Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions developer/debugging.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -288,6 +288,10 @@ After running a sync, you see duplicate resources in C1: one created via Terrafo
| Azure AD | Object ID | `12345678-1234-...` |
| GCP | Resource path | `projects/my-project` |
| AWS | Full ARN | `arn:aws:iam::123...` |
| Databricks (group) | `account/<account-id>/group/<group-id>` | `account/8c6f99ec-.../group/79416186968854` |
| Databricks (workspace) | Deployment name | `dbc-dd4d071e-0b85` |

Some connectors don't use the native ID for every resource type. For example, a Databricks group's ID is a compound path, not the bare Databricks group ID. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats) for the full list.

**Step 3:** Update Terraform to use the exact match:

Expand Down
18 changes: 18 additions & 0 deletions developer/recipes-id.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,31 @@ Each recipe includes the problem, solution code, and rationale.
| **GitHub** | Node ID or numeric ID | Integer as string | `12345678` |
| **Salesforce** | Salesforce ID | 18-char ID | `00e3h000000bRQAAA2` |
| **Google Workspace** | Google Group ID | Variable | `00gjdgxs3x1h123` |
| **Databricks** | Connector resource ID (varies by resource type) | See [Databricks resource IDs](#databricks-resource-ids) | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` |

**Why this matters:** C1 uses these IDs to correlate resources across syncs. Using the wrong ID causes duplicate objects or failed correlations.

**Key points:**
- Azure AD has two IDs: Object ID (use this) and Application ID (client ID for OAuth)
- AWS uses full ARNs, not account IDs alone
- GitHub has numeric IDs and GraphQL node IDs; either works but be consistent
- Databricks does not use the native ID for every resource type. Groups, workspaces, and workspace roles use a connector-built value, so check the table below before setting `match_baton_id`

### Databricks resource IDs

baton-databricks (v0.1.16 and later) sets `RawId` to the connector's resource ID. For groups, that is a compound path, not the Databricks group ID. A bare group ID in `match_baton_id` does not merge: after sync, the connector's group appears as a second resource next to the pre-created one.

| Resource type | `match_baton_id` value | Example |
|---------------|------------------------|---------|
| Group (account) | `account/<account-id>/group/<group-id>` | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` |
| Group (workspace) | `workspace/<deployment-name>/group/<group-id>` | `workspace/dbc-dd4d071e-0b85/group/79416186968854` |
| Workspace | Deployment name, not the numeric workspace ID | `dbc-dd4d071e-0b85` |
| Workspace role | `<deployment-name>:<role>` | `dbc-dd4d071e-0b85:databricks-sql-access` |
| Account role | Role name | `account_admin` |
| User | Databricks user ID | `74984374645487` |
| Service principal | Databricks service principal ID | `71985169525637` |

Entitlements match on the parent resource's `match_baton_id` plus the slug (for example, `member` on a group).

## Setting RawId annotation

Expand Down
3 changes: 3 additions & 0 deletions developer/syncing.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -236,6 +236,9 @@ r.WithAnnotation(&v2.RawId{Id: user.ID})
| GCP | Resource name | `projects/my-project-123` |
| Azure AD | Object ID | `550e8400-e29b-41d4-a716-446655440000` |
| GitHub | Node ID or numeric ID | `MDQ6VXNlcjE=` or `12345` |
| Databricks | Resource ID (compound for groups) | `account/8c6f99ec-78ce-4654-8f92-e716b3dd67a7/group/79416186968854` |

For Databricks resource types whose `RawId` is not the native ID, see [Databricks resource IDs](/developer/recipes-id#databricks-resource-ids).

### Entitlements()

Expand Down
4 changes: 4 additions & 0 deletions developer/terraform-best-practices.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,10 @@ resource "conductorone_custom_app_entitlement" "custom_app_entitlement" {
}
```

<Warning>
In Okta, `match_baton_id` is the native group ID. That isn't true for every connector. For a Databricks group, `match_baton_id` must be the compound resource ID (`account/<account-id>/group/<group-id>`), not the bare Databricks group ID. With the bare ID, the connector's group is created as a second resource and the pre-created entitlement gets no grants. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats).
</Warning>

### Keep in mind

- **`display_name`** is required, but if the entitlement is connector-managed, the connector will overwrite it on sync. Add `lifecycle { ignore_changes = [display_name] }` when using `match_baton_id` to prevent Terraform from flagging this as drift.
Expand Down
4 changes: 4 additions & 0 deletions developer/terraform.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,10 @@ resource "conductorone_custom_app_entitlement" "test" {
// Once the Okta app is finished syncing, you will see the entitlement be populated with the corresponding grants from Okta.
```

<Warning>
This example works because Okta's connector uses the native Okta group ID as the match key. Other connectors may not. For a Databricks group, set `match_baton_id` to `account/<account-id>/group/<group-id>`, not the bare Databricks group ID. With the bare ID, the sync creates a second resource for the group instead of merging. See [per-connector ID formats](/developer/recipes-id#per-connector-id-formats).
</Warning>




Expand Down