Skip to content

Releases: databricks/cli

v1.19.0

Choose a tag to compare

@oss-cli oss-cli released this 30 Sep 13:13
Immutable release. Only release title and notes can be modified.
0365164

CLI

  • Honor CLAUDE_CONFIG_DIR in aitools commands. (#6838)
  • Added --ttl and --no-expiry flags to databricks postgres create-branch so a branch's expiration can be set without hand-writing a --json spec. --ttl accepts the REST API duration form (604800s), a Go duration (168h), or day/week units (7d, 3w); --no-expiry creates a branch that never expires. One of --ttl, --no-expiry, or a spec expiration in --json is required. (#6313)
  • databricks ssh connect serverless sessions now provide Claude Code and Codex configured with Unity Gateway out of the box. (#6885)

AI Runtime

  • Add databricks air images push (Preview) to configure Docker authentication and push container images to Databricks Artifact Registry. (#6869)
  • air run now grants the configured permissions on the MLflow experiment as well as the job. (#6870)

Bundles

  • Add libraries field to clusters. (#6831)
  • Error out when a configured workspace_id does not match the connected workspace, instead of silently using it in resource URLs emitted by bundle summary. (#6754)
  • Fix spurious recreation of Lakebase (Postgres) branches, roles, and catalogs when the referenced project is updated in place: an in-place project change (e.g. display_name) no longer forces a delete + create of resources that reference the project's or branch's name. (#6865)
  • Direct engine now detects and applies an explicitly configured integer zero (e.g. gcp_attributes.local_ssd_count: 0) added to a resource first deployed without the field. (#6867)
  • Migrate existing Terraform deployment state to the direct engine before deploying (previously done after a Terraform deploy), so the deploy runs on the direct engine. (#6749)
  • The postgres_snapshot_schedules resource (introduced in v1.16.0) is now marked Beta and is no longer available in PyDABs, matching the other postgres_* resources; configure it in YAML instead. (#6887)

v1.18.0

Choose a tag to compare

@oss-cli oss-cli released this 24 Sep 12:36
Immutable release. Only release title and notes can be modified.
47b22a2

Release v1.18.0 (2026-09-24)

CLI

  • The AI Runtime commands have moved to databricks air. The previous databricks experimental air path now directs users to the new command. (#6722)
  • Write local state, cache, and config files atomically so an interrupted or concurrent write cannot corrupt them. (#6708)
  • Deprecate --region in databricks auth docker configure ahead of its removal in the next release, infer the Artifact Registry region when it is omitted, and add databricks auth docker host --profile <name> to show the profile's registry host and credential-helper status. (#6782)
  • Return UNAUTHENTICATED instead of INVALID_REFRESH_TOKEN when databricks auth token --output json cannot refresh a cached U2M token. (#6731)
  • Retry the current-user (SCIM Me) lookup on transient HTTP 500 responses so a temporarily-unavailable backend no longer fails bundle commands outright. (#6766)
  • Preserve workspace-file and volume access for SSH server descendants when the bootstrap notebook exits and the server survives. (#6645)
  • ssh connect and ssh setup now accept a --keep-detached-processes flag to keep processes detached from the SSH session (tmux, setsid, nohup) running after the tunnel shuts down. Teardown then terminates only the tunnel's own process group, and the bootstrap job run is held open while any detached process is still running, so the survivors keep their /Workspace and /Volumes access. A held-open run also suppresses cluster autotermination, so the flag is off by default, is bounded by --server-timeout, and is dedicated-cluster only. Without it, the server now logs a warning naming the detached processes it is about to destroy, instead of sweeping them silently. (#6387)

Bundles

  • direct: Allow clearing a catalog's or schema's custom_max_retention_hours by removing it from configuration. (#6792)
  • direct: Allow clearing a genie space's description and a secret's comment by removing them from configuration. (#6789)
  • Fix direct-engine deploy recreating an MLflow experiment on every deploy when its trace_location was set out-of-band. (#6787)
  • direct: Store a Genie space's serialized_space in state as a content hash instead of its full contents. (#6707)
  • Fix bundle deploy failing with "Invalid python file reference" for jobs that use git_source with a spark_python_task on the direct engine. (#6751)
  • Fixed the direct engine mishandling UC grants that combine ALL_PRIVILEGES with a privilege it does not imply (MANAGE, READ_METADATA, EXTERNAL_USE_SCHEMA, EXTERNAL_USE_LOCATION): such privileges were dropped when granted and left behind when revoked, so the deployment never converged. (#6733, #6743)
  • Don't fail migration if clean up actions fail. (#6772)
  • Ignore the backend-provided spark.sql.ansi.enabled: "true" pipeline configuration default when detecting direct-engine drift. (#6816)
  • Fix recreating a postgres synced table sometimes failing with a 409 ALREADY_EXISTS error while the previous table is still being deleted. (#6728)
  • Direct engine no longer recreates a resource when an immutable field the config omits was populated by the backend. (#6790)

Dependency Updates

  • Bump dependencies with known vulnerabilities. (#6723)
  • Bump github.com/databricks/databricks-sdk-go from v0.178.0 to v0.182.0. (#6817)
  • Bump the Databricks Terraform provider from v1.132.0 to v1.134.0. (#6818)

v1.17.0

Choose a tag to compare

@oss-cli oss-cli released this 16 Sep 14:34
Immutable release. Only release title and notes can be modified.
7ef3e5c

Release v1.17.0

Notable Changes

  • Bump the direct deployment state version to 3. Clients older than v1.8.0 will reject bundles deployed with this release. (#6713)

CLI

  • Add an INVALID_REFRESH_TOKEN error code to databricks auth token --output json failures. (#6684)
  • Add experimental databricks auth docker configure to configure Docker credential helper access for Databricks Artifact Registry. (#6700)
  • Add experimental databricks auth docker token to generate Docker credentials for Databricks Artifact Registry. (#6699)
  • databricks environments setup-local now reports the E_PROVISION_CONFLICT error code instead of the generic E_PROVISION when uv sync fails to resolve a dependency conflict. (#6666)
  • Preserve SSH sessions across temporary tunnel disconnects, with bounded replay and backpressure for large transfers. (#6650)
  • Allow OAuth U2M logins to override the CLI client ID with --client-id, profile client_id, or DATABRICKS_CLIENT_ID. (#6594)

Bundles

  • direct: Store a dashboard's serialized_dashboard in state as a content hash instead of its full contents. (#6105)
  • direct: Fix pipelines recreation when the whole ingestion_definition block is added or removed. (#6589)
  • bundle plan, deploy, and destroy no longer report removing permissions, grants, or secret scope ACLs from a bundle as a deletion, since it leaves the resource untouched. (#6647)
  • bundle plan and deploy no longer list or count a resource that was already deleted remotely as a deletion, matching bundle destroy; applying still cleans up its stale state entry. (#6675)
  • Fix bundle run failing with expected an int, found a string when an unrelated resource references another resource that is not deployed. bundle run now resolves ${resources.*} references only within the resource being run. (#6690)
  • Add grants support for the AI Gateway model_service, mcp_service, and model_provider_service resources (direct engine). (#6635)
  • Add bundle support for the AI Gateway mcp_service resource (direct engine). (#6633)
  • Add bundle support for the AI Gateway model_provider_service resource (direct engine). (#6634)
  • Add bundle support for the AI Gateway model_service resource (direct engine). (#6525)
  • Prevent resource drift on catalogs if storage_root contained a trailing slash in the URL. (#6622)
  • Fixed a "lineage mismatch in state files" error that could occur after destroying a bundle and redeploying it from another machine. bundle destroy now removes the local state file so no stale lineage is left behind, and prunes the state directories it leaves empty (such as .internal/ and sync-snapshots/). (#6210, #6685)
  • direct: bundle plan no longer reports a permanent update on a cluster that uses a cluster policy: when the cluster spec sets policy_id, a field present in the remote but absent from the bundle config is not treated as drift. (#6531)
  • bundle deploy on the direct engine now reports each resource as soon as it is deployed, instead of listing them all after the deployment finishes. A deploy that fails part way through now reports the resources it did apply. (#6361)
  • Direct-engine bundles no longer flag phantom drift on server-populated nested fields under reused config types (e.g. external_locations file-event-queue resource IDs, database_instances parent-instance refs, apps git credential ID). (#6618)
  • databricks bundle generate app now reproduces a git-backed app's git_repository and git_source configuration instead of emitting a workspace source_code_path, so generating from a Git-deployed app no longer silently converts it to workspace source. (#6656)
  • Improved configuration load time for bundles with many included files. (#6195)
  • bundle destroy no longer deletes triggered job runs, leaving them untouched on the backend. (#6672)
  • direct: resources.job_runs: new lifecycle.triggers.on_file_change setting to restart the run when monitored files change. Can be set to a series of paths or globs. (#6309)
  • Bundle summary now shows a name for Postgres branches, endpoints, databases, and roles instead of a blank Name field. (#6663)
  • Added PyDABs (Python) support for cluster policies, dashboards, and Genie spaces. (#6585)
  • CLI commands no longer imply that a resource whose type has no workspace URL is merely not deployed yet. (#6583)
  • Capture the implicit dependency a vector search index has on a catalog or schema defined in the same bundle, so the catalog and schema are deployed first. (#6655)

Dependency Updates

  • Bump dependencies with known vulnerabilities. (#6695)
  • Bump github.com/databricks/databricks-sdk-go from v0.177.0 to v0.178.0. (#6673)
  • Bump Terraform provider from v1.131.0 to v1.132.0. (#6671)

v1.16.1

Choose a tag to compare

@oss-cli oss-cli released this 10 Sep 16:22
Immutable release. Only release title and notes can be modified.
e7f04d0

Release v1.16.1

CLI

  • Revert tunnel resume layer to fix SSH transfer regression in v1.16.0 affecting transfers larger than 1 MiB. (#6608, #6612)

v1.16.0

Choose a tag to compare

@oss-cli oss-cli released this 09 Sep 13:48
Immutable release. Only release title and notes can be modified.
d9988db

Release v1.16.0

CLI

  • aitools install now registers the official Claude marketplace if it is missing before installing the Databricks Claude plugin. (#6485)
  • databricks aitools install --output json now reports an error_category for a failed or skipped install (per agent, and at the top level for a failure with no per-agent entry), giving coding agents and CI a stable classification of why an install did not complete. (#6482)
  • databricks aitools install honors --output json, emitting a structured {scope, agents[...]} document that reports each agent's delivery and install status so coding agents and CI can consume the result without scraping the text output. JSON mode requires --scope and --agents so the command runs without interactive prompts. (#6481)
  • databricks bundle sync now prints sync progress (Action: PUT, Uploaded ...) by default, matching databricks sync. Previously it was silent unless --output was passed. Use --output json for machine-readable output. (#6568)
  • Support major-only DBR runtime versions such as 19.x-scala2.13 in the cluster picker used by databricks auth login --configure-cluster and databricks labs. (#6574)
  • Deprecated the databricks environments setup-local --constraints-only flag in favour of the orthogonal --no-dbconnect; the flag still works as a hidden alias but is hidden from --help and prints a one-line deprecation notice, and will be removed in a later release. (#6470)
  • Add orthogonal --no-constraints and --no-dbconnect flags to databricks environments setup-local: --no-constraints skips writing the remote Python-version and dependency pins, and --no-dbconnect skips the databricks-connect dependency. (#6464)
  • databricks environments setup-local now reports a distinct E_PROVISION_CONFLICT error code in --output json when the project's dependencies conflict with the pins written for the target environment, making the requirements unsatisfiable (the same conflict surfaced as a W_USER_CONSTRAINT_CONFLICT warning); it is reported after the project files are written, without attempting the doomed provisioning, while other provisioning failures continue to report E_PROVISION. (#6479)
  • databricks ssh connect and ssh setup now verify the tunnel's SSH host key against the key the workspace published for the connection, recorded in ~/.databricks/ssh-tunnel-known-hosts/<name> instead of ~/.ssh/known_hosts. Reconnecting with a name used before no longer fails with Host key verification failed when the compute behind that name changed, and no longer needs a manual ssh-keygen -R; host blocks written by an earlier databricks ssh setup pick this up once you re-run it. (#6557)
  • Stop databricks ssh connect --ide from adding a duplicate entry to the IDE's Remote Explorer on every connect: the remote authority is now the SSH host alias alone, instead of embedding the per-instance remote OS user. (#6550)
  • Add --max-clients and --server-timeout flags to databricks ssh setup, and --server-timeout to databricks ssh connect. Both are fixed when the SSH tunnel server job is submitted, so ssh setup now serializes them into the generated ProxyCommand instead of falling back to the built-in defaults. (#6547)
  • ssh connect sessions no longer end when the tunnel's websocket connection is lost. The CLI reattaches to the running session and replays the bytes that were missed, so the shell and everything running in it stay intact, and a transient failure to open a replacement connection for the periodic auth refresh is retried rather than ending the session. Reattaching requires an SSH server started by a CLI that supports it; against an older server the connection behaves as before. (#6558)

Bundles

  • Added PyDABs (Python) support for secrets: Resources.add_secret and the secret_mutator decorator. (#6553)
  • Fix job and pipeline environment dependencies with a * version wildcard (e.g. numpy==2.5.*) being treated as local file paths. (#6555)
  • Add the postgres_snapshot_schedules bundle resource for managing a Lakebase Postgres branch's automatic-snapshot schedule (direct deployment engine only). (#6449)

Dependency Updates

  • Bump github.com/databricks/databricks-sdk-go from v0.175.0 to v0.177.0. (#6448)
  • Bump Terraform provider from v1.128.0 to v1.131.0. (#6544)

v1.15.0

Choose a tag to compare

@oss-cli oss-cli released this 03 Sep 10:12
Immutable release. Only release title and notes can be modified.
52835e6

Release v1.15.0 (2026-09-03)

CLI

  • When uv python install fails, databricks environments setup-local now falls back to a compatible Python interpreter already installed on the machine. (#6457)
  • Allow databricks environments setup-local to update pyproject.toml files containing TOML multi-line strings. (#6445)

Bundles

  • Before committing the automatic terraform→direct migration, run a deployment plan against the converted state; if the plan fails the migration is abandoned. (#6486)
  • The dbt-sql bundle template now uses Databricks Runtime 16.4 LTS (up from 15.4 LTS) for classic (non-serverless) compute. (#6418)
  • Fixed the direct engine silently ignoring edits to duration and timestamp fields, such as a Lakebase endpoint's suspend_timeout_duration. Such a change planned 0 to change and was never applied. (#6377)
  • Fixed $${...} not escaping a literal ${...} on the direct engine, which failed with an invalid dependency error. (#6484, #6489)
  • Remove forward_user_access_token from update_mask for Apps because it's not supported. Fixes regression in 1.14.1. (#6510)
  • direct: Fix deploying an update to postgres_projects.default_endpoint_settings. (#6440)
  • direct: Fix deploying an update to postgres_endpoints.settings.pg_settings. (#6441)
  • direct: Fix deploying an update to expire_time, ttl or suspend_timeout_duration on Lakebase resources. (#6443)
  • Added PyDABs (Python) support for catalogs: Resources.add_catalog and the catalog_mutator decorator. (#6408)
  • Bundle templates now use serverless environment version 5, which offers better performance, and databricks-connect 16.4. (#6378)
  • Fixed a job with a table_update trigger never converging on the direct engine. (#6442)

Dependency Updates

  • Bump Go toolchain to 1.26.8. (#6476)

v1.14.1

Choose a tag to compare

@oss-cli oss-cli released this 28 Aug 11:08
Immutable release. Only release title and notes can be modified.
c00e54b

Release v1.14.1

Bundles

  • Fix bundle deploy failing with deployment_source.source_code_path cannot be set on UpdateApp (400) when updating an app that has an active deployment (#6401).
  • Fixed ${resources...} references to resource keys starting with an underscore (e.g. _my_job). On the direct engine, deploying such a resource with permissions or grants failed with cannot parse "/jobs/${resources.jobs._my_job.id}", and user-written references to it were silently left unresolved (#6422)

v1.14.0

Choose a tag to compare

@oss-cli oss-cli released this 26 Aug 12:35
Immutable release. Only release title and notes can be modified.
80dbcba

Notable Changes

  • Bundles still on Terraform state are now migrated to the direct engine automatically, after a deploy whose dry-run conversion comes back clean. To opt out, set engine: terraform under bundle or DATABRICKS_BUNDLE_ENGINE=terraform. See https://docs.databricks.com/aws/en/dev-tools/bundles/direct

CLI

  • Fixed idle databricks ssh connect sessions disconnecting after a few minutes, on dedicated clusters and on serverless. The tunnel now keeps itself warm: the SSH client and the SSH server on the compute exchange keepalives every 30 seconds, and the CLI's proxy pings the tunnel's websocket every 20 seconds. A session nobody is typing into stays connected, with no need to set ServerAliveInterval by hand.

Bundles

  • bundle plan no longer reports a permanent, unconvergeable update on securable_kind for Unity Catalog TABLE securables declared under an app's resources. The field is computed by the backend (output-only), so it is now ignored during drift detection. Direct engine only (#6342).
  • Add support for the cluster_policies resource type in Declarative Automation Bundles. Cluster policies are only supported in direct deployment mode.
  • bundle destroy no longer counts resources that are already gone remotely in its Destroy: N deleted summary. Such deletes only clean up stale state and are not listed under the deletion prompt, so they are now excluded from the count as well, matching the terraform engine.
  • bundle destroy now also removes the directory named after the bundle, not just the target directory beneath it, when workspace.root_path ends in ${bundle.name}/${bundle.target} — which includes the default root path. It is removed non-recursively, so it stays in place while another target of the same bundle is still deployed there. Previously every destroy left an empty directory behind (#6317).
  • job_runs now plans skip for a run that is still in progress and when on_bundle_deploy is removed, instead of treating either case as an update. (#6357)
  • Added DATABRICKS_BUNDLE_RESOURCE_MAX_WAIT (in seconds) to cap how long deploy and destroy wait for a resource. Direct engine only.
  • Fixed bundle deploy on the direct engine failing with Nothing to update, or reporting a change it never applied, when a schema, catalog, volume, registered model or external location field was removed from the configuration or set outside the bundle. The update now sends the fields the plan reports as cleared instead of dropping them.

Dependency Updates

  • Bump github.com/databricks/databricks-sdk-go from v0.171.0 to v0.175.0 (#6322).
  • Bump Terraform provider from v1.127.0 to v1.128.0 (#6323).

v1.13.0

Choose a tag to compare

@oss-cli oss-cli released this 20 Aug 13:59
Immutable release. Only release title and notes can be modified.
8dc3c2e

Release v1.13.0 (2026-08-20)

Notable Changes

  • bundle deploy now reports the per-resource actions it took, how many files it synced, and a summary of created/changed/deleted/unchanged resources; bundle destroy reports how many resources it deleted. -q prints only the summaries, -qq only warnings and errors. (#5720)

CLI

  • databricks aitools install now supports Goose, installing Databricks agent skills into its skills directory.
  • Error messages for failed key lookups and variable references now suggest the closest matching key if one is found. (#6208)
  • Released binaries are now built against the FIPS 140-3 validated Go Cryptographic Module, with FIPS 140-3 mode enabled by default. TLS connections negotiate only FIPS-approved cipher suites, which drops ChaCha20 and CBC from what the client offers. FIPS mode can be disabled at startup with GODEBUG=fips140=off, which restores the previous TLS behaviour (#6262).
  • databricks environments setup-local now removes a databricks-connect pin from [project].dependencies, an optional-dependency extra, or a dependency group when its version range conflicts with the compute target's databricks-connect version, so uv sync no longer fails with an unsatisfiable resolution when a template ships a conflicting pin. A pin that co-resolves, carries no version, or is marker-gated is left untouched, and each removed pin is reported with the new W_DBCONNECT_CONSOLIDATED warning. Wildcard version pins such as ==15.1.* are now also checked for conflicts with the environment's constraints.

Bundles

  • Allow dashes in the catalog and schema names prompted by databricks bundle init, and backtick-quote the catalog and schema identifiers in the SQL generated by the built-in templates so names with dashes work at runtime.
  • Fixed bundle.git.branch, bundle.git.commit, and bundle.git.origin_url being empty for bundles deployed from a workspace Git folder that has Git CLI access. The workspace API does not report git metadata for those folders, so it is now read from the Repos API instead.
  • direct: job_runs deploy progress lines now include the resource key (e.g. Output from job_runs.foo: id=123: ...) so concurrent runs are easier to tell apart.
  • direct: resources.job_runs can set lifecycle.triggers.on_bundle_deploy: true to re-fire the run on every bundle deploy. Removing the trigger does not recreate the existing run.
  • When migrating a bundle to the direct deployment engine, resources that only the direct engine supports (e.g. instance pools, catalogs) are now skipped by the deploy that migrates the state instead of failing it. They are created by the next deploy, which runs on the migrated state.
  • Warn on invalid secret_scopes permission levels (READ, WRITE, MANAGE); fail under bundle validate --strict.
  • Reject secret scope permissions that name no principal, instead of failing after the scope is created.
  • Write the deployment state atomically so an interrupted save cannot leave a state file that the CLI refuses to read.
  • Warn when the deployment state was last written by a newer CLI version than the one running.
  • Support pip extras (e.g. [train]) on local wheels in a job environment's dependencies (#1602).

Dependency Updates

  • Bump github.com/databricks/databricks-sdk-go from v0.170.0 to v0.171.0 (#6320).
  • Bump the Databricks Terraform provider to 1.127.0 (#6319).
  • Bump Go toolchain to 1.26.6 (#6266).
  • Bump Go toolchain to 1.26.7 (#6325).

v1.12.1

Choose a tag to compare

@oss-cli oss-cli released this 12 Aug 14:33
Immutable release. Only release title and notes can be modified.
1752dfa

Release v1.12.1

Dependency Updates

  • Bump github.com/databricks/databricks-sdk-go from v0.166.0 to v0.170.0 (#6251).