Skip to content

Update Databricks CLI to v1.20.0 and remove Terraform bundling - #2243

Merged
rugpanov merged 3 commits into
mainfrom
cli-1.20.0-remove-terraform
Oct 9, 2026
Merged

rugpanov merged 3 commits into
mainfrom
cli-1.20.0-remove-terraform

Conversation

@rugpanov

@rugpanov rugpanov commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Databricks CLI v1.20.0 removes the Terraform deployment engine and the hidden bundle debug terraform command. Packaging called that command to download Terraform and the Databricks provider. Thus #2241, the plain version bump, fails packaging, and all e2e jobs fail with it. This PR replaces #2241.

Fixes #2166: the VSIX no longer ships the Terraform v1.5.5 binary that security scans flag.

  • Bump the bundled CLI to v1.20.0.
  • Stop bundling Terraform. The VSIX now contains only bin/databricks. The setupCLIDependencies.ts packaging step and its host-CLI download are gone.
  • Stop setting the DATABRICKS_TF_* variables for CLI processes and integrated terminals, and stop writing the Terraform CLI config on activation. The extension clears its terminal variables on each activation, so old values do not stay.
  • Remove the Terraform-engine deprecation warning, its bundleTerraformEngineWarning telemetry event, and its databricks.bundle.hideTerraformEngineWarning state key. CLI v1.20.0 rejects engine: terraform in validate, so the warning cannot show.

Backward compatibility

  • A bundle on the Terraform engine fails validate and deploy with the CLI error. The CLI error tells the user to remove bundle.engine, links the migration guide, and migrates existing Terraform state automatically.
  • A user can pin CLI v1.19.x or lower with databricks.cli.path, or put an older databricks first on PATH in a terminal. That CLI no longer gets the bundled Terraform. It downloads Terraform at runtime, and this fails on restricted networks. We accept this, because the extension moves to the direct engine.

Tests

  • Unit tests with the bundled CLI v1.20.0: 1290 pass, 0 fail.
  • yarn run build and yarn run test:lint pass.
  • ./scripts/package-vsix.sh darwin-arm64: the VSIX builds. extension/bin/ contains only databricks, and the packaged package.json has no terraformMetadata.
  • CI integration tests (full e2e suite on the packaged VSIX, Linux and Windows): all 46 jobs pass. On the first attempt, deploy_and_run_job on Linux timed out while it waited for the job run status. The deploy step had already passed. The re-run of that job passed.

This pull request and its description were written by Isaac.

*Why*:
* CLI v1.20.0 removes the Terraform deployment engine and the hidden `bundle debug terraform` command.
* Packaging called that command to download Terraform and the provider, so the VSIX build failed and every e2e job failed with it.
* With the engine gone, the bundled Terraform binary, the `DATABRICKS_TF_*` env vars, and the Terraform-engine warning are dead code.

*What:*
* Bump `cli.version` to 1.20.0.
* Stop bundling Terraform: delete `setupCLIDependencies.ts` and its step (plus the host-CLI download it needed) in `package-vsix.sh`, and the now-unused `BUILD_PLATFORM_ARCH`.
* Remove `terraformUtils.ts`, the `DATABRICKS_TF_*` env vars from CLI and terminal environments, and the Terraform CLI config write on activation. The terminal env collection is already cleared on each activation, so old values do not stay.
* Remove the Terraform-engine warning (`BundleEngineManager`), its telemetry event, its state key, and the `engine` field it read from validate output. CLI v1.20.0 rejects `engine: terraform`, so the warning can no longer show.
* Drop the now-unused `extract-zip` dev dependency and fix Terraform mentions in comments.

*Verification:*
* `yarn install --immutable`, `yarn run build`, `yarn run test:lint`: pass.
* Unit tests against the bundled CLI v1.20.0: 1290 passing, 0 failing.
* `./scripts/package-vsix.sh darwin-arm64`: VSIX builds; `extension/bin/` has only `databricks`, and the packaged `package.json` has no `terraformMetadata`.

Co-authored-by: Isaac <no-reply@databricks.com>
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:32 — with GitHub Actions Active
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:32 — with GitHub Actions Active
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:32 — with GitHub Actions Active
@rugpanov

rugpanov commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Integration tests running for 17d1995c — ⏳.
View run

*Why*:
* The edited comment broke mid-sentence on a short line.

*What:*
* Reflow the comment into full lines.

*Verification:*
* Prettier and ESLint pass on the file.

Co-authored-by: Isaac <no-reply@databricks.com>
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:43 — with GitHub Actions Active
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:45 — with GitHub Actions Active
@rugpanov
rugpanov deployed to test-trigger-is October 8, 2026 13:45 — with GitHub Actions Active
@rugpanov

rugpanov commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 Integration tests ❌ failed for 97b2f8f4.
View run

@rugpanov
rugpanov marked this pull request as ready for review October 8, 2026 14:17
@rugpanov
rugpanov deployed to test-trigger-is October 9, 2026 10:45 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

If integration tests don't run automatically, an authorized user can run them manually by following the instructions below:

Trigger:
go/deco-tests-run/vscode

Inputs:

  • PR number: 2243
  • Commit SHA: 4bc79c6b93c13cc0ad82e7c2f2018e68eddc0590

Checks will be approved automatically on success.

@rugpanov
rugpanov deployed to test-trigger-is October 9, 2026 10:45 — with GitHub Actions Active
@rugpanov
rugpanov deployed to test-trigger-is October 9, 2026 10:45 — with GitHub Actions Active
@rugpanov

rugpanov commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

🤖 Integration tests ❌ failed for 4bc79c6b.
View run

@rugpanov
rugpanov merged commit b087b77 into main Oct 9, 2026
10 of 11 checks passed
@rugpanov
rugpanov deleted the cli-1.20.0-remove-terraform branch October 9, 2026 11:23

This branch was successfully deployed

1 active deployment
test-trigger-is — 4bc79c6b Deployed Oct 9, 2026 by rugpanov via Trigger Tests #2312
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bundled Terraform binary contains vulnerable Go dependencies (golang.org/x/crypto, golang.org/x/net, grpc, go-getter, pgx)

2 participants