diff --git a/developer/debugging.mdx b/developer/debugging.mdx index 90562d28..920699e1 100644 --- a/developer/debugging.mdx +++ b/developer/debugging.mdx @@ -288,6 +288,10 @@ After running a sync, you see duplicate resources in C1: one created via Terrafo | Azure AD | Object ID | `12345678-1234-...` | | GCP | Resource path | `projects/my-project` | | AWS | Full ARN | `arn:aws:iam::123...` | +| Databricks (group) | `account//group/` | `account/8c6f99ec-.../group/79416186968854` | +| Databricks (workspace) | Deployment name | `dbc-dd4d071e-0b85` | + +Some connectors don't use the native ID for every resource type. For example, a Databricks group's ID is a compound path, not the bare Databricks group ID. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats) for the full list. **Step 3:** Update Terraform to use the exact match: diff --git a/developer/recipes-id.mdx b/developer/recipes-id.mdx index fde22b20..63f6c339 100644 --- a/developer/recipes-id.mdx +++ b/developer/recipes-id.mdx @@ -21,6 +21,7 @@ Each recipe includes the problem, solution code, and rationale. | **GitHub** | Node ID or numeric ID | Integer as string | `12345678` | | **Salesforce** | Salesforce ID | 18-char ID | `00e3h000000bRQAAA2` | | **Google Workspace** | Google Group ID | Variable | `00gjdgxs3x1h123` | +| **Databricks** | Connector resource ID (varies by resource type) | See [Databricks resource IDs](#databricks-resource-ids) | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` | **Why this matters:** C1 uses these IDs to correlate resources across syncs. Using the wrong ID causes duplicate objects or failed correlations. @@ -28,6 +29,23 @@ Each recipe includes the problem, solution code, and rationale. - Azure AD has two IDs: Object ID (use this) and Application ID (client ID for OAuth) - AWS uses full ARNs, not account IDs alone - GitHub has numeric IDs and GraphQL node IDs; either works but be consistent +- Databricks does not use the native ID for every resource type. Groups, workspaces, and workspace roles use a connector-built value, so check the table below before setting `match_baton_id` + +### Databricks resource IDs + +baton-databricks (v0.1.16 and later) sets `RawId` to the connector's resource ID. For groups, that is a compound path, not the Databricks group ID. A bare group ID in `match_baton_id` does not merge: after sync, the connector's group appears as a second resource next to the pre-created one. + +| Resource type | `match_baton_id` value | Example | +|---------------|------------------------|---------| +| Group (account) | `account//group/` | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` | +| Group (workspace) | `workspace//group/` | `workspace/dbc-dd4d071e-0b85/group/79416186968854` | +| Workspace | Deployment name, not the numeric workspace ID | `dbc-dd4d071e-0b85` | +| Workspace role | `:` | `dbc-dd4d071e-0b85:databricks-sql-access` | +| Account role | Role name | `account_admin` | +| User | Databricks user ID | `74984374645487` | +| Service principal | Databricks service principal ID | `71985169525637` | + +Entitlements match on the parent resource's `match_baton_id` plus the slug (for example, `member` on a group). ## Setting RawId annotation diff --git a/developer/syncing.mdx b/developer/syncing.mdx index 54347dc8..74d88b75 100644 --- a/developer/syncing.mdx +++ b/developer/syncing.mdx @@ -236,6 +236,9 @@ r.WithAnnotation(&v2.RawId{Id: user.ID}) | GCP | Resource name | `projects/my-project-123` | | Azure AD | Object ID | `550e8400-e29b-41d4-a716-446655440000` | | GitHub | Node ID or numeric ID | `MDQ6VXNlcjE=` or `12345` | +| Databricks | Resource ID (compound for groups) | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` | + +For Databricks resource types whose `RawId` is not the native ID, see [Databricks resource IDs](/developer/recipes-id#databricks-resource-ids). ### Entitlements() diff --git a/developer/terraform-best-practices.mdx b/developer/terraform-best-practices.mdx index d4d9ccb9..de0a9634 100644 --- a/developer/terraform-best-practices.mdx +++ b/developer/terraform-best-practices.mdx @@ -132,6 +132,10 @@ resource "conductorone_custom_app_entitlement" "custom_app_entitlement" { } ``` + +In Okta, `match_baton_id` is the native group ID. That isn't true for every connector. For a Databricks group, `match_baton_id` must be the compound resource ID (`account//group/`), not the bare Databricks group ID. With the bare ID, the connector's group is created as a second resource and the pre-created entitlement gets no grants. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats). + + ### Keep in mind - **`display_name`** is required, but if the entitlement is connector-managed, the connector will overwrite it on sync. Add `lifecycle { ignore_changes = [display_name] }` when using `match_baton_id` to prevent Terraform from flagging this as drift. diff --git a/developer/terraform.mdx b/developer/terraform.mdx index 1b61941e..c523ce3b 100644 --- a/developer/terraform.mdx +++ b/developer/terraform.mdx @@ -126,6 +126,10 @@ resource "conductorone_custom_app_entitlement" "test" { // Once the Okta app is finished syncing, you will see the entitlement be populated with the corresponding grants from Okta. ``` + +This example works because Okta's connector uses the native Okta group ID as the match key. Other connectors may not. For a Databricks group, set `match_baton_id` to `account//group/`, not the bare Databricks group ID. With the bare ID, the sync creates a second resource for the group instead of merging. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats). + +