Description
Databricks groups organize permissions granted to their members. Leaving powerful permissions on a group with an unclear purpose can give unintended access to members added later. An empty group can also be a legitimate group awaiting provisioning.
Members can be users, service principals or other groups. Attaching an AWS instance profile grants permission to use that profile; it is separate from adding a member.
Potential impact
- Future members may receive unnecessary resource-creation or data-access permissions.
- Unclear ownership and purpose can make access review and revocation harder.
Remediation
Document the group’s owner and purpose, and retain only required members and permissions. Check whether an empty group is awaiting planned provisioning before removing unused groups and unnecessary permissions. Do not add users or AWS instance-profile permissions merely to populate an empty group.
Examples
These excerpts illustrate membership for a workspace-level group. The before example shows only group creation and does not include membership managed through other provisioning paths.
Before
resource "databricks_group" "example" {
display_name = "Some Group"
allow_cluster_create = true
allow_instance_pool_create = true
}
After
resource "databricks_group" "example" {
display_name = "Some Group"
allow_cluster_create = true
allow_instance_pool_create = true
}
resource "databricks_user" "example" {
user_name = "someone@example.com"
}
resource "databricks_group_member" "example" {
group_id = databricks_group.example.id
member_id = databricks_user.example.id
}
The after example creates a user and adds that user to the group. Both examples retain cluster and instance-pool creation privileges, so verify that they are actually needed. Adding a member does not itself establish least privilege.