Skip to main content

permissions

Creates, updates, deletes, gets or lists a permissions resource.

Overview

Namepermissions
TypeResource
Iddatabricks_workspace.iam.permissions

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
object_idstring
access_control_listarray
object_typestring

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectrequest_object_type, request_object_id, deployment_nameGets the permissions of an object. Objects can inherit permissions from their parent objects or root
updateupdaterequest_object_type, request_object_id, deployment_nameUpdates the permissions on an object. Objects can inherit permissions from their parent objects or
setreplacerequest_object_type, request_object_id, deployment_nameSets permissions on an object, replacing existing permissions if they exist. Deletes all direct

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
deployment_namestringThe Databricks Workspace Deployment Name (default: dbc-abcd0123-a1bc)
request_object_idstringThe id of the request object.
request_object_typestringThe type of the request object. Can be one of the following: alerts, alertsv2, authorization, clusters, cluster-policies, dashboards, database-projects, dbsql-dashboards, directories, experiments, files, genie, instance-pools, jobs, notebooks, pipelines, queries, registered-models, repos, serving-endpoints, or warehouses.

SELECT examples

Gets the permissions of an object. Objects can inherit permissions from their parent objects or root

SELECT
object_id,
access_control_list,
object_type
FROM databricks_workspace.iam.permissions
WHERE request_object_type = '{{ request_object_type }}' -- required
AND request_object_id = '{{ request_object_id }}' -- required
AND deployment_name = '{{ deployment_name }}' -- required
;

UPDATE examples

Updates the permissions on an object. Objects can inherit permissions from their parent objects or

UPDATE databricks_workspace.iam.permissions
SET
access_control_list = '{{ access_control_list }}'
WHERE
request_object_type = '{{ request_object_type }}' --required
AND request_object_id = '{{ request_object_id }}' --required
AND deployment_name = '{{ deployment_name }}' --required
RETURNING
object_id,
access_control_list,
object_type;

REPLACE examples

Sets permissions on an object, replacing existing permissions if they exist. Deletes all direct

REPLACE databricks_workspace.iam.permissions
SET
access_control_list = '{{ access_control_list }}'
WHERE
request_object_type = '{{ request_object_type }}' --required
AND request_object_id = '{{ request_object_id }}' --required
AND deployment_name = '{{ deployment_name }}' --required
RETURNING
object_id,
access_control_list,
object_type;