakebase-database
databricks_postgres_endpointresourcelakebase-endpointlakebase-endpoint
databricks_postgres_projectresourcelakebase-projectlakebase-project
databricks_postgres_roleresourcedatabase-configurationlakebase-postgres-role
databricks_postgres_synced_tableresourcedatabase-configurationlakebase-postgres-synced-table
databricks_providerresourcedelta-sharing-providerdelta-sharing-provider
databricks_quality_monitor_v2resourcequality-monitorquality-monitor-v2
databricks_quality_monitorresourcequality-monitorquality-monitor
databricks_queryresourceanalytics-artifactquery
databricks_registered_modelresourceregistered-modelregistered-model
databricks_restrict_workspace_admins_settingresourceworkspace-configurationrestrict-workspace-admins-setting
databricks_rfa_access_request_destinationsresourceidentity-access-configurationrfa-access-request-destinations
databricks_schemaresourceunity-catalog-schemaunity-catalog-schema
databricks_secret_aclresourcesecret-configurationsecret-acl
databricks_secret_scoperesourcesecret-scopesecret-scope
databricks_secret_ucresourcesecret-configurationunity-catalog-secret
databricks_secretresourcesecret-configurationsecret
databricks_service_principal_federation_policyresourceidentity-access-configurationservice-principal-federation-policy
databricks_service_principal_roleresourceidentity-access-configurationservice-principal-role
databricks_service_principal_secretresourcesecret-configurationservice-principal-secret
databricks_service_principalresourceservice-identityservice-principal
databricks_shareresourcedelta-sharedelta-share
databricks_sql_alertresourceanalytics-artifactsql-alert
databricks_sql_dashboardresourceanalytics-artifactsql-dashboard
databricks_sql_global_configresourcesql-configurationsql-global-config
databricks_sql_permissionsresourcesql-configurationsql-permissions
databricks_sql_queryresourceanalytics-artifactsql-query
databricks_sql_tableresourceunity-catalog-data-detailsql-table
databricks_sql_visualizationresourceanalytics-artifactsql-visualization
databricks_sql_widgetresourceanalytics-artifactsql-widget
databricks_storage_credentialresourcestorage-credentialstorage-credential
databricks_supervisor_agent_toolresourceml-platform-detailsupervisor-agent-tool
databricks_supervisor_agentresourcesupervisor-agentsupervisor-agent
databricks_system_schemaresourceunity-catalog-data-detailsystem-schema
databricks_tableresourceunity-catalog-data-detailunity-catalog-table
databricks_tag_policyresourceunity-catalog-data-detailtag-policy
databricks_user_instance_profileresourceidentity-access-configurationuser-instance-profile
databricks_user_roleresourceidentity-access-configurationuser-role
databricks_vector_search_endpointresourcevector-search-endpointvector-search-endpoint
databricks_vector_search_indexresourcevector-search-indexvector-search-index
databricks_volumeresourceunity-catalog-volumeunity-catalog-volume
databricks_warehouses_default_warehouse_overrideresourceworkspace-configurationwarehouses-default-warehouse-override
databricks_workspace_bindingresourceworkspace-configurationworkspace-binding
databricks_workspace_confresourceworkspace-configurationworkspace-configuration
databricks_workspace_entity_tag_assignmentresourceunity-catalog-data-detailworkspace-entity-tag-assignment
databricks_workspace_iam_direct_group_member_v2resourceidentity-access-configurationworkspace-group-member
databricks_workspace_iam_group_v2resourceidentity-groupworkspace-identity-group
databricks_workspace_iam_service_principal_v2resourceservice-identityworkspace-service-principal
databricks_workspace_iam_workspace_assignment_v2resourceidentity-access-configurationworkspace-identity-assignment
databricks_workspace_iam_workspace_identity_detail_v2resourceidentity-access-configurationworkspace-identity-detail
databricks_workspace_network_optionresourceworkspace-configurationworkspace-network-option
databricks_workspace_setting_v2resourceworkspace-configurationworkspace-setting

Local vocabulary

Concepts

databricks.concept.ai-gateway-service Source

A governed Mosaic AI Gateway service for models, model providers, or MCP tools.

Used by ai-gateway-mcp-service, ai-gateway-model-provider-service, ai-gateway-model-service.

databricks.concept.ai-inference-endpoint Source

A managed endpoint that serves model inference requests.

Used by model-serving, model-serving-provisioned-throughput.

databricks.concept.ai-search-endpoint Source

A Mosaic AI Search endpoint providing managed search capacity.

Used by ai-search-endpoint, ai-search-index.

databricks.concept.ai-search-index Source

A governed Mosaic AI Search index.

Used by ai-search-index.

databricks.concept.analytics-artifact Source

A dashboard, query, alert, visualization, or widget presented through Databricks analytics.

Used by 9 Rules
databricks.concept.application-configuration Source

A template, embedding, or deployment configuration supporting Databricks applications.

Used by apps-custom-template, dashboard-embedding-access-policy, dashboard-embedding-approved-domains.

databricks.concept.compute-cluster Source

A Databricks compute cluster running data, analytics, or machine-learning workloads.

Used by cluster-library, compute-cluster, lakeflow-job.

databricks.concept.compute-configuration Source

A policy, library, environment, identity registration, or setting supporting Databricks compute.

Used by 8 Rules
databricks.concept.database-configuration Source

A database, role, synchronization, catalog, or change-data configuration supporting Lakebase.

Used by 6 Rules
databricks.concept.delta-share Source

A governed collection of data assets shared through Delta Sharing.

Used by delta-share, unity-catalog-catalog.

databricks.concept.delta-sharing-provider Source

An external organization providing data through Delta Sharing.

Used by delta-sharing-provider, unity-catalog-catalog.

databricks.concept.external-location Source

A Unity Catalog external location pairing a cloud storage path with a storage credential.

Used by external-location.

databricks.concept.identity-group Source

A managed group principal used to assign access collectively.

Used by account-identity-group, identity-group, workspace-identity-group.

databricks.concept.instance-pool Source

A shared pool of cloud instances used to reduce Databricks cluster start time.

Used by compute-cluster, instance-pool.

databricks.concept.knowledge-assistant Source

A Databricks Knowledge Assistant grounded in governed enterprise knowledge.

Used by knowledge-assistant, knowledge-assistant-source.

databricks.concept.lakebase-branch Source

An isolated Lakebase database environment sharing project storage through copy-on-write.

Used by lakebase-branch, lakebase-database, lakebase-endpoint.

databricks.concept.lakebase-data-api Source

A Lakebase Data API exposing governed database access.

Used by lakebase-data-api.

databricks.concept.lakebase-database Source

A logical Postgres database contained by a Lakebase branch.

Used by lakebase-database.

databricks.concept.lakebase-endpoint Source

A Lakebase Postgres compute endpoint providing read-write or read-only database access.

Used by lakebase-endpoint.

databricks.concept.lakebase-project Source

A Lakebase Autoscaling project containing branches, Postgres compute endpoints, and databases.

Used by lakebase-branch, lakebase-data-api, lakebase-project.

databricks.concept.lakeflow-pipeline Source

A Lakeflow pipeline running declarative batch or streaming data processing.

Used by lakeflow-pipeline, online-table.

databricks.concept.lakehouse-federation-connection Source

A Unity Catalog connection to an external data system for Lakehouse Federation.

Used by lakehouse-federation-connection, unity-catalog-catalog.

databricks.concept.legacy-storage-mount Source

A legacy DBFS mount configuration linking Databricks to cloud object storage.

Used by 5 Rules
databricks.concept.log-delivery Source

A Databricks account or workspace log-delivery configuration.

Used by log-delivery.

databricks.concept.ml-platform-detail Source

An experiment, model version, agent tool, feature, or ML configuration supporting Databricks AI and ML.

Used by 9 Rules
databricks.concept.network-binding Source

A binding attaching Databricks serverless network configuration to a workspace.

Used by network-connectivity-binding.

databricks.concept.network-connectivity-configuration Source

A regional Databricks network connectivity configuration for serverless workloads.

Used by 4 Rules
databricks.concept.network-security-configuration Source

Network policy or access configuration supporting Databricks connectivity.

Used by account-network-policy, ip-access-list.

databricks.concept.online-serving-configuration Source

An online table or feature-serving configuration supporting Databricks online serving.

Used by online-table.

databricks.concept.orchestration-configuration Source

A task, query, repository, or environment artifact supporting Databricks orchestration.

No Rule in this Dialect uses this definition.

databricks.concept.private-access-settings Source

Databricks private access settings controlling private workspace ingress.

Used by private-access-settings, workspace.

databricks.concept.private-endpoint-registration Source

A Databricks registration of a cloud private connectivity endpoint.

Used by service-direct-endpoint, vpc-endpoint-registration.

databricks.concept.private-endpoint-rule Source

A Databricks rule provisioning private connectivity from serverless compute to a cloud resource.

Used by private-endpoint-rule.

databricks.concept.quality-monitor Source

A Databricks monitor evaluating data or model quality over time.

Used by 4 Rules
databricks.concept.registered-model Source

A governed machine-learning model registered in Unity Catalog.

Used by registered-model.

databricks.concept.secret-configuration Source

A secret identity or access configuration whose value remains outside architecture output.

Used by 4 Rules
databricks.concept.secret-scope Source

A Databricks secret scope grouping sensitive configuration without exposing secret values.

Used by secret, secret-acl, secret-scope.

databricks.concept.service-credential Source

A Unity Catalog credential authorizing access to a cloud service.

Used by service-credential.

databricks.concept.sharing-configuration Source

A sharing, provider, recipient, or catalog integration configuration.

No Rule in this Dialect uses this definition.

databricks.concept.sql-configuration Source

Configuration or access control supporting Databricks SQL.

Used by sql-global-config, sql-permissions.

databricks.concept.storage-credential Source

A Unity Catalog credential authorizing access to cloud storage.

Used by external-location, metastore-data-access, storage-credential.

databricks.concept.supervisor-agent Source

A Databricks supervisor agent coordinating governed tools and specialist agents.

Used by supervisor-agent, supervisor-agent-tool.

databricks.concept.unity-catalog-access-detail Source

An assignment, binding, or access configuration supporting Unity Catalog.

Used by catalog-workspace-binding, metastore-assignment.

databricks.concept.unity-catalog-catalog Source

A Unity Catalog catalog organizing governed data and AI assets.

Used by lakeflow-pipeline, unity-catalog-catalog, unity-catalog-schema.

databricks.concept.unity-catalog-data-detail Source

A governed data object or configuration within Unity Catalog.

Used by 8 Rules
databricks.concept.unity-catalog-metastore Source

A regional Unity Catalog metastore governing Databricks data and AI assets.

Used by 8 Rules
databricks.concept.unity-catalog-schema Source

A Unity Catalog schema organizing tables, volumes, models, and functions within a catalog.

Used by 4 Rules
databricks.concept.unity-catalog-volume Source

A Unity Catalog volume governing file storage for non-tabular data.

Used by unity-catalog-volume.

databricks.concept.vector-search-endpoint Source

A Mosaic AI Vector Search endpoint providing compute for vector indexes.

Used by vector-search-endpoint, vector-search-index.

databricks.concept.vector-search-index Source

A governed vector index served through Mosaic AI Vector Search.

Used by vector-search-index.

databricks.concept.workflow Source

A managed workflow coordinating steps and service calls.

Used by lakeflow-job.

databricks.concept.workspace Source

A Databricks workspace providing an isolated environment for data, analytics, and AI workloads.

Used by metastore-assignment, network-connectivity-binding, workspace.

databricks.concept.workspace-deployment-credential Source

A cloud identity registration used to deploy Databricks workspace resources.

Used by log-delivery, workspace, workspace-deployment-credential.

databricks.concept.workspace-network-configuration Source

A Databricks registration of customer-managed workspace network infrastructure.

Used by workspace, workspace-network-configuration.

databricks.concept.workspace-root-storage Source

A cloud storage registration used as root storage by Databricks workspaces.

Used by log-delivery, workspace, workspace-root-storage.

Contexts

Relations

databricks.relation.branched-from Source

Introduced by a labeled emission. Used by lakebase-branch, lakebase-provisioned-instance.

databricks.relation.connects-to-storage Source

Introduced by a labeled emission. Used by private-endpoint-rule.

databricks.relation.delivers-to Source

Introduced by a labeled emission. Used by log-delivery.

databricks.relation.federates-through Source

Introduced by a labeled emission. Used by unity-catalog-catalog.

databricks.relation.imports-from-provider Source

Introduced by a labeled emission. Used by unity-catalog-catalog.

databricks.relation.imports-share Source

Introduced by a labeled emission. Used by unity-catalog-catalog.

databricks.relation.publishes-to-catalog Source

Introduced by a labeled emission. Used by lakeflow-pipeline.

databricks.relation.publishes-to-schema Source

Introduced by a labeled emission. Used by lakeflow-pipeline.

databricks.relation.runs-on Source

Introduced by a labeled emission. Used by lakeflow-job.

databricks.relation.served-by Source

Introduced by a labeled emission. Used by ai-search-index, vector-search-index.

databricks.relation.stores-in Source

Introduced by a labeled emission.

Used by 6 Rules
databricks.relation.uses-cloud-identity Source

Introduced by a labeled emission.

Used by 4 Rules
databricks.relation.uses-cloud-network Source

Introduced by a labeled emission. Used by workspace-network-configuration.

databricks.relation.uses-credential Source

Introduced by a labeled emission. Used by external-location.

databricks.relation.uses-deployment-credential Source

Introduced by a labeled emission. Used by log-delivery, workspace.

databricks.relation.uses-driver-pool Source

Introduced by a labeled emission. Used by compute-cluster.

databricks.relation.uses-network Source

Introduced by a labeled emission. Used by workspace.

databricks.relation.uses-pool Source

Introduced by a labeled emission. Used by compute-cluster.

databricks.relation.uses-private-access Source

Introduced by a labeled emission. Used by workspace.

databricks.relation.uses-root-storage Source

Introduced by a labeled emission. Used by workspace.

databricks.relation.uses-serverless-network Source

Introduced by a labeled emission. Used by workspace.

RF Vocabulary used

Rule details

Open a Rule for its declared behavior and source. Matching, emission resolution and composition define how evidence can establish it.

databricks.rule.access-control-rule-set Source

Matches resource instances of databricks_access_control_rule_set.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.account-federation-policy Source

Matches resource instances of databricks_account_federation_policy.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.account-group-member Source

Matches resource instances of databricks_account_iam_direct_group_member_v2.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.account-identity-group Source

Matches resource instances of databricks_account_iam_group_v2.

Classification: databricks.concept.identity-group.

databricks.rule.account-service-principal Source

Matches resource instances of databricks_account_iam_service_principal_v2.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["application_id", "service_principal_id"]
  • scope: "provider"

Endpoint

  • attributes: ["application_id", "service_principal_id"]
databricks.rule.account-workspace-assignment Source

Matches resource instances of databricks_account_iam_workspace_assignment_v2.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.account-network-policy Source

Matches resource instances of databricks_account_network_policy.

Classification: databricks.concept.network-security-configuration.

databricks.rule.account-setting Source

Matches resource instances of databricks_account_setting_v2.

Classification: databricks.concept.workspace-configuration.

databricks.rule.ai-gateway-mcp-service Source

Matches resource instances of databricks_ai_gateway_mcp_service.

Classification: databricks.concept.ai-gateway-service.

databricks.rule.ai-gateway-model-provider-service Source

Matches resource instances of databricks_ai_gateway_model_provider_service.

Classification: databricks.concept.ai-gateway-service.

databricks.rule.ai-gateway-model-service Source

Matches resource instances of databricks_ai_gateway_model_service.

Classification: databricks.concept.ai-gateway-service.

databricks.rule.ai-search-endpoint Source

Matches resource instances of databricks_ai_search_endpoint.

Classification: databricks.concept.ai-search-endpoint.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
databricks.rule.ai-search-index Source

Matches resource instances of databricks_ai_search_index.

Classification: databricks.concept.ai-search-index.

Relations

Conditions, identity and resolution

Relation through source.endpoint

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.dashboard-embedding-access-policy Source

Matches resource instances of databricks_aibi_dashboard_embedding_access_policy_setting.

Classification: databricks.concept.application-configuration.

databricks.rule.dashboard-embedding-approved-domains Source

Matches resource instances of databricks_aibi_dashboard_embedding_approved_domains_setting.

Classification: databricks.concept.application-configuration.

databricks.rule.alert-v2 Source

Matches resource instances of databricks_alert_v2.

Classification: databricks.concept.analytics-artifact.

databricks.rule.alert Source

Matches resource instances of databricks_alert.

Classification: databricks.concept.analytics-artifact.

databricks.rule.apps-custom-template Source

Matches resource instances of databricks_apps_settings_custom_template.

Classification: databricks.concept.application-configuration.

databricks.rule.artifact-allowlist Source

Matches resource instances of databricks_artifact_allowlist.

Classification: databricks.concept.compute-configuration.

databricks.rule.automatic-cluster-update-setting Source

Matches resource instances of databricks_automatic_cluster_update_workspace_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.aws-s3-mount Source

Matches resource instances of databricks_aws_s3_mount.

Classification: databricks.concept.legacy-storage-mount.

databricks.rule.azure-adls-gen1-mount Source

Matches resource instances of databricks_azure_adls_gen1_mount.

Classification: databricks.concept.legacy-storage-mount.

databricks.rule.azure-adls-gen2-mount Source

Matches resource instances of databricks_azure_adls_gen2_mount.

Classification: databricks.concept.legacy-storage-mount.

databricks.rule.azure-blob-mount Source

Matches resource instances of databricks_azure_blob_mount.

Classification: databricks.concept.legacy-storage-mount.

databricks.rule.catalog-workspace-binding Source

Matches resource instances of databricks_catalog_workspace_binding.

Classification: databricks.concept.unity-catalog-access-detail.

databricks.rule.unity-catalog-catalog Source

Matches resource instances of databricks_catalog.

Classification: databricks.concept.unity-catalog-catalog.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.storage_root

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.connection_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.provider_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.share_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.cluster-policy Source

Matches resource instances of databricks_cluster_policy.

Classification: databricks.concept.compute-configuration.

databricks.rule.compute-cluster Source

Matches resource instances of databricks_cluster.

Classification: databricks.concept.compute-cluster.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Relation through source.instance_pool_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.driver_instance_pool_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.gcp_attributes[0].google_service_account

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.compliance-security-profile-setting Source

Matches resource instances of databricks_compliance_security_profile_workspace_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.lakehouse-federation-connection Source

Matches resource instances of databricks_connection.

Classification: databricks.concept.lakehouse-federation-connection.

Contexts

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.service-credential Source

Matches resource instances of databricks_credential.

Classification: databricks.concept.service-credential.

Contexts

Relations

Conditions, identity and resolution

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.azure_managed_identity[0].managed_identity_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.dashboard Source

Matches resource instances of databricks_dashboard.

Classification: databricks.concept.analytics-artifact.

databricks.rule.data-classification-catalog-config Source

Matches resource instances of databricks_data_classification_catalog_config.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.data-quality-monitor Source

Matches resource instances of databricks_data_quality_monitor.

Classification: databricks.concept.quality-monitor.

databricks.rule.lakebase-provisioned-catalog Source

Matches resource instances of databricks_database_database_catalog.

Classification: databricks.concept.database-configuration.

databricks.rule.lakebase-provisioned-instance Source

Matches resource instances of databricks_database_instance.

Classification: rf.concept.managed-database.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "uid"]

Relation through source.parent_instance_ref.name

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.lakebase-provisioned-synced-table Source

Matches resource instances of databricks_database_synced_database_table.

Classification: databricks.concept.database-configuration.

databricks.rule.default-namespace-setting Source

Matches resource instances of databricks_default_namespace_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.disable-legacy-access-setting Source

Matches resource instances of databricks_disable_legacy_access_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.disable-legacy-dbfs-setting Source

Matches resource instances of databricks_disable_legacy_dbfs_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.disable-legacy-features-setting Source

Matches resource instances of databricks_disable_legacy_features_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.disaster-recovery-stable-url Source

Matches resource instances of databricks_disaster_recovery_stable_url.

Classification: databricks.concept.workspace-configuration.

databricks.rule.service-direct-endpoint Source

Matches resource instances of databricks_endpoint.

Classification: databricks.concept.private-endpoint-registration.

databricks.rule.enhanced-security-monitoring-setting Source

Matches resource instances of databricks_enhanced_security_monitoring_workspace_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.entitlements Source

Matches resource instances of databricks_entitlements.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.entity-tag-assignment Source

Matches resource instances of databricks_entity_tag_assignment.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.default-workspace-base-environment Source

Matches resource instances of databricks_environments_default_workspace_base_environment.

Classification: databricks.concept.compute-configuration.

databricks.rule.workspace-base-environment Source

Matches resource instances of databricks_environments_workspace_base_environment.

Classification: databricks.concept.compute-configuration.

databricks.rule.external-location Source

Matches resource instances of databricks_external_location.

Classification: databricks.concept.external-location.

Contexts

Relations

Conditions, identity and resolution

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.credential_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.url

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.external-metadata Source

Matches resource instances of databricks_external_metadata.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.feature-engineering-feature Source

Matches resource instances of databricks_feature_engineering_feature.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.feature-engineering-kafka-config Source

Matches resource instances of databricks_feature_engineering_kafka_config.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.feature-engineering-materialized-feature Source

Matches resource instances of databricks_feature_engineering_materialized_feature.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.global-init-script Source

Matches resource instances of databricks_global_init_script.

Classification: databricks.concept.compute-configuration.

databricks.rule.grant Source

Matches resource instances of databricks_grant.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.grants Source

Matches resource instances of databricks_grants.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.group-instance-profile Source

Matches resource instances of databricks_group_instance_profile.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.group-member Source

Matches resource instances of databricks_group_member.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.group-role Source

Matches resource instances of databricks_group_role.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.identity-group Source

Matches resource instances of databricks_group.

Classification: databricks.concept.identity-group.

databricks.rule.instance-pool Source

Matches resource instances of databricks_instance_pool.

Classification: databricks.concept.instance-pool.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
databricks.rule.instance-profile Source

Matches resource instances of databricks_instance_profile.

Classification: databricks.concept.compute-configuration.

databricks.rule.ip-access-list Source

Matches resource instances of databricks_ip_access_list.

Classification: databricks.concept.network-security-configuration.

databricks.rule.lakeflow-job Source

Matches resource instances of databricks_job.

Classification: databricks.concept.workflow.

Relations

Conditions, identity and resolution

Relation through source.existing_cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.knowledge-assistant-source Source

Matches resource instances of databricks_knowledge_assistant_knowledge_source.

Classification: databricks.concept.ml-platform-detail.

Contributions

Conditions, identity and resolution

Contribution through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.knowledge-assistant Source

Matches resource instances of databricks_knowledge_assistant.

Classification: databricks.concept.knowledge-assistant.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
databricks.rule.lakehouse-monitor Source

Matches resource instances of databricks_lakehouse_monitor.

Classification: databricks.concept.quality-monitor.

databricks.rule.cluster-library Source

Matches resource instances of databricks_library.

Classification: databricks.concept.compute-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.cluster_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.materialized-feature-tag Source

Matches resource instances of databricks_materialized_features_feature_tag.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.metastore-assignment Source

Matches resource instances of databricks_metastore_assignment.

Classification: databricks.concept.unity-catalog-access-detail.

Contributions

Conditions, identity and resolution

Contribution through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Contribution through source.workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.workspace_id
  • match.strategy: "exact"
databricks.rule.metastore-data-access Source

Matches resource instances of databricks_metastore_data_access.

Classification: databricks.concept.storage-credential.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.azure_managed_identity[0].managed_identity_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.gcp_service_account_key[0].email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
databricks.rule.unity-catalog-metastore Source

Matches resource instances of databricks_metastore.

Classification: databricks.concept.unity-catalog-metastore.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Relation through source.storage_root

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.mlflow-experiment Source

Matches resource instances of databricks_mlflow_experiment.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.mlflow-model Source

Matches resource instances of databricks_mlflow_model.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.mlflow-webhook Source

Matches resource instances of databricks_mlflow_webhook.

Classification: databricks.concept.ml-platform-detail.

databricks.rule.model-serving-provisioned-throughput Source

Matches resource instances of databricks_model_serving_provisioned_throughput.

Classification: databricks.concept.ai-inference-endpoint.

databricks.rule.model-serving Source

Matches resource instances of databricks_model_serving.

Classification: databricks.concept.ai-inference-endpoint.

databricks.rule.mount Source

Matches resource instances of databricks_mount.

Classification: databricks.concept.legacy-storage-mount.

databricks.rule.workspace-deployment-credential Source

Matches resource instances of databricks_mws_credentials.

Classification: databricks.concept.workspace-deployment-credential.

Conditions, identity and resolution

Identity

  • attributes: ["id", "credentials_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "credentials_id"]
databricks.rule.log-delivery Source

Matches resource instances of databricks_mws_log_delivery.

Classification: databricks.concept.log-delivery.

Relations

Conditions, identity and resolution

Relation through source.storage_configuration_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.storage_configuration_id
  • match.strategy: "exact"

Relation through source.credentials_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.credentials_id
  • match.strategy: "exact"
databricks.rule.network-connectivity-binding Source

Matches resource instances of databricks_mws_ncc_binding.

Classification: databricks.concept.network-binding.

Contributions

Conditions, identity and resolution

Contribution through source.network_connectivity_config_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.network_connectivity_config_id
  • match.strategy: "exact"

Contribution through source.workspace_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.workspace_id
  • match.strategy: "exact"
databricks.rule.private-endpoint-rule Source

Matches resource instances of databricks_mws_ncc_private_endpoint_rule.

Classification: databricks.concept.private-endpoint-rule.

Contexts

Relations

Conditions, identity and resolution

Context through source.network_connectivity_config_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.network_connectivity_config_id
  • match.strategy: "exact"

Relation through source.resource_id

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.network-connectivity-configuration Source

Matches resource instances of databricks_mws_network_connectivity_config.

Classification: databricks.concept.network-connectivity-configuration.

Conditions, identity and resolution

Identity

  • attributes: ["id", "network_connectivity_config_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "network_connectivity_config_id"]
databricks.rule.workspace-network-configuration Source

Matches resource instances of databricks_mws_networks.

Classification: databricks.concept.workspace-network-configuration.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "network_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "network_id"]

Relation through source.vpc_id

  • on_null: "absent"
  • on_empty: "absent"

Relation through source.gcp_network_info[0].vpc_id

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.mws-permission-assignment Source

Matches resource instances of databricks_mws_permission_assignment.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.private-access-settings Source

Matches resource instances of databricks_mws_private_access_settings.

Classification: databricks.concept.private-access-settings.

Conditions, identity and resolution

Identity

  • attributes: ["id", "private_access_settings_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "private_access_settings_id"]
databricks.rule.workspace-root-storage Source

Matches resource instances of databricks_mws_storage_configurations.

Classification: databricks.concept.workspace-root-storage.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "storage_configuration_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "storage_configuration_id"]

Relation through source.bucket_name

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.vpc-endpoint-registration Source

Matches resource instances of databricks_mws_vpc_endpoint.

Classification: databricks.concept.private-endpoint-registration.

databricks.rule.workspace Source

Matches resource instances of databricks_mws_workspaces.

Classification: databricks.concept.workspace.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "workspace_id"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "workspace_id"]

Relation through source.network_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.network_id
  • match.strategy: "exact"

Relation through source.storage_configuration_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.storage_configuration_id
  • match.strategy: "exact"

Relation through source.credentials_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.credentials_id
  • match.strategy: "exact"

Relation through source.private_access_settings_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.private_access_settings_id
  • match.strategy: "exact"

Relation through source.network_connectivity_config_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.network_connectivity_config_id
  • match.strategy: "exact"
databricks.rule.online-table Source

Matches resource instances of databricks_online_table.

Classification: databricks.concept.online-serving-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.spec[0].pipeline_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.permission-assignment Source

Matches resource instances of databricks_permission_assignment.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.permissions Source

Matches resource instances of databricks_permissions.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.lakeflow-pipeline Source

Matches resource instances of databricks_pipeline.

Classification: databricks.concept.lakeflow-pipeline.

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]

Relation through source.catalog

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.target

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.policy-info Source

Matches resource instances of databricks_policy_info.

Classification: databricks.concept.compute-configuration.

databricks.rule.lakebase-branch Source

Matches resource instances of databricks_postgres_branch.

Classification: databricks.concept.lakebase-branch.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "uid"]

Context through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.spec.source_branch

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.lakebase-postgres-catalog Source

Matches resource instances of databricks_postgres_catalog.

Classification: databricks.concept.database-configuration.

databricks.rule.lakebase-postgres-cdf-config Source

Matches resource instances of databricks_postgres_cdf_config.

Classification: databricks.concept.database-configuration.

databricks.rule.lakebase-data-api Source

Matches resource instances of databricks_postgres_data_api.

Classification: databricks.concept.lakebase-data-api.

Contexts

Conditions, identity and resolution

Context through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.lakebase-database Source

Matches resource instances of databricks_postgres_database.

Classification: databricks.concept.lakebase-database.

Contexts

Conditions, identity and resolution

Context through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.lakebase-endpoint Source

Matches resource instances of databricks_postgres_endpoint.

Classification: databricks.concept.lakebase-endpoint.

Contexts

Conditions, identity and resolution

Context through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.lakebase-project Source

Matches resource instances of databricks_postgres_project.

Classification: databricks.concept.lakebase-project.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["name", "uid"]
databricks.rule.lakebase-postgres-role Source

Matches resource instances of databricks_postgres_role.

Classification: databricks.concept.database-configuration.

databricks.rule.lakebase-postgres-synced-table Source

Matches resource instances of databricks_postgres_synced_table.

Classification: databricks.concept.database-configuration.

databricks.rule.delta-sharing-provider Source

Matches resource instances of databricks_provider.

Classification: databricks.concept.delta-sharing-provider.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
databricks.rule.quality-monitor-v2 Source

Matches resource instances of databricks_quality_monitor_v2.

Classification: databricks.concept.quality-monitor.

databricks.rule.quality-monitor Source

Matches resource instances of databricks_quality_monitor.

Classification: databricks.concept.quality-monitor.

databricks.rule.query Source

Matches resource instances of databricks_query.

Classification: databricks.concept.analytics-artifact.

databricks.rule.registered-model Source

Matches resource instances of databricks_registered_model.

Classification: databricks.concept.registered-model.

Contexts

Conditions, identity and resolution

Context through source.schema_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.restrict-workspace-admins-setting Source

Matches resource instances of databricks_restrict_workspace_admins_setting.

Classification: databricks.concept.workspace-configuration.

databricks.rule.rfa-access-request-destinations Source

Matches resource instances of databricks_rfa_access_request_destinations.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.unity-catalog-schema Source

Matches resource instances of databricks_schema.

Classification: databricks.concept.unity-catalog-schema.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.catalog_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.storage_root

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.secret-acl Source

Matches resource instances of databricks_secret_acl.

Classification: databricks.concept.secret-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.scope

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.secret-scope Source

Matches resource instances of databricks_secret_scope.

Classification: databricks.concept.secret-scope.

Conditions, identity and resolution

Identity

  • attributes: ["id", "name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
databricks.rule.unity-catalog-secret Source

Matches resource instances of databricks_secret_uc.

Classification: databricks.concept.secret-configuration.

databricks.rule.secret Source

Matches resource instances of databricks_secret.

Classification: databricks.concept.secret-configuration.

Contributions

Conditions, identity and resolution

Contribution through source.scope

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.service-principal-federation-policy Source

Matches resource instances of databricks_service_principal_federation_policy.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.service-principal-role Source

Matches resource instances of databricks_service_principal_role.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.service-principal-secret Source

Matches resource instances of databricks_service_principal_secret.

Classification: databricks.concept.secret-configuration.

databricks.rule.service-principal Source

Matches resource instances of databricks_service_principal.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["application_id", "id"]
  • scope: "provider"

Endpoint

  • attributes: ["application_id", "id", "acl_principal_id"]
databricks.rule.delta-share Source

Matches resource instances of databricks_share.

Classification: databricks.concept.delta-share.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
databricks.rule.sql-alert Source

Matches resource instances of databricks_sql_alert.

Classification: databricks.concept.analytics-artifact.

databricks.rule.sql-dashboard Source

Matches resource instances of databricks_sql_dashboard.

Classification: databricks.concept.analytics-artifact.

databricks.rule.sql-global-config Source

Matches resource instances of databricks_sql_global_config.

Classification: databricks.concept.sql-configuration.

databricks.rule.sql-permissions Source

Matches resource instances of databricks_sql_permissions.

Classification: databricks.concept.sql-configuration.

databricks.rule.sql-query Source

Matches resource instances of databricks_sql_query.

Classification: databricks.concept.analytics-artifact.

databricks.rule.sql-table Source

Matches resource instances of databricks_sql_table.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.sql-visualization Source

Matches resource instances of databricks_sql_visualization.

Classification: databricks.concept.analytics-artifact.

databricks.rule.sql-widget Source

Matches resource instances of databricks_sql_widget.

Classification: databricks.concept.analytics-artifact.

databricks.rule.storage-credential Source

Matches resource instances of databricks_storage_credential.

Classification: databricks.concept.storage-credential.

Contexts

Relations

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]

Context through source.metastore_id

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.azure_managed_identity[0].managed_identity_id

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.id
  • match.strategy: "exact"

Relation through source.gcp_service_account_key[0].email

  • on_null: "absent"
  • on_empty: "absent"
  • external: "allow"
  • match.by: target.email
  • match.strategy: "exact"
databricks.rule.supervisor-agent-tool Source

Matches resource instances of databricks_supervisor_agent_tool.

Classification: databricks.concept.ml-platform-detail.

Contributions

Conditions, identity and resolution

Contribution through source.parent

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.id
  • match.strategy: "exact"
databricks.rule.supervisor-agent Source

Matches resource instances of databricks_supervisor_agent.

Classification: databricks.concept.supervisor-agent.

Conditions, identity and resolution

Identity

  • attributes: ["id"]
  • scope: "provider"

Endpoint

  • attributes: ["id"]
databricks.rule.system-schema Source

Matches resource instances of databricks_system_schema.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.unity-catalog-table Source

Matches resource instances of databricks_table.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.tag-policy Source

Matches resource instances of databricks_tag_policy.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.user-instance-profile Source

Matches resource instances of databricks_user_instance_profile.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.user-role Source

Matches resource instances of databricks_user_role.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.vector-search-endpoint Source

Matches resource instances of databricks_vector_search_endpoint.

Classification: databricks.concept.vector-search-endpoint.

Conditions, identity and resolution

Identity

  • attributes: ["name"]
  • scope: "provider"

Endpoint

  • attributes: ["id", "name"]
databricks.rule.vector-search-index Source

Matches resource instances of databricks_vector_search_index.

Classification: databricks.concept.vector-search-index.

Relations

Conditions, identity and resolution

Relation through source.endpoint_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"
databricks.rule.unity-catalog-volume Source

Matches resource instances of databricks_volume.

Classification: databricks.concept.unity-catalog-volume.

Contexts

Relations

Conditions, identity and resolution

Context through source.schema_name

  • on_null: "absent"
  • on_empty: "absent"
  • match.by: target.name
  • match.strategy: "exact"

Relation through source.storage_location

  • on_null: "absent"
  • on_empty: "absent"
databricks.rule.warehouses-default-warehouse-override Source

Matches resource instances of databricks_warehouses_default_warehouse_override.

Classification: databricks.concept.workspace-configuration.

databricks.rule.workspace-binding Source

Matches resource instances of databricks_workspace_binding.

Classification: databricks.concept.workspace-configuration.

databricks.rule.workspace-configuration Source

Matches resource instances of databricks_workspace_conf.

Classification: databricks.concept.workspace-configuration.

databricks.rule.workspace-entity-tag-assignment Source

Matches resource instances of databricks_workspace_entity_tag_assignment.

Classification: databricks.concept.unity-catalog-data-detail.

databricks.rule.workspace-group-member Source

Matches resource instances of databricks_workspace_iam_direct_group_member_v2.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.workspace-identity-group Source

Matches resource instances of databricks_workspace_iam_group_v2.

Classification: databricks.concept.identity-group.

databricks.rule.workspace-service-principal Source

Matches resource instances of databricks_workspace_iam_service_principal_v2.

Classification: rf.concept.service-identity.

Conditions, identity and resolution

Identity

  • attributes: ["application_id", "service_principal_id"]
  • scope: "provider"

Endpoint

  • attributes: ["application_id", "service_principal_id"]
databricks.rule.workspace-identity-assignment Source

Matches resource instances of databricks_workspace_iam_workspace_assignment_v2.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.workspace-identity-detail Source

Matches resource instances of databricks_workspace_iam_workspace_identity_detail_v2.

Classification: databricks.concept.identity-access-configuration.

databricks.rule.workspace-network-option Source

Matches resource instances of databricks_workspace_network_option.

Classification: databricks.concept.workspace-configuration.

databricks.rule.workspace-setting Source

Matches resource instances of databricks_workspace_setting_v2.

Classification: databricks.concept.workspace-configuration.