CXP-898: add RawId annotations to resources for match_baton_id - #67
agustin-conductor wants to merge 1 commit into
Conversation
C1 uplift matches Terraform-preloaded resources and entitlements (match_baton_id + slug) against the RawId annotation on the resource. Without it, preloaded entitlements never merge and get duplicated. RawId is set to each resource's ID, so groups synced under both the account and workspaces stay unique within the resource type. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Connector PR Review: CXP-898: add RawId annotations to resources for match_baton_idBlocking Issues: 0 | Suggestions: 0 | Threads Resolved: 0 Review SummaryEvery resource builder (account, workspace, group, role, service principal, user) now adds a Security IssuesNone found. Correctness IssuesNone found. SuggestionsNone. |
Summary
Fixes CXP-898. Customers who preload resources and entitlements through Terraform (
match_baton_id) end up with duplicates after sync, because the connector doesn't emit aRawIdannotation.C1's uplift matches preloaded objects against the
RawIdon the resource:match_baton_idequals the resource'sRawId, within the same resource type.match_baton_id, slug), wherematch_baton_idis the parent resource'sRawId.See
pkg/mapper/{resource,entitlement}/v2/uplift.goin c1. C1 never reads RawIds set on entitlements, so none are added here. Only resource-level RawIds made the GCP fix work (baton-google-cloud-platform#37).Changes
Every resource builder now attaches
v2.RawIdset to that resource's ID:account/<acct>/group/<gid>orworkspace/<ws>/group/<gid><role>(account) or<ws>:<role>(workspace)Groups use their composite resource ID because the same Databricks group is synced under both the account and each workspace. A bare Databricks ID could collide within the
groupresource type.Resource, entitlement and grant IDs don't change, so existing syncs are unaffected.
Terraform example:
match_baton_id = "account/<acct>/group/<gid>",slug = "member".Testing
go build ./...,go vet,go test ./...pass.pkg/connector/raw_id_test.gochecks that each resource type carries aRawIdequal to its resource ID. The account resource isn't covered because building it needs a real client.🤖 Generated with Claude Code