Review Databricks job and cluster permissions

Limit Databricks job and cluster permissions to the users, groups, and service principals that need them.

Description

Grant execution and management permissions on Databricks jobs and clusters only to the principals that need them. The absence of a databricks_permissions resource in Terraform does not establish that existing permissions are missing or public.

Potential impact

Excessive permissions can allow a principal to alter jobs or control clusters and, depending on the granted access, affect the data they process.

Remediation

Check effective permissions and grant the minimum access supported by each resource type. Consider a dedicated service principal as the owner of automated jobs; user ownership is not inherently a vulnerability. Applying databricks_permissions can overwrite existing permissions, so retain required access.

Examples

The example assigns job ownership to a service principal and viewing access to the users group. Restrict that group if workspace-wide viewing is unnecessary. Job tasks and the service principal definition are omitted.

Before

hcl
resource "databricks_job" "feature_job" {
  name                = "Featurization"
  max_concurrent_runs = 1
}

After

hcl
resource "databricks_job" "feature_job" {
  name                = "Featurization"
  max_concurrent_runs = 1
}

resource "databricks_permissions" "feature_job_permissions" {
  job_id = databricks_job.feature_job.id

  access_control {
    group_name       = "users"
    permission_level = "CAN_VIEW"
  }

  access_control {
    service_principal_name = databricks_service_principal.aws_principal.application_id
    permission_level       = "IS_OWNER"
  }
}

References