Releases: databricks/cli
Releases · databricks/cli
Release list
v1.19.0
CLI
- Honor
CLAUDE_CONFIG_DIRinaitoolscommands. (#6838) - Added
--ttland--no-expiryflags todatabricks postgres create-branchso a branch's expiration can be set without hand-writing a--jsonspec.--ttlaccepts the REST API duration form (604800s), a Go duration (168h), or day/week units (7d,3w);--no-expirycreates a branch that never expires. One of--ttl,--no-expiry, or a spec expiration in--jsonis required. (#6313) databricks ssh connectserverless sessions now provide Claude Code and Codex configured with Unity Gateway out of the box. (#6885)
AI Runtime
- Add
databricks air images push(Preview) to configure Docker authentication and push container images to Databricks Artifact Registry. (#6869) air runnow grants the configuredpermissionson the MLflow experiment as well as the job. (#6870)
Bundles
- Add libraries field to clusters. (#6831)
- Error out when a configured
workspace_iddoes not match the connected workspace, instead of silently using it in resource URLs emitted bybundle summary. (#6754) - Fix spurious recreation of Lakebase (Postgres) branches, roles, and catalogs when the referenced project is updated in place: an in-place project change (e.g.
display_name) no longer forces a delete + create of resources that reference the project's or branch'sname. (#6865) - Direct engine now detects and applies an explicitly configured integer zero (e.g.
gcp_attributes.local_ssd_count: 0) added to a resource first deployed without the field. (#6867) - Migrate existing Terraform deployment state to the direct engine before deploying (previously done after a Terraform deploy), so the deploy runs on the direct engine. (#6749)
- The
postgres_snapshot_schedulesresource (introduced in v1.16.0) is now marked Beta and is no longer available in PyDABs, matching the otherpostgres_*resources; configure it in YAML instead. (#6887)
v1.18.0
Release v1.18.0 (2026-09-24)
CLI
- The AI Runtime commands have moved to
databricks air. The previousdatabricks experimental airpath now directs users to the new command. (#6722) - Write local state, cache, and config files atomically so an interrupted or concurrent write cannot corrupt them. (#6708)
- Deprecate
--regionindatabricks auth docker configureahead of its removal in the next release, infer the Artifact Registry region when it is omitted, and adddatabricks auth docker host --profile <name>to show the profile's registry host and credential-helper status. (#6782) - Return
UNAUTHENTICATEDinstead ofINVALID_REFRESH_TOKENwhendatabricks auth token --output jsoncannot refresh a cached U2M token. (#6731) - Retry the current-user (SCIM
Me) lookup on transient HTTP 500 responses so a temporarily-unavailable backend no longer fails bundle commands outright. (#6766) - Preserve workspace-file and volume access for SSH server descendants when the bootstrap notebook exits and the server survives. (#6645)
ssh connectandssh setupnow accept a--keep-detached-processesflag to keep processes detached from the SSH session (tmux,setsid,nohup) running after the tunnel shuts down. Teardown then terminates only the tunnel's own process group, and the bootstrap job run is held open while any detached process is still running, so the survivors keep their/Workspaceand/Volumesaccess. A held-open run also suppresses cluster autotermination, so the flag is off by default, is bounded by--server-timeout, and is dedicated-cluster only. Without it, the server now logs a warning naming the detached processes it is about to destroy, instead of sweeping them silently. (#6387)
Bundles
- direct: Allow clearing a catalog's or schema's
custom_max_retention_hoursby removing it from configuration. (#6792) - direct: Allow clearing a genie space's
descriptionand a secret'scommentby removing them from configuration. (#6789) - Fix direct-engine deploy recreating an MLflow experiment on every deploy when its
trace_locationwas set out-of-band. (#6787) - direct: Store a Genie space's
serialized_spacein state as a content hash instead of its full contents. (#6707) - Fix
bundle deployfailing with "Invalid python file reference" for jobs that usegit_sourcewith aspark_python_taskon the direct engine. (#6751) - Fixed the direct engine mishandling UC grants that combine
ALL_PRIVILEGESwith a privilege it does not imply (MANAGE,READ_METADATA,EXTERNAL_USE_SCHEMA,EXTERNAL_USE_LOCATION): such privileges were dropped when granted and left behind when revoked, so the deployment never converged. (#6733, #6743) - Don't fail migration if clean up actions fail. (#6772)
- Ignore the backend-provided
spark.sql.ansi.enabled: "true"pipeline configuration default when detecting direct-engine drift. (#6816) - Fix recreating a postgres synced table sometimes failing with a 409 ALREADY_EXISTS error while the previous table is still being deleted. (#6728)
- Direct engine no longer recreates a resource when an immutable field the config omits was populated by the backend. (#6790)
Dependency Updates
v1.17.0
Release v1.17.0
Notable Changes
- Bump the direct deployment state version to 3. Clients older than v1.8.0 will reject bundles deployed with this release. (#6713)
CLI
- Add an
INVALID_REFRESH_TOKENerror code todatabricks auth token --output jsonfailures. (#6684) - Add experimental
databricks auth docker configureto configure Docker credential helper access for Databricks Artifact Registry. (#6700) - Add experimental
databricks auth docker tokento generate Docker credentials for Databricks Artifact Registry. (#6699) databricks environments setup-localnow reports theE_PROVISION_CONFLICTerror code instead of the genericE_PROVISIONwhenuv syncfails to resolve a dependency conflict. (#6666)- Preserve SSH sessions across temporary tunnel disconnects, with bounded replay and backpressure for large transfers. (#6650)
- Allow OAuth U2M logins to override the CLI client ID with
--client-id, profileclient_id, orDATABRICKS_CLIENT_ID. (#6594)
Bundles
- direct: Store a dashboard's
serialized_dashboardin state as a content hash instead of its full contents. (#6105) - direct: Fix pipelines recreation when the whole
ingestion_definitionblock is added or removed. (#6589) bundle plan,deploy, anddestroyno longer report removingpermissions,grants, or secret scope ACLs from a bundle as a deletion, since it leaves the resource untouched. (#6647)bundle plananddeployno longer list or count a resource that was already deleted remotely as a deletion, matchingbundle destroy; applying still cleans up its stale state entry. (#6675)- Fix
bundle runfailing withexpected an int, found a stringwhen an unrelated resource references another resource that is not deployed.bundle runnow resolves${resources.*}references only within the resource being run. (#6690) - Add grants support for the AI Gateway
model_service,mcp_service, andmodel_provider_serviceresources (direct engine). (#6635) - Add bundle support for the AI Gateway
mcp_serviceresource (direct engine). (#6633) - Add bundle support for the AI Gateway
model_provider_serviceresource (direct engine). (#6634) - Add bundle support for the AI Gateway
model_serviceresource (direct engine). (#6525) - Prevent resource drift on catalogs if
storage_rootcontained a trailing slash in the URL. (#6622) - Fixed a "lineage mismatch in state files" error that could occur after destroying a bundle and redeploying it from another machine.
bundle destroynow removes the local state file so no stale lineage is left behind, and prunes the state directories it leaves empty (such as.internal/andsync-snapshots/). (#6210, #6685) - direct:
bundle planno longer reports a permanent update on a cluster that uses a cluster policy: when the cluster spec setspolicy_id, a field present in the remote but absent from the bundle config is not treated as drift. (#6531) bundle deployon the direct engine now reports each resource as soon as it is deployed, instead of listing them all after the deployment finishes. A deploy that fails part way through now reports the resources it did apply. (#6361)- Direct-engine bundles no longer flag phantom drift on server-populated nested fields under reused config types (e.g.
external_locationsfile-event-queue resource IDs,database_instancesparent-instance refs,appsgit credential ID). (#6618) databricks bundle generate appnow reproduces a git-backed app'sgit_repositoryandgit_sourceconfiguration instead of emitting a workspacesource_code_path, so generating from a Git-deployed app no longer silently converts it to workspace source. (#6656)- Improved configuration load time for bundles with many included files. (#6195)
bundle destroyno longer deletes triggered job runs, leaving them untouched on the backend. (#6672)- direct: resources.job_runs: new lifecycle.triggers.on_file_change setting to restart the run when monitored files change. Can be set to a series of paths or globs. (#6309)
- Bundle summary now shows a name for Postgres branches, endpoints, databases, and roles instead of a blank Name field. (#6663)
- Added PyDABs (Python) support for cluster policies, dashboards, and Genie spaces. (#6585)
- CLI commands no longer imply that a resource whose type has no workspace URL is merely not deployed yet. (#6583)
- Capture the implicit dependency a vector search index has on a catalog or schema defined in the same bundle, so the catalog and schema are deployed first. (#6655)
Dependency Updates
v1.16.1
v1.16.0
Release v1.16.0
CLI
aitools installnow registers the official Claude marketplace if it is missing before installing the Databricks Claude plugin. (#6485)databricks aitools install --output jsonnow reports anerror_categoryfor a failed or skipped install (per agent, and at the top level for a failure with no per-agent entry), giving coding agents and CI a stable classification of why an install did not complete. (#6482)databricks aitools installhonors--output json, emitting a structured{scope, agents[...]}document that reports each agent's delivery and install status so coding agents and CI can consume the result without scraping the text output. JSON mode requires--scopeand--agentsso the command runs without interactive prompts. (#6481)databricks bundle syncnow prints sync progress (Action: PUT,Uploaded ...) by default, matchingdatabricks sync. Previously it was silent unless--outputwas passed. Use--output jsonfor machine-readable output. (#6568)- Support major-only DBR runtime versions such as
19.x-scala2.13in the cluster picker used bydatabricks auth login --configure-clusteranddatabricks labs. (#6574) - Deprecated the
databricks environments setup-local --constraints-onlyflag in favour of the orthogonal--no-dbconnect; the flag still works as a hidden alias but is hidden from--helpand prints a one-line deprecation notice, and will be removed in a later release. (#6470) - Add orthogonal
--no-constraintsand--no-dbconnectflags todatabricks environments setup-local:--no-constraintsskips writing the remote Python-version and dependency pins, and--no-dbconnectskips the databricks-connect dependency. (#6464) databricks environments setup-localnow reports a distinctE_PROVISION_CONFLICTerror code in--output jsonwhen the project's dependencies conflict with the pins written for the target environment, making the requirements unsatisfiable (the same conflict surfaced as aW_USER_CONSTRAINT_CONFLICTwarning); it is reported after the project files are written, without attempting the doomed provisioning, while other provisioning failures continue to reportE_PROVISION. (#6479)databricks ssh connectandssh setupnow verify the tunnel's SSH host key against the key the workspace published for the connection, recorded in~/.databricks/ssh-tunnel-known-hosts/<name>instead of~/.ssh/known_hosts. Reconnecting with a name used before no longer fails withHost key verification failedwhen the compute behind that name changed, and no longer needs a manualssh-keygen -R; host blocks written by an earlierdatabricks ssh setuppick this up once you re-run it. (#6557)- Stop
databricks ssh connect --idefrom adding a duplicate entry to the IDE's Remote Explorer on every connect: the remote authority is now the SSH host alias alone, instead of embedding the per-instance remote OS user. (#6550) - Add
--max-clientsand--server-timeoutflags todatabricks ssh setup, and--server-timeouttodatabricks ssh connect. Both are fixed when the SSH tunnel server job is submitted, sossh setupnow serializes them into the generatedProxyCommandinstead of falling back to the built-in defaults. (#6547) ssh connectsessions no longer end when the tunnel's websocket connection is lost. The CLI reattaches to the running session and replays the bytes that were missed, so the shell and everything running in it stay intact, and a transient failure to open a replacement connection for the periodic auth refresh is retried rather than ending the session. Reattaching requires an SSH server started by a CLI that supports it; against an older server the connection behaves as before. (#6558)
Bundles
- Added PyDABs (Python) support for secrets:
Resources.add_secretand thesecret_mutatordecorator. (#6553) - Fix job and pipeline environment dependencies with a
*version wildcard (e.g.numpy==2.5.*) being treated as local file paths. (#6555) - Add the
postgres_snapshot_schedulesbundle resource for managing a Lakebase Postgres branch's automatic-snapshot schedule (direct deployment engine only). (#6449)
Dependency Updates
v1.15.0
Release v1.15.0 (2026-09-03)
CLI
- When
uv python installfails,databricks environments setup-localnow falls back to a compatible Python interpreter already installed on the machine. (#6457) - Allow
databricks environments setup-localto updatepyproject.tomlfiles containing TOML multi-line strings. (#6445)
Bundles
- Before committing the automatic terraform→direct migration, run a deployment plan against the converted state; if the plan fails the migration is abandoned. (#6486)
- The
dbt-sqlbundle template now uses Databricks Runtime 16.4 LTS (up from 15.4 LTS) for classic (non-serverless) compute. (#6418) - Fixed the direct engine silently ignoring edits to duration and timestamp fields, such as a Lakebase endpoint's
suspend_timeout_duration. Such a change planned0 to changeand was never applied. (#6377) - Fixed
$${...}not escaping a literal${...}on the direct engine, which failed with aninvalid dependencyerror. (#6484, #6489) - Remove forward_user_access_token from update_mask for Apps because it's not supported. Fixes regression in 1.14.1. (#6510)
- direct: Fix deploying an update to
postgres_projects.default_endpoint_settings. (#6440) - direct: Fix deploying an update to
postgres_endpoints.settings.pg_settings. (#6441) - direct: Fix deploying an update to
expire_time,ttlorsuspend_timeout_durationon Lakebase resources. (#6443) - Added PyDABs (Python) support for catalogs:
Resources.add_catalogand thecatalog_mutatordecorator. (#6408) - Bundle templates now use serverless environment version 5, which offers better performance, and
databricks-connect16.4. (#6378) - Fixed a job with a
table_updatetrigger never converging on the direct engine. (#6442)
Dependency Updates
- Bump Go toolchain to 1.26.8. (#6476)
v1.14.1
Release v1.14.1
Bundles
- Fix
bundle deployfailing withdeployment_source.source_code_path cannot be set on UpdateApp(400) when updating an app that has an active deployment (#6401). - Fixed
${resources...}references to resource keys starting with an underscore (e.g._my_job). On the direct engine, deploying such a resource withpermissionsorgrantsfailed withcannot parse "/jobs/${resources.jobs._my_job.id}", and user-written references to it were silently left unresolved (#6422)
v1.14.0
Notable Changes
- Bundles still on Terraform state are now migrated to the direct engine automatically, after a deploy whose dry-run conversion comes back clean. To opt out, set
engine: terraformunderbundleorDATABRICKS_BUNDLE_ENGINE=terraform. See https://docs.databricks.com/aws/en/dev-tools/bundles/direct
CLI
- Fixed idle
databricks ssh connectsessions disconnecting after a few minutes, on dedicated clusters and on serverless. The tunnel now keeps itself warm: the SSH client and the SSH server on the compute exchange keepalives every 30 seconds, and the CLI's proxy pings the tunnel's websocket every 20 seconds. A session nobody is typing into stays connected, with no need to setServerAliveIntervalby hand.
Bundles
bundle planno longer reports a permanent, unconvergeable update onsecurable_kindfor Unity CatalogTABLEsecurables declared under an app'sresources. The field is computed by the backend (output-only), so it is now ignored during drift detection. Direct engine only (#6342).- Add support for the
cluster_policiesresource type in Declarative Automation Bundles. Cluster policies are only supported in direct deployment mode. bundle destroyno longer counts resources that are already gone remotely in itsDestroy: N deletedsummary. Such deletes only clean up stale state and are not listed under the deletion prompt, so they are now excluded from the count as well, matching the terraform engine.bundle destroynow also removes the directory named after the bundle, not just the target directory beneath it, whenworkspace.root_pathends in${bundle.name}/${bundle.target}— which includes the default root path. It is removed non-recursively, so it stays in place while another target of the same bundle is still deployed there. Previously every destroy left an empty directory behind (#6317).job_runsnow plans skip for a run that is still in progress and whenon_bundle_deployis removed, instead of treating either case as an update. (#6357)- Added
DATABRICKS_BUNDLE_RESOURCE_MAX_WAIT(in seconds) to cap how long deploy and destroy wait for a resource. Direct engine only. - Fixed
bundle deployon the direct engine failing withNothing to update, or reporting a change it never applied, when a schema, catalog, volume, registered model or external location field was removed from the configuration or set outside the bundle. The update now sends the fields the plan reports as cleared instead of dropping them.
Dependency Updates
v1.13.0
Release v1.13.0 (2026-08-20)
Notable Changes
bundle deploynow reports the per-resource actions it took, how many files it synced, and a summary of created/changed/deleted/unchanged resources;bundle destroyreports how many resources it deleted.-qprints only the summaries,-qqonly warnings and errors. (#5720)
CLI
databricks aitools installnow supports Goose, installing Databricks agent skills into its skills directory.- Error messages for failed key lookups and variable references now suggest the closest matching key if one is found. (#6208)
- Released binaries are now built against the FIPS 140-3 validated Go Cryptographic Module, with FIPS 140-3 mode enabled by default. TLS connections negotiate only FIPS-approved cipher suites, which drops ChaCha20 and CBC from what the client offers. FIPS mode can be disabled at startup with
GODEBUG=fips140=off, which restores the previous TLS behaviour (#6262). databricks environments setup-localnow removes adatabricks-connectpin from[project].dependencies, an optional-dependency extra, or a dependency group when its version range conflicts with the compute target'sdatabricks-connectversion, souv syncno longer fails with an unsatisfiable resolution when a template ships a conflicting pin. A pin that co-resolves, carries no version, or is marker-gated is left untouched, and each removed pin is reported with the newW_DBCONNECT_CONSOLIDATEDwarning. Wildcard version pins such as==15.1.*are now also checked for conflicts with the environment's constraints.
Bundles
- Allow dashes in the catalog and schema names prompted by
databricks bundle init, and backtick-quote the catalog and schema identifiers in the SQL generated by the built-in templates so names with dashes work at runtime. - Fixed
bundle.git.branch,bundle.git.commit, andbundle.git.origin_urlbeing empty for bundles deployed from a workspace Git folder that has Git CLI access. The workspace API does not report git metadata for those folders, so it is now read from the Repos API instead. - direct: job_runs deploy progress lines now include the resource key (e.g.
Output from job_runs.foo: id=123: ...) so concurrent runs are easier to tell apart. - direct:
resources.job_runscan setlifecycle.triggers.on_bundle_deploy: trueto re-fire the run on every bundle deploy. Removing the trigger does not recreate the existing run. - When migrating a bundle to the direct deployment engine, resources that only the direct engine supports (e.g. instance pools, catalogs) are now skipped by the deploy that migrates the state instead of failing it. They are created by the next deploy, which runs on the migrated state.
- Warn on invalid
secret_scopespermission levels (READ,WRITE,MANAGE); fail underbundle validate --strict. - Reject secret scope permissions that name no principal, instead of failing after the scope is created.
- Write the deployment state atomically so an interrupted save cannot leave a state file that the CLI refuses to read.
- Warn when the deployment state was last written by a newer CLI version than the one running.
- Support pip extras (e.g.
[train]) on local wheels in a job environment'sdependencies(#1602).