|
| 1 | +locals { |
| 2 | + admin_user_map = var.workspace_admins.user == null ? {} : { |
| 3 | + for user in var.workspace_admins.user : "user.${user}" => user if user != null |
| 4 | + } |
| 5 | + |
| 6 | + admin_sp_map = var.workspace_admins.service_principal == null ? {} : { |
| 7 | + for sp in var.workspace_admins.service_principal : "service_principal.${sp}" => sp if sp != null |
| 8 | + } |
| 9 | + |
| 10 | + members_object_list = concat( |
| 11 | + flatten([for group, params in var.iam : [ |
| 12 | + for pair in setproduct([group], params.user) : { |
| 13 | + type = "user", group = pair[0], member = pair[1] |
| 14 | + }] if params.user != null |
| 15 | + ]), |
| 16 | + flatten([for group, params in var.iam : [ |
| 17 | + for pair in setproduct([group], params.service_principal) : { |
| 18 | + type = "service_principal", group = pair[0], member = pair[1] |
| 19 | + }] if params.service_principal != null |
| 20 | + ]) |
| 21 | + ) |
| 22 | +} |
| 23 | + |
| 24 | +data "databricks_group" "admin" { |
| 25 | + display_name = "admins" |
| 26 | +} |
| 27 | + |
| 28 | +resource "databricks_group" "this" { |
| 29 | + for_each = toset(keys(var.iam)) |
| 30 | + |
| 31 | + display_name = each.key |
| 32 | + lifecycle { ignore_changes = [external_id, allow_cluster_create, allow_instance_pool_create, databricks_sql_access, workspace_access] } |
| 33 | +} |
| 34 | + |
| 35 | +resource "databricks_user" "this" { |
| 36 | + for_each = toset(flatten(concat( |
| 37 | + values({ for group, member in var.iam : group => member.user if member.user != null }), |
| 38 | + values(local.admin_user_map) |
| 39 | + ))) |
| 40 | + |
| 41 | + user_name = each.key |
| 42 | + lifecycle { ignore_changes = [external_id, allow_cluster_create, allow_instance_pool_create, databricks_sql_access, workspace_access] } |
| 43 | +} |
| 44 | + |
| 45 | +resource "databricks_service_principal" "this" { |
| 46 | + for_each = toset(flatten(concat( |
| 47 | + values({ for group, member in var.iam : group => member.service_principal if member.service_principal != null }), |
| 48 | + values(local.admin_sp_map) |
| 49 | + ))) |
| 50 | + |
| 51 | + display_name = each.key |
| 52 | + application_id = lookup(var.user_object_ids, each.value) |
| 53 | + lifecycle { ignore_changes = [external_id, allow_cluster_create, allow_instance_pool_create, databricks_sql_access, workspace_access] } |
| 54 | +} |
| 55 | + |
| 56 | +resource "databricks_group_member" "admin" { |
| 57 | + for_each = merge(local.admin_user_map, local.admin_sp_map) |
| 58 | + |
| 59 | + group_id = data.databricks_group.admin.id |
| 60 | + member_id = startswith(each.key, "user") ? databricks_user.this[each.value].id : databricks_service_principal.this[each.value].id |
| 61 | +} |
| 62 | + |
| 63 | +resource "databricks_group_member" "this" { |
| 64 | + for_each = { |
| 65 | + for entry in local.members_object_list : "${entry.type}.${entry.group}.${entry.member}" => entry |
| 66 | + } |
| 67 | + |
| 68 | + group_id = databricks_group.this[each.value.group].id |
| 69 | + member_id = startswith(each.key, "user") ? databricks_user.this[each.value.member].id : databricks_service_principal.this[each.value.member].id |
| 70 | +} |
| 71 | + |
| 72 | +resource "databricks_entitlements" "this" { |
| 73 | + for_each = { |
| 74 | + for group, params in var.iam : group => params |
| 75 | + } |
| 76 | + |
| 77 | + group_id = databricks_group.this[each.key].id |
| 78 | + allow_cluster_create = contains(coalesce(each.value.entitlements, ["none"]), "allow_cluster_create") |
| 79 | + allow_instance_pool_create = contains(coalesce(each.value.entitlements, ["none"]), "allow_instance_pool_create") |
| 80 | + databricks_sql_access = contains(coalesce(each.value.entitlements, ["none"]), "databricks_sql_access") |
| 81 | + workspace_access = true |
| 82 | + |
| 83 | + depends_on = [databricks_group_member.this] |
| 84 | +} |
0 commit comments