Skip to content

Commit 6b9da82

Browse files
alex-khakhlyukIsaac
andauthored
Add grants support for AI Gateway securables (model_service, mcp_service, model_provider_service) (#6635)
…ice, model_provider_service) Follow-up to the #6410 split. Wires UC grants (the `grants` field + `.grants` sub-resource) into all three AI Gateway securables, mirroring volumes/registered_models: the `Grants` field on each resource config, the resource->securable_type mapping (model_service/mcp_service/ model_provider_service), and the direct-engine grants sub-resource registration. Stacked on the model_provider_service branch. ## Changes <!-- Brief summary of your changes that is easy to understand --> ## Why <!-- Why are these changes needed? Provide the context that the reviewer might be missing. For example, were there any decisions behind the change that are not reflected in the code itself? --> ## Tests <!-- How have you tested the changes? --> <!-- If your PR needs to be included in the release notes for next release, add a changelog fragment: create .nextchanges/<section>/<name>.md with a one-line description (e.g. .nextchanges/cli/quickstart.md). See .nextchanges/README.md. --> --------- Co-authored-by: Isaac <no-reply@databricks.com>
1 parent ee6cf8c commit 6b9da82

54 files changed

Lines changed: 1154 additions & 22 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
* Add grants support for the AI Gateway `model_service`, `mcp_service`, and `model_provider_service` resources (direct engine). ([#6635](https://github.com/databricks/cli/pull/6635))

‎acceptance/bundle/invariant/configs/mcp_service.yml.tmpl‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,7 @@ resources:
77
parent: schemas/main.default
88
mcp_service_id: test-mcp-service-$UNIQUE_NAME
99
comment: test mcp service
10+
grants:
11+
- principal: account users
12+
privileges:
13+
- APPLY_TAG

‎acceptance/bundle/invariant/configs/model_provider_service.yml.tmpl‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,10 @@ resources:
77
parent: schemas/main.default
88
model_provider_service_id: test-model-provider-service-$UNIQUE_NAME
99
comment: test model provider service
10+
grants:
11+
- principal: account users
12+
privileges:
13+
- APPLY_TAG
1014
config:
1115
provider_type: EXTERNAL_MODEL_PROVIDER_TYPE_CUSTOM
1216
targets:

‎acceptance/bundle/invariant/configs/model_service.yml.tmpl‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,3 +7,7 @@ resources:
77
parent: schemas/main.default
88
model_service_id: test-model-service-$UNIQUE_NAME
99
comment: test model service
10+
grants:
11+
- principal: account users
12+
privileges:
13+
- APPLY_TAG

‎acceptance/bundle/refschema/out.fields.txt‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2103,6 +2103,12 @@ resources.mcp_services.*.mcp_service_id string ALL
21032103
resources.mcp_services.*.modified_status string INPUT
21042104
resources.mcp_services.*.parent string ALL
21052105
resources.mcp_services.*.url string INPUT
2106+
resources.mcp_services.*.grants.full_name string ALL
2107+
resources.mcp_services.*.grants.securable_type string ALL
2108+
resources.mcp_services.*.grants[*] catalog.PrivilegeAssignment ALL
2109+
resources.mcp_services.*.grants[*].principal string ALL
2110+
resources.mcp_services.*.grants[*].privileges []catalog.Privilege ALL
2111+
resources.mcp_services.*.grants[*].privileges[*] catalog.Privilege ALL
21062112
resources.model_provider_services.*.comment string ALL
21072113
resources.model_provider_services.*.config *catalog.ModelProviderServiceConfig ALL
21082114
resources.model_provider_services.*.config.allow_all_targets bool ALL
@@ -2189,6 +2195,12 @@ resources.model_provider_services.*.model_provider_service_id string ALL
21892195
resources.model_provider_services.*.modified_status string INPUT
21902196
resources.model_provider_services.*.parent string ALL
21912197
resources.model_provider_services.*.url string INPUT
2198+
resources.model_provider_services.*.grants.full_name string ALL
2199+
resources.model_provider_services.*.grants.securable_type string ALL
2200+
resources.model_provider_services.*.grants[*] catalog.PrivilegeAssignment ALL
2201+
resources.model_provider_services.*.grants[*].principal string ALL
2202+
resources.model_provider_services.*.grants[*].privileges []catalog.Privilege ALL
2203+
resources.model_provider_services.*.grants[*].privileges[*] catalog.Privilege ALL
21922204
resources.model_services.*.comment string ALL
21932205
resources.model_services.*.config *catalog.ModelServiceConfig ALL
21942206
resources.model_services.*.config.inference_table *catalog.InferenceTableConfig ALL
@@ -2246,6 +2258,12 @@ resources.model_services.*.model_service_id string ALL
22462258
resources.model_services.*.modified_status string INPUT
22472259
resources.model_services.*.parent string ALL
22482260
resources.model_services.*.url string INPUT
2261+
resources.model_services.*.grants.full_name string ALL
2262+
resources.model_services.*.grants.securable_type string ALL
2263+
resources.model_services.*.grants[*] catalog.PrivilegeAssignment ALL
2264+
resources.model_services.*.grants[*].principal string ALL
2265+
resources.model_services.*.grants[*].privileges []catalog.Privilege ALL
2266+
resources.model_services.*.grants[*].privileges[*] catalog.Privilege ALL
22492267
resources.model_serving_endpoints.*.ai_gateway *serving.AiGatewayConfig ALL
22502268
resources.model_serving_endpoints.*.ai_gateway.fallback_config *serving.FallbackConfig ALL
22512269
resources.model_serving_endpoints.*.ai_gateway.fallback_config.enabled bool ALL
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
bundle:
2+
name: deploy-mcp-service-grants-$UNIQUE_NAME
3+
4+
resources:
5+
mcp_services:
6+
my_mcp_service:
7+
parent: schemas/main.myschema
8+
mcp_service_id: myservice
9+
comment: mycomment
10+
grants:
11+
- principal: deco-test-user@databricks.com
12+
privileges: ["APPLY_TAG"]
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
{
2+
"method": "PATCH",
3+
"path": "/api/2.1/unity-catalog/permissions/mcp_service/main.myschema.myservice",
4+
"body": {
5+
"changes": [
6+
{
7+
"add": [
8+
"APPLY_TAG"
9+
],
10+
"principal": "deco-test-user@databricks.com",
11+
"remove": [
12+
"ALL_PRIVILEGES"
13+
]
14+
}
15+
]
16+
}
17+
}

‎acceptance/bundle/resources/grants/mcp_services/out.destroy.requests.direct.json‎

Whitespace-only changes.
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"plan_version": [PLAN_VERSION],
3+
"cli_version": "[CLI_VERSION]",
4+
"plan": {
5+
"resources.mcp_services.my_mcp_service": {
6+
"action": "create",
7+
"new_state": {
8+
"value": {
9+
"comment": "mycomment",
10+
"mcp_service_id": "myservice",
11+
"parent": "schemas/main.myschema"
12+
}
13+
}
14+
},
15+
"resources.mcp_services.my_mcp_service.grants": {
16+
"depends_on": [
17+
{
18+
"node": "resources.mcp_services.my_mcp_service",
19+
"label": "${resources.mcp_services.my_mcp_service.id}"
20+
}
21+
],
22+
"action": "create",
23+
"new_state": {
24+
"value": {
25+
"securable_type": "mcp_service",
26+
"full_name": "",
27+
"__embed__": [
28+
{
29+
"principal": "deco-test-user@databricks.com",
30+
"privileges": [
31+
"APPLY_TAG"
32+
]
33+
}
34+
]
35+
},
36+
"vars": {
37+
"full_name": "${resources.mcp_services.my_mcp_service.id}"
38+
}
39+
}
40+
}
41+
}
42+
}

‎acceptance/bundle/resources/grants/mcp_services/out.test.toml‎

Lines changed: 3 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)