I am attempting to manage my Azure Databricks users and groups with Terraform, using the databrickslabs/databricks provider. Something like this:
resource "databricks_group" "group" {
display_name = var.group_name
force = true
allow_cluster_create = false
allow_instance_pool_create = false
databricks_sql_access = true
workspace_access = true
}
resource "databricks_user" "user" {
user_name = var.user_mail
display_name = var.user_name
force = true
}
resource "databricks_group_member" "membership" {
group_id = databricks_group.group.id
member_id = databricks_user.user.id
}
This is all deployed through my Azure service principal, as part of a larger codebase that also provisions the Databricks Workspace...and it works great.
However, if I add users to one of the Databricks built-in groups (admins or users), while the deployment works, terraform destroy -- again, running as my service principal -- gives the following error when trying to destroy the databricks_group_member.membership resource:
Error: cannot delete group member: PERMISSION_DENIED: Requesting user '0a19c919-7b10-499d-acd4-057944582a41' does not have permission to edit system groups.
Why can my service principal define group membership, but not delete it? Is there some special Databricks permission I can give my service principal -- when I create the workspace -- which will resolve this? Otherwise, I have to manually do terraform state rm on the resource to get the destroy to go through.