Description
Grant execution and management permissions on Databricks jobs and clusters only to the principals that need them. The absence of a databricks_permissions resource in Terraform does not establish that existing permissions are missing or public.
Potential impact
Excessive permissions can allow a principal to alter jobs or control clusters and, depending on the granted access, affect the data they process.
Remediation
Check effective permissions and grant the minimum access supported by each resource type. Consider a dedicated service principal as the owner of automated jobs; user ownership is not inherently a vulnerability. Applying databricks_permissions can overwrite existing permissions, so retain required access.
Examples
The example assigns job ownership to a service principal and viewing access to the users group. Restrict that group if workspace-wide viewing is unnecessary. Job tasks and the service principal definition are omitted.
Before
resource "databricks_job" "feature_job" {
name = "Featurization"
max_concurrent_runs = 1
}
After
resource "databricks_job" "feature_job" {
name = "Featurization"
max_concurrent_runs = 1
}
resource "databricks_permissions" "feature_job_permissions" {
job_id = databricks_job.feature_job.id
access_control {
group_name = "users"
permission_level = "CAN_VIEW"
}
access_control {
service_principal_name = databricks_service_principal.aws_principal.application_id
permission_level = "IS_OWNER"
}
}