Repository navigation
[CXH-2721] - Add Unity Catalog catalog sync and catalog scoping config - Databricks Connector - #71
Open
mateoHernandez123 wants to merge 2 commits into
Conversation
This was referenced Oct 9, 2026
mateoHernandez123
force-pushed
the
mateoHernandez123/unity-catalog-foundation-and-metastore
branch
from
October 9, 2026 13:20
e894653 to
019c458
Compare
mateoHernandez123
force-pushed
the
mateoHernandez123/unity-catalog-catalog-sync
branch
3 times, most recently
from
October 9, 2026 16:46
b12726a to
b2ecaf2
Compare
…config Co-authored-by: Cursor <cursoragent@cursor.com>
…fixes to catalogs Carries the metastore fixes down to the catalog securable: the Revoke pre-read bypasses the uhttp response cache so a page cached before the last change cannot make it skip the PATCH, and a revoke against a catalog that is gone reports GrantAlreadyRevoked rather than failing the task on every retry. The out-of-scope branch keeps InvalidArgument: a catalog the operator filtered out is not an absence, and reporting success there would claim a revoke the connector never looked at. Co-authored-by: Cursor <cursoragent@cursor.com>
mateoHernandez123
force-pushed
the
mateoHernandez123/unity-catalog-catalog-sync
branch
from
October 9, 2026 16:54
b2ecaf2 to
00adc02
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Second of four stacked PRs for Unity Catalog. Adds the
catalogresource type and the two config fields that scope a Unity Catalog sync (CXH-2721).A catalog's parent is the metastore that owns it, not the workspace it is read through. The workspace host is an access path, resolved per call by the routing added in #70 — a catalog listed through two workspaces is one resource, not two.
Resource hierarchy
This PR delivers the
cataloglevel.Stack position
This PR is #2 of 4 and is based on branch 1, not on
main. #70 has to merge first; once it does I will retarget this PR's base tomain. Everything in the diff below branch 1's commit belongs to branch 1.mateoHernandez123/unity-catalog-foundation-and-metastoremainmateoHernandez123/unity-catalog-catalog-syncmateoHernandez123/unity-catalog-schema-syncmateoHernandez123/unity-catalog-table-and-volume-syncSync:
catalog, NEW) — child ofmetastore. Listed through every workspace attached to the metastore and unioned, because anISOLATEDcatalog is only listable from the workspaces bound to it. Keyed{metastore_id}::{name}, so the same catalog reached through two workspaces derives one resource id. One entitlement per catalog-level privilege plus the read-onlyowner.metastore) — unchanged from branch 1Provisioning:
PATCH .../permissions/catalog/{name}path and the same echo-confirmed idempotency as the metastore level:GrantAlreadyExists/GrantAlreadyRevokedcome off the echoed assignments, not off the HTTP status.Auth:
Unchanged credentials. Two new optional fields, mutually exclusive:
--databricks-catalogs(BATON_DATABRICKS_CATALOGS) — sync only these catalogs, by name.--databricks-exclude-catalogs(BATON_DATABRICKS_EXCLUDE_CATALOGS) — sync everything except these.Not a breaking change: both default to empty, which syncs every catalog. One entry scopes a whole subtree, since schemas, tables and volumes are all listed through their catalog. Matching is case-insensitive because Unity Catalog resolves catalog names case-insensitively. The filter is applied when catalogs are collected, so an out-of-scope catalog is absent in exactly the way a deleted one is, rather than surfacing as unreachable.
Architecture highlights:
New()as well as declared mutually exclusive in the config schema, becauseNew()is exported and a caller can bypass the SDK's check.What is and is not verified
Being explicit so nobody reads more into this than it earned.
Verified. The full stack applied together was run against a ConductorOne tenant in Squire several times. Sync completed clean, the metastore → catalog → schema → table/volume hierarchy landed with the expected parents, direct grants landed on the right principals, and grants reaching a user through a group surfaced as expanded grants in C1.
Not verified. The four cuts were not validated individually — the validation was always against the whole stack. Each branch builds, tests and lints on its own and the capabilities/config metadata matches its own binary, but no one has run a C1 sync against branch 1, 2 or 3 in isolation.
Not verified, specifically. The view case — a view rejecting
ALL_PRIVILEGESwith a 400 even though the documentation lists it — is covered by a unit test and by the privilege sets, but it was never exercised against a live tenant: the Databricks account ran out of credits and no SQL warehouse would start, so no view or materialized view could be created to grant against.Useful links: