Skip to main content

privilege_assignments

Creates, updates, deletes, gets or lists a privilege_assignments resource.

Overview

Nameprivilege_assignments
TypeResource
Iddatabricks_workspace.catalog.privilege_assignments

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
principal_idintegerUnique identifier of the principal. For active principals, both ``principal`` and ``principal_id`` are present.
principalstring
privilegesarrayThe privileges assigned to the principal.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectsecurable_type, full_name, deployment_nameinclude_deleted_principals, page_size, page_token, principalLists the privilege assignments for a securable. Does not include inherited privileges. Paginated

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
deployment_namestringThe Databricks Workspace Deployment Name (default: dbc-abcd0123-a1bc)
full_namestringFull name of securable.
securable_typestringType of securable.
include_deleted_principalsbooleanOptional. If true, also return privilege assignments whose principals have been deleted.
page_sizeintegerSpecifies the maximum number of privilege assignments to return (page length). Every PrivilegeAssignment present in a single page response is guaranteed to contain all the privileges granted on the requested Securable for the respective principal. If not set, page length is the server configured value. If set to - lesser than 0: invalid parameter error - 0: page length is set to a server configured value - lesser than 150 but greater than 0: invalid parameter error (this is to ensure that server is able to return at least one complete PrivilegeAssignment in a single page response) - greater than (or equal to) 150: page length is the minimum of this value and a server configured value
page_tokenstringOpaque pagination token to go to next page based on previous query.
principalstringIf provided, only the permissions for the specified principal (user or group) are returned.

SELECT examples

Lists the privilege assignments for a securable. Does not include inherited privileges. Paginated

SELECT
principal_id,
principal,
privileges
FROM databricks_workspace.catalog.privilege_assignments
WHERE securable_type = '{{ securable_type }}' -- required
AND full_name = '{{ full_name }}' -- required
AND deployment_name = '{{ deployment_name }}' -- required
AND include_deleted_principals = '{{ include_deleted_principals }}'
AND page_size = '{{ page_size }}'
AND page_token = '{{ page_token }}'
AND principal = '{{ principal }}'
;