Secret Scopes

Package: databricks.bundles.secret_scopes

Classes

class AzureKeyVaultSecretScopeMetadata

The metadata of the Azure KeyVault for a secret scope of type AZURE_KEYVAULT

dns_name: str

The DNS of the KeyVault

resource_id: str

The resource id of the azure KeyVault that user wants to associate the scope with.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class Lifecycle
prevent_destroy: bool | None = None

Lifecycle setting to prevent the resource from being destroyed.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class ScopeBackendType

The types of secret scope backends in the Secret Manager. Azure KeyVault backed secret scopes will be supported in a later release.

DATABRICKS = 'DATABRICKS'
AZURE_KEYVAULT = 'AZURE_KEYVAULT'
class SecretScope
name: str

Scope name requested by the user. Scope names are unique.

backend_type: ScopeBackendType | None = None

The backend type the scope will be created with. If not specified, will default to DATABRICKS

keyvault_metadata: AzureKeyVaultSecretScopeMetadata | None = None

The metadata for the secret scope if the backend_type is AZURE_KEYVAULT

lifecycle: Lifecycle | None = None

Settings that control the deployment lifecycle of the resource, such as preventing it from being destroyed.

permissions: list[SecretScopePermission]

The permissions to apply to the secret scope. Permissions are managed via secret scope ACLs.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class SecretScopePermission
level: SecretScopePermissionLevel

The permission level to apply. The allowed levels depend on the resource type.

group_name: str | None = None

The name of the group granted the permission level. This field translates to a principal field in secret scope ACL.

service_principal_name: str | None = None

The application ID of an active service principal. This field translates to a principal field in secret scope ACL.

user_name: str | None = None

The name of the user granted the permission level. This field translates to a principal field in secret scope ACL.

classmethod from_dict(
value: dict,
) → Self
as_dict(
self,
) → dict
class SecretScopePermissionLevel
READ = 'READ'
WRITE = 'WRITE'
MANAGE = 'MANAGE'