<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removing compute policy permissions using Terraform in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/removing-compute-policy-permissions-using-terraform/m-p/119682#M3378</link>
    <description>&lt;P&gt;By default, the "users" and "admins" groups have CAN_USE permission on the Personal Compute policy.&lt;/P&gt;&lt;P&gt;I'm using Terraform and would like to prevent regular users from using this policy to create additional compute clusters.&lt;/P&gt;&lt;P&gt;I haven't found a way to do this. The&amp;nbsp;databricks_permissions resource requires an access_control block with a valid group_name and permission_level.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Because at least one access_control block is required, I must specify some permission.&lt;/LI&gt;&lt;LI&gt;I can't just give the admins CAN_USE here, because the API won't let you modify admin permissions for cluster-policy resources.&lt;/LI&gt;&lt;LI&gt;The only supported permission level is CAN_USE, so I can't set a lower permission level, like CAN_VIEW.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;How can I remove the default permissions from the "users" group here?&lt;/P&gt;&lt;PRE&gt;resource "databricks_permissions" "personal_compute_policy" {&lt;BR /&gt;  cluster_policy_id = data.databricks_cluster_policy.personal_compute.id&lt;BR /&gt;&lt;BR /&gt;  access_control {&lt;BR /&gt;    group_name = "users"&lt;BR /&gt;    permission_level = "CAN_USE"&lt;BR /&gt;  }&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;data "databricks_cluster_policy" "personal_compute" {&lt;BR /&gt;  name = "Personal Compute"&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 03:39:01 GMT</pubDate>
    <dc:creator>mzs</dc:creator>
    <dc:date>2025-05-20T03:39:01Z</dc:date>
    <item>
      <title>Removing compute policy permissions using Terraform</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-compute-policy-permissions-using-terraform/m-p/119682#M3378</link>
      <description>&lt;P&gt;By default, the "users" and "admins" groups have CAN_USE permission on the Personal Compute policy.&lt;/P&gt;&lt;P&gt;I'm using Terraform and would like to prevent regular users from using this policy to create additional compute clusters.&lt;/P&gt;&lt;P&gt;I haven't found a way to do this. The&amp;nbsp;databricks_permissions resource requires an access_control block with a valid group_name and permission_level.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Because at least one access_control block is required, I must specify some permission.&lt;/LI&gt;&lt;LI&gt;I can't just give the admins CAN_USE here, because the API won't let you modify admin permissions for cluster-policy resources.&lt;/LI&gt;&lt;LI&gt;The only supported permission level is CAN_USE, so I can't set a lower permission level, like CAN_VIEW.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;How can I remove the default permissions from the "users" group here?&lt;/P&gt;&lt;PRE&gt;resource "databricks_permissions" "personal_compute_policy" {&lt;BR /&gt;  cluster_policy_id = data.databricks_cluster_policy.personal_compute.id&lt;BR /&gt;&lt;BR /&gt;  access_control {&lt;BR /&gt;    group_name = "users"&lt;BR /&gt;    permission_level = "CAN_USE"&lt;BR /&gt;  }&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;data "databricks_cluster_policy" "personal_compute" {&lt;BR /&gt;  name = "Personal Compute"&lt;BR /&gt;}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 03:39:01 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-compute-policy-permissions-using-terraform/m-p/119682#M3378</guid>
      <dc:creator>mzs</dc:creator>
      <dc:date>2025-05-20T03:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Removing compute policy permissions using Terraform</title>
      <link>https://community.databricks.com/t5/administration-architecture/removing-compute-policy-permissions-using-terraform/m-p/119829#M3385</link>
      <description>&lt;P&gt;I learned the Personal Compute policy can be turned off at the account level:&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/databricks/admin/clusters/personal-compute#manage-policy" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/databricks/admin/clusters/personal-compute#manage-policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 04:44:11 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/removing-compute-policy-permissions-using-terraform/m-p/119829#M3385</guid>
      <dc:creator>mzs</dc:creator>
      <dc:date>2025-05-21T04:44:11Z</dc:date>
    </item>
  </channel>
</rss>

