<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>All board posts in Databricks Platform Discussions</title>
    <link>https://community.databricks.com/t5/databricks-platform-discussions/ct-p/databricks-platform-discussion</link>
    <description>All board posts in Databricks Platform Discussions</description>
    <pubDate>Tue, 11 Aug 2026 08:32:19 GMT</pubDate>
    <dc:creator>databricks-platform-discussion</dc:creator>
    <dc:date>2026-08-11T08:32:19Z</dc:date>
    <item>
      <title>Azure Databricks Default Package Repository with Azure Key Vault-backed Secret Scope</title>
      <link>https://community.databricks.com/t5/administration-architecture/azure-databricks-default-package-repository-with-azure-key-vault/m-p/165320#M5507</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m trying to configure Default Python Package Repository in an Azure Databricks workspace and would like to clarify whether the predefined secret scope can be backed by Azure Key Vault.&lt;/P&gt;&lt;P&gt;According to the documentation, Default Package Repository can use the predefined secret scope:&lt;/P&gt;&lt;P&gt;databricks-package-management&lt;/P&gt;&lt;P&gt;with the following keys:&lt;/P&gt;&lt;P&gt;pip-index-url&lt;BR /&gt;pip-extra-index-urls&lt;BR /&gt;pip-cert&lt;/P&gt;&lt;P&gt;The documentation shows an example using:&lt;/P&gt;&lt;P&gt;databricks secrets create-scope databricks-package-management followed by put-secret commands.&lt;/P&gt;&lt;P&gt;However, I cannot find an explicit statement saying that databricks-package-management must be a Databricks-backed secret scope.&lt;/P&gt;&lt;P&gt;The documentation also describes two types of secret scopes, including Azure Key Vault-backed scopes. An Azure Key Vault-backed scope is read-only from the Databricks side, so the secrets would be created directly in Azure Key Vault rather than using databricks secrets put-secret.&lt;/P&gt;&lt;P&gt;My question is:&lt;/P&gt;&lt;P&gt;Has anyone successfully configured Default Package Repository using databricks-package-management as an Azure Key Vault-backed secret scope?&lt;/P&gt;&lt;P&gt;I have already tested this configuration. The Key Vault-backed scope exists and contains pip-index-url, and Databricks can read the secret through the scope.&lt;/P&gt;&lt;P&gt;However, I cannot specify the secret scope in the Default Package Repositories UI, and I would like to understand whether Databricks automatically resolves the predefined databricks-package-management scope or whether this functionality specifically requires a Databricks-backed scope.&lt;/P&gt;&lt;P&gt;Has anyone tested this configuration and got it working?&lt;/P&gt;&lt;P&gt;Alternatively, does anyone have official information or a technical reference confirming that databricks-package-management must use a Databricks-backed scope and cannot use an Azure Key Vault-backed scope?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 08:19:09 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/azure-databricks-default-package-repository-with-azure-key-vault/m-p/165320#M5507</guid>
      <dc:creator>kfadratek</dc:creator>
      <dc:date>2026-08-11T08:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Google Drive ingestion pipeline failing – “Google Drive file system is not enabled”</title>
      <link>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165318#M55418</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Lakeflow Connect for Google Drive requires &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Serverless Compute&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Unity Catalog Account-level feature flags&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt; Databricks Community / Free Edition runs on a restricted, shared classic compute environment where Lakeflow Connect preview connectors and serverless ingestion infrastructure are disabled.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 07:45:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165318#M55418</guid>
      <dc:creator>sridhar_dbx</dc:creator>
      <dc:date>2026-08-11T07:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Google Drive ingestion pipeline failing – “Google Drive file system is not enabled”</title>
      <link>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165314#M55417</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247406"&gt;@hj648&lt;/a&gt;&amp;nbsp;, Google authentication is limited on the Databricks free edition.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ShamenParis_0-1786431679086.png" style="width: 400px;"&gt;&lt;img src="https://community.databricks.com/t5/image/serverpage/image-id/29874iB053E6218AE811F9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ShamenParis_0-1786431679086.png" alt="ShamenParis_0-1786431679086.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For more information:&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/getting-started/free-edition-limitations" target="_blank"&gt;https://docs.databricks.com/aws/en/getting-started/free-edition-limitations&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 07:04:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165314#M55417</guid>
      <dc:creator>ShamenParis</dc:creator>
      <dc:date>2026-08-11T07:04:05Z</dc:date>
    </item>
    <item>
      <title>Solution: Simplify Genie Agent Instruction Updates Across Multiple Spaces</title>
      <link>https://community.databricks.com/t5/data-engineering/solution-simplify-genie-agent-instruction-updates-across/m-p/165309#M55416</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;As the number of Genie Agents grows, maintaining consistent instructions across multiple Genie Spaces becomes increasingly cumbersome. Updating the same instructions manually in each space requires significant effort and is both time-consuming and error-prone.&lt;/P&gt;&lt;P&gt;To simplify this process, we have created a notebook-based solution that automatically updates Genie instructions across multiple spaces. To use it, simply replace the following values in the notebook:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Genie Space IDs&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Databricks Workspace URL&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Personal Access Token (PAT)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Desired Instructions&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Once configured, the notebook will automatically apply the same instructions to all specified Genie Spaces, eliminating the need for repetitive manual updates.&lt;/P&gt;&lt;P&gt;This should significantly reduce maintenance effort and ensure consistency across your Genie Agents.&lt;/P&gt;&lt;P&gt;Attached notebook code:&lt;/P&gt;&lt;P&gt;================================start here====================================&lt;/P&gt;&lt;P&gt;import requests&lt;BR /&gt;import json&lt;/P&gt;&lt;P&gt;workspace_url = "&amp;lt;your databricks workspace url"&lt;BR /&gt;token = "&amp;lt;your PAT token"&lt;/P&gt;&lt;P&gt;headers = {&lt;BR /&gt;"Authorization": f"Bearer {token}",&lt;BR /&gt;"Content-Type": "application/json"&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;space_ids = [&lt;BR /&gt;"&amp;lt;genie space id 1&amp;gt;",&lt;BR /&gt;"&amp;lt;genie space id 2&amp;gt;",&lt;BR /&gt;"&amp;lt;genie space id n&amp;gt;&lt;BR /&gt;]&lt;/P&gt;&lt;P&gt;NEW_INSTRUCTION = """&lt;BR /&gt;Your Role: Databricks SQL Analyst.&lt;BR /&gt;Rule 1: Use only tables, columns, joins, and logic defined in this Genie space. Never invent any.&lt;BR /&gt;Rule 2: Before generating a query, validate all rules.&lt;BR /&gt;&amp;lt;Your extended prompt Rules&amp;gt;&lt;BR /&gt;"""&lt;/P&gt;&lt;P&gt;for space_id in space_ids:&lt;BR /&gt;try:&lt;BR /&gt;# Get existing space&lt;BR /&gt;url = f"{workspace_url}/api/2.0/genie/spaces/{space_id}"&lt;BR /&gt;response = requests.get(&lt;BR /&gt;f"{url}?include_serialized_space=true",&lt;BR /&gt;headers=headers&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;response.raise_for_status()&lt;/P&gt;&lt;P&gt;space = response.json()&lt;/P&gt;&lt;P&gt;serialized = json.loads(space["serialized_space"])&lt;/P&gt;&lt;P&gt;# Replace instructions&lt;BR /&gt;serialized["instructions"]["text_instructions"] = [{&lt;BR /&gt;"content": [NEW_INSTRUCTION]&lt;BR /&gt;}]&lt;/P&gt;&lt;P&gt;payload = {&lt;BR /&gt;"serialized_space": json.dumps(serialized)&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;update_resp = requests.patch(&lt;BR /&gt;url,&lt;BR /&gt;headers=headers,&lt;BR /&gt;json=payload&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;print(&lt;BR /&gt;f"{space_id}: {update_resp.status_code}"&lt;BR /&gt;)&lt;BR /&gt;except requests.exceptions.RequestException as e:&lt;BR /&gt;print(f"{space_id}: Request failed - {e}")&lt;BR /&gt;except Exception as e:&lt;BR /&gt;print(f"{space_id}: Unexpected error - {e}")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;=========================================end here================================&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 05:54:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/solution-simplify-genie-agent-instruction-updates-across/m-p/165309#M55416</guid>
      <dc:creator>harisrinivasay</dc:creator>
      <dc:date>2026-08-11T05:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Google Drive ingestion pipeline failing – “Google Drive file system is not enabled”</title>
      <link>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165305#M55415</link>
      <description>&lt;P&gt;Thanks for the suggestion. I’ll check whether this limitation is specific to the Free edition. Appreciate your help!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 03:53:24 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165305#M55415</guid>
      <dc:creator>hj648</dc:creator>
      <dc:date>2026-08-11T03:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Requesting free/discounted voucher for Data Engineer Associate certification exam</title>
      <link>https://community.databricks.com/t5/data-engineering/requesting-free-discounted-voucher-for-data-engineer-associate/m-p/165302#M55414</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247057"&gt;@Rahulkumar65&lt;/a&gt;&amp;nbsp;&lt;SPAN&gt;Vouchers are distributed to the eligible participants after the Learning Festival. Lookout for the next one in October. If your organisation is a partner of Databricks, then check with your admin.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 03:22:37 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/requesting-free-discounted-voucher-for-data-engineer-associate/m-p/165302#M55414</guid>
      <dc:creator>Sumit_7</dc:creator>
      <dc:date>2026-08-11T03:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Google Drive ingestion pipeline failing – “Google Drive file system is not enabled”</title>
      <link>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165299#M55413</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247406"&gt;@hj648&lt;/a&gt;&amp;nbsp;First assumption is that may be its the limitation of Free edition. Other members may help here.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 03:19:30 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165299#M55413</guid>
      <dc:creator>Sumit_7</dc:creator>
      <dc:date>2026-08-11T03:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Creating Databricks agent</title>
      <link>https://community.databricks.com/t5/data-engineering/creating-databricks-agent/m-p/165295#M55412</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/147238"&gt;@DineshOjha&lt;/a&gt;&amp;nbsp;This doc will be useful in proceeding&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/agents/" target="_blank"&gt;https://docs.databricks.com/aws/en/agents/&lt;/A&gt;. Give it a try and let me know.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 03:04:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/creating-databricks-agent/m-p/165295#M55412</guid>
      <dc:creator>Sumit_7</dc:creator>
      <dc:date>2026-08-11T03:04:08Z</dc:date>
    </item>
    <item>
      <title>Creating Databricks agent</title>
      <link>https://community.databricks.com/t5/data-engineering/creating-databricks-agent/m-p/165282#M55411</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are trying to create a Databricks agent and were looking for a step by step approach if there is any. We did go through the&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/agents/custom-agents/author-agent" target="_blank"&gt;Author an agent and deploy it on Databricks Apps | Databricks on AWS&lt;/A&gt;&amp;nbsp;but weren't very clear on creation of a new agent.&lt;/P&gt;&lt;P&gt;We are working on a migration project, moving data from Hive to Databricks, so we want to create a data validation agent which can query both hive and databricks.&lt;/P&gt;&lt;P&gt;Can you please guide us on how to proceed?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 22:30:42 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/creating-databricks-agent/m-p/165282#M55411</guid>
      <dc:creator>DineshOjha</dc:creator>
      <dc:date>2026-08-10T22:30:42Z</dc:date>
    </item>
    <item>
      <title>Google Drive ingestion pipeline failing – “Google Drive file system is not enabled”</title>
      <link>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165274#M55410</link>
      <description>&lt;P class=""&gt;Hello Databricks Community,&lt;/P&gt;&lt;P&gt;I am using &lt;STRONG&gt;Databricks Free Edition&lt;/STRONG&gt; and trying to ingest a CSV file from Google Drive using &lt;STRONG&gt;Data Engineering → Data Ingestion → Ingest data from Google Drive&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The pipeline validation is failing with the following error:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Pipeline validation error&lt;/STRONG&gt;&lt;BR /&gt;Error while reading file from Google Drive&lt;BR /&gt;&lt;STRONG&gt;Google Drive file system is not enabled&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I am the &lt;STRONG&gt;workspace admin&lt;/STRONG&gt;, but under &lt;STRONG&gt;Settings → Workspace admin&lt;/STRONG&gt;, I do not see a &lt;STRONG&gt;Previews&lt;/STRONG&gt; option or any option to enable Google Drive/Lakeflow Connect for Google Drive.&lt;/P&gt;&lt;P&gt;I would like to know:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;How can I enable the &lt;STRONG&gt;Google Drive file system&lt;/STRONG&gt; in Databricks Free Edition?&lt;/LI&gt;&lt;LI&gt;Is Google Drive ingestion available for &lt;STRONG&gt;Free Edition&lt;/STRONG&gt; workspaces?&lt;/LI&gt;&lt;LI&gt;If it requires &lt;STRONG&gt;account-level enablement&lt;/STRONG&gt;, is there any way for a Free Edition workspace admin to enable it?&lt;/LI&gt;&lt;LI&gt;Is this error related to my Google Drive configuration, or is the Google Drive connector unavailable/not enabled in my workspace?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I am trying to ingest orderscsv.csv from my Google Drive into a Unity Catalog table in my Databricks workspace.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 17:55:25 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/google-drive-ingestion-pipeline-failing-google-drive-file-system/m-p/165274#M55410</guid>
      <dc:creator>hj648</dc:creator>
      <dc:date>2026-08-10T17:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Lakehouse Monitoring Solution</title>
      <link>https://community.databricks.com/t5/data-engineering/lakehouse-monitoring-solution/m-p/165271#M55409</link>
      <description>&lt;P&gt;Hi Surya, You can begin with Data Quality Monitoring solution - already present. It has anomaly detection &amp;amp; Data Profiling (formerly known as Lakehouse Monitoring) solutions helping in Statistical Profiling, data quality, snapshot quality monitors, drift detection and time series monitors.&amp;nbsp;More details &lt;A href="https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/data-quality-monitoring/" target="_self"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 17:13:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/lakehouse-monitoring-solution/m-p/165271#M55409</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-08-10T17:13:20Z</dc:date>
    </item>
    <item>
      <title>Lakehouse Monitoring Solution</title>
      <link>https://community.databricks.com/t5/data-engineering/lakehouse-monitoring-solution/m-p/165269#M55408</link>
      <description>&lt;P&gt;I wonder if there is any GitHub that specifically focuses on Databricks' Lakehouse monitoring solution with definitions and codes that can do this.&lt;/P&gt;&lt;P&gt;I want to onboard it for a customer of mine and don't want to write from scratch if one is already present or available.&lt;/P&gt;&lt;P&gt;Any pointers are welcome...&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Surya&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 16:47:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/lakehouse-monitoring-solution/m-p/165269#M55408</guid>
      <dc:creator>suryaprayaga</dc:creator>
      <dc:date>2026-08-10T16:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: How should schema evolution be handled across silver and gold layers in a medallion architecture</title>
      <link>https://community.databricks.com/t5/data-engineering/how-should-schema-evolution-be-handled-across-silver-and-gold/m-p/165264#M55407</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;You can skip using&amp;nbsp;traditional schema migration tools like Liquibase, Flyway or Alembic into Delta Lake as they&amp;nbsp;were generally designed for relational databases where state is tracked through sequential DDL scripts.&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;&lt;FONT size="3"&gt;Silver Layer&lt;/FONT&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;New Columns -&lt;/STRONG&gt;&amp;nbsp;You can let Spark handle column additions automatically during writes. For standard append or overwrite operations, configure the schema merge option on the Data Frame writer. You can check the cdc merge configuration &amp;amp; use it if feasible&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Column Renames -&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;You can treat renames as transformation logic rather than table migrations. Keep Bronze completely immutable. In your Silver transformations, read the incoming Bronze fields and alias them to the standardized Silver naming conventions. If you must physically rename a column on a Delta table without rewriting underlying data files, enable &lt;STRONG&gt;Delta Column Mapping&lt;/STRONG&gt; on the Silver table properties which generally turns renames into instant metadata updates.&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Dropped Columns -&lt;/STRONG&gt;&amp;nbsp;To keep Silver from accumulating dead columns over time, you can avoid using SELECT * in Silver job definitions explicitly project the required column list instead. If you need to physically purge a dropped column from the table metadata without triggering a heavy data rewrite, use &lt;STRONG&gt;Delta Column Mapping&lt;/STRONG&gt; allows you to execute column &lt;STRONG&gt;drops&lt;/STRONG&gt; as metadata operations if feasible.&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;FONT size="3"&gt;Gold Layer&lt;/FONT&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Automatic Column Sync -&lt;/STRONG&gt;&amp;nbsp;Configure the on_schema_change setting in your dbt incremental model config blocks or globally in your project file. Setting on_schema_change to sync_all_columns will generally add new columns to Gold and drop removed columns on the next incremental execution. Alternatively, append_new_columns will add incoming fields while preserving historical columns if an upstream field is dropped.&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;STRONG&gt;Renames &amp;amp; Deprecations -&lt;/STRONG&gt;&amp;nbsp;Handle column renames within your dbt model CTEs by aliasing the updated Silver column back to the expected Gold schema. For dropped columns where downstream BI dashboards still uses, you can supply default NULL values in the dbt SELECT statement before removing the column entirely via sync_all_columns.&lt;/FONT&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;FONT size="3"&gt;Deployment&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="3"&gt;You can add a schema validation task at the start of your workflow that compares bronze and silver metadata, firing an alert when schema drift occurs to catch unexpected source changes before they hit reports.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 16:01:51 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/how-should-schema-evolution-be-handled-across-silver-and-gold/m-p/165264#M55407</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-08-10T16:01:51Z</dc:date>
    </item>
    <item>
      <title>How should schema evolution be handled across silver and gold layers in a medallion architecture?</title>
      <link>https://community.databricks.com/t5/data-engineering/how-should-schema-evolution-be-handled-across-silver-and-gold/m-p/165262#M55406</link>
      <description>&lt;P class=""&gt;We run a medallion pipeline on Databricks:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Bronze: AutoLoader ingests raw CSV files into Delta tables (append-only, all columns as STRING, schema evolution via addNewColumns)&lt;/LI&gt;&lt;LI&gt;Silver: PySpark jobs clean and transform bronze data into Delta tables using batch writes and CDC merge&lt;/LI&gt;&lt;LI&gt;Gold: dbt incremental models aggregate silver into fact and measure tables&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;AutoLoader handles bronze schema evolution automatically. The problem is silver and gold.&lt;/P&gt;&lt;P&gt;When a source adds or renames a column, we currently handle it manually - authoring ALTER TABLE statements for silver Delta tables and running dbt run --full-refresh for gold. This works but is ad-hoc and error-prone, especially for column renames.&lt;/P&gt;&lt;P class=""&gt;Our most frequent case is new columns being added by the source. We also care about dropped columns - we don't want dead columns accumulating in silver and gold tables over time.&lt;/P&gt;&lt;P class=""&gt;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is there a recommended pattern for managing silver Delta table schema changes in a DAB-deployed pipeline - beyond manual ALTER TABLE?&lt;/LI&gt;&lt;LI&gt;Should we introduce a schema migration tool like Alembic/Liquibase/Flyway for Delta tables?&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 10 Aug 2026 15:15:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/how-should-schema-evolution-be-handled-across-silver-and-gold/m-p/165262#M55406</guid>
      <dc:creator>temarych</dc:creator>
      <dc:date>2026-08-10T15:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Synced table pipeline fails with permission denied for database</title>
      <link>https://community.databricks.com/t5/data-engineering/synced-table-pipeline-fails-with-permission-denied-for-database/m-p/165244#M55405</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247171"&gt;@KhaturiabPreet&lt;/a&gt;&amp;nbsp; !&lt;/P&gt;&lt;P&gt;I like you analysis it made me do some reading this morning to freshen up my memory.&lt;/P&gt;&lt;P&gt;I checked the the doc and I can say that&amp;nbsp;databricks_writer_&amp;lt;dbid&amp;gt; being unable to CONNECT does not look like an expected state because it is the&amp;nbsp;system role used to create and manage synced tables&amp;nbsp;and synced tables themselves are owned by that role. .&lt;/P&gt;&lt;P&gt;The doc does not say that users need to manually grant CONNECT to databricks_writer_&amp;lt;dbid&amp;gt; as part of synced table setup since its prerequisites concern the Lakebase project, UC source and permissions&amp;nbsp;&amp;nbsp;create_database_objects_if_missing = true is also explicitly supported when creating the synced table&lt;A title="https://docs.databricks.com/aws/en/oltp/projects/sync-tables" href="https://docs.databricks.com/aws/en/oltp/projects/sync-tables" target="_self"&gt;https://docs.databricks.com/aws/en/oltp/projects/sync-tables&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Therefore, given that the database was created through the Lakebase UI and every synced table failed until the writer privilege was corrected this looks much more like provisioning or bug than a skipped setup step.&lt;/P&gt;&lt;P&gt;Another thingGRANT CONNECT explains and fixes the failure but I would not consider manual modification of the system role the ideal long term configuration procedure as standard PostgreSQL GRANT commands are the documented mechanism for Lakebase database privileges including database privileges. however&amp;nbsp;databricks_writer_&amp;lt;dbid&amp;gt;&amp;nbsp;is categorized as a system managed role used by internal services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so this:&lt;/P&gt;&lt;PRE&gt;GRANT CONNECT ON DATABASE &amp;lt;database_name&amp;gt;
TO databricks_writer_&amp;lt;dbid&amp;gt;;&lt;/PRE&gt;&lt;P&gt;is a technically correct remediation in my opinion as demonstrated by all three pipelines immediately succeeding but I would open a DBKS support case and ask them to confirm whether that database was incorrectly provisioned.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is another strong point supporting your case which is the documented behavior says changing the pipeline run as identity does not reassign synced table ownership so recreating under different user or SP identities would not fix an ACL problem on databricks_writer_&amp;lt;dbid&amp;gt;.&lt;/P&gt;&lt;P&gt;and yes checking effective CONNECT is a sensible temporary readiness check&amp;nbsp;especially for older or existing databases but I would avoid parsing pg_database.datacl directly and yoy have&amp;nbsp;has_database_privilege() specifically for checking database connection permissions.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;PRE&gt;SELECT
    has_database_privilege(
        'databricks_writer_&amp;lt;dbid&amp;gt;',
        '&amp;lt;database_name&amp;gt;',
        'CONNECT'
    ) AS writer_can_connect;&lt;/PRE&gt;&lt;P&gt;you could check both relevant database privileges:&lt;/P&gt;&lt;PRE&gt;SELECT
    has_database_privilege(
        'databricks_writer_&amp;lt;dbid&amp;gt;',
        '&amp;lt;database_name&amp;gt;',
        'CONNECT'
    ) AS writer_can_connect,
    has_database_privilege(
        'databricks_writer_&amp;lt;dbid&amp;gt;',
        '&amp;lt;database_name&amp;gt;',
        'CREATE'
    ) AS writer_can_create;&lt;/PRE&gt;&lt;P&gt;This is preferable to inspecting pg_database.datacl because it tests the effective permission&amp;nbsp;including inherited or public privileges rather than requiring your automation to interpret PostgreSQL ACL strings.&lt;/P&gt;&lt;P&gt;I didn't find anything in the doc until now a documented lakebase management API that exposes effective PostgreSQL database grants directly.&lt;/P&gt;&lt;P&gt;The lakebase Postgres REST API is primarily for infrastructure or resource management and DBKS distinguishes that API from actual database access. So I think for an automated readiness test today executing has_database_privilege() over a PostgreSQL connection is the cleaner supported approach.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 11:21:48 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/synced-table-pipeline-fails-with-permission-denied-for-database/m-p/165244#M55405</guid>
      <dc:creator>amirabedhiafi</dc:creator>
      <dc:date>2026-08-10T11:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks Support #00984257 - Password Reset Email is not working for me</title>
      <link>https://community.databricks.com/t5/data-engineering/databricks-support-00984257-password-reset-email-is-not-working/m-p/165235#M55404</link>
      <description>&lt;P&gt;Issue Resolved with the help of DBX support team&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 10:08:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/databricks-support-00984257-password-reset-email-is-not-working/m-p/165235#M55404</guid>
      <dc:creator>Mubin4all</dc:creator>
      <dc:date>2026-08-10T10:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks Support #00984257 - Password Reset Email is not working for me</title>
      <link>https://community.databricks.com/t5/data-engineering/databricks-support-00984257-password-reset-email-is-not-working/m-p/165234#M55403</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/235177"&gt;@Mubin4all&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;I would recommend not creating another Webassessor account&amp;nbsp;as duplicate accounts can make the issue more difficult to resolve.&lt;/P&gt;&lt;P&gt;If the password reset email is not arriving even after checking youe spalm this will most likely need to be handled by the DBKS certification support team as they can check the Webassessor account associated with your login.&lt;/P&gt;&lt;P&gt;Try to check this old thread&amp;nbsp;&lt;A href="https://community.databricks.com/t5/certifications/webassessor-databricks-login-not-working/td-p/64326" target="_blank"&gt;Solved: webassessor databricks login not working - Databricks Community - 64326&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope it helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 10:01:33 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/databricks-support-00984257-password-reset-email-is-not-working/m-p/165234#M55403</guid>
      <dc:creator>amirabedhiafi</dc:creator>
      <dc:date>2026-08-10T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to expose JWT in Databricks Job?</title>
      <link>https://community.databricks.com/t5/data-engineering/is-it-safe-to-expose-jwt-in-databricks-job/m-p/165230#M55402</link>
      <description>&lt;P&gt;Hello !&lt;/P&gt;&lt;P&gt;What I can say is that your conclusion is correct since DBKS&amp;nbsp;does not currently expose the identity of the principal that called run-now to the running job through the Jobs API or notebook context and the audit event is the authoritative source but it is not designed for synchronous runtime identity resolution.&lt;/P&gt;&lt;P&gt;I would not pass the Databricks/Entra OAuth JWT access token itself as a job parameter.&lt;/P&gt;&lt;P&gt;DBKS explicitly shows resolved parameters on the job run details page. &lt;A title="https://docs.databricks.com/aws/en/jobs/dynamic-value-references" href="https://docs.databricks.com/aws/en/jobs/dynamic-value-references" target="_self"&gt;https://docs.databricks.com/aws/en/jobs/dynamic-value-references&lt;/A&gt;&amp;nbsp;more importantly the runNow audit event includes job_parameters, notebook_params, python_params...&amp;nbsp;in its request params and you can check this doc link to better understand the situation&amp;nbsp;&lt;A title="https://docs.databricks.com/aws/en/admin/account-settings/audit-logs" href="https://docs.databricks.com/aws/en/admin/account-settings/audit-logs" target="_self"&gt;https://docs.databricks.com/aws/en/admin/account-settings/audit-logs&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;which means something like:&lt;/P&gt;&lt;PRE&gt;{
  "job_id": 123,
  "job_parameters": {
    "jwt": "eyJhbGciOi..."
  }
}&lt;/PRE&gt;&lt;P&gt;can potentially make a bearer credential persist in places where you don't want credentials to exist like in job run metadata, audit records, logs or parameter inspection.&lt;/P&gt;&lt;P&gt;So what you need to do is simply treat tokens as secrets and avoid putting credentials directly into notebooks or jobs or logging them.&lt;/P&gt;&lt;P&gt;If that JWT is the token SPN B used to call:&lt;/P&gt;&lt;PRE&gt;POST /api/2.2/jobs/run-now
Authorization: Bearer &amp;lt;token&amp;gt;&lt;/PRE&gt;&lt;P&gt;then anybody obtaining it before expiration could potentially replay it with the permissions of SPN B.&lt;/P&gt;&lt;P&gt;Interestingly, what I really find amazing is that&amp;nbsp;does know the caller since the jobs&amp;nbsp;audit event represents an on demand invocation and every audit record has:&lt;/P&gt;&lt;PRE&gt;user_identity&lt;/PRE&gt;&lt;P&gt;which DBKS defines as the identity of the user initiating the request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that DBKS does not propagate that audit user_identity into the job runtime and the documented dynamic values provide job.id, job.run_id, job.trigger.type, timestamps... but no triggered_by/caller identity&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/jobs/dynamic-value-references" target="_blank"&gt;https://docs.databricks.com/aws/en/jobs/dynamic-value-references&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and unfortunately the system tables are explicitly not intended for realtime monitoring because in DBKS&amp;nbsp;recent events may not appear immediately and Azure diagnostic log delivery isn't a reliable workaround either (auditable events typically arrive within about 15 minutes)&lt;/P&gt;&lt;P&gt;What I would recommend is if the caller identity is required inside the job immediately you can&amp;nbsp;use a purpose built signed identity assertion&amp;nbsp;rather than forwarding the OAuth access token.&lt;/P&gt;&lt;P&gt;for example SPN B (or preferably a trusted issuer) sends:&lt;/P&gt;&lt;PRE&gt;{
  "caller_assertion": "&amp;lt;signed-JWT&amp;gt;",
  "request_id": "8d6835..."
}&lt;/PRE&gt;&lt;P&gt;with claims such as:&lt;/P&gt;&lt;PRE&gt;{
  "sub": "SPN-B-application-id",
  "aud": "databricks-job-123",
  "iat": 1786352400,
  "exp": 1786352700,
  "jti": "8d6835..."
}&lt;/PRE&gt;&lt;P&gt;the job verifies:&lt;/P&gt;&lt;PRE&gt;signature
aud == expected job
exp &amp;lt; = 5 minutes
jti not previously used
issuer is trusted&lt;/PRE&gt;&lt;P&gt;so a JWT as a format is not inherently the problem. Passing a bearer/access JWT is.&lt;/P&gt;&lt;P&gt;For a prod security sensitive use case, I would go for :&lt;/P&gt;&lt;PRE&gt;SPN B
  │
  │ authenticated request
  ▼
thin trigger service or DBKS app
  │
  ├── validates caller = SPN B
  │
  ├── generates request_id
  │
  ├── creates short-lived signed assertion
  │
  ▼
DBKS run-now
  │
  │ caller_assertion + request_id
  ▼
Job running as SPN A
  │
  ├── verifies assertion
  └── knows caller = SPN B&lt;/PRE&gt;&lt;P&gt;this proxy does not need to be a large additional system since it can be a very thin authenticated endpoint whose only responsibility is identity propagation. A DBKS app is also worth considering because DBKS apps support OAuth for users or SP and explicitly recommend recording the original identity when performing actions on behalf of callers so if immediate caller identification is not required for authorization and is needed only for auditing or reporting, I would avoid all of this complexity and continue using:&lt;/P&gt;&lt;PRE&gt;SELECT
    event_time,
    user_identity,
    request_params['job_id'] AS job_id
FROM system.access.audit
WHERE service_name = 'jobs'
  AND action_name = 'runNow'&lt;/PRE&gt;&lt;P&gt;the audit table is actually the correct source of truth user_identity is the initiating identity while run_as is the execution identity.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 09:45:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-engineering/is-it-safe-to-expose-jwt-in-databricks-job/m-p/165230#M55402</guid>
      <dc:creator>amirabedhiafi</dc:creator>
      <dc:date>2026-08-10T09:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Building an Agentic HR Front Door on Databricks</title>
      <link>https://community.databricks.com/t5/generative-ai/building-an-agentic-hr-front-door-on-databricks/m-p/165225#M1998</link>
      <description>&lt;P&gt;Interesting to see the shift from AI assistants that answer questions to agents that can actually complete tasks. For enterprise adoption, I’m curious how teams are thinking about measuring business impact here — is the focus more on reducing manual HR workflows, improving employee experience, or increasing the accuracy and speed of decisions?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 06:58:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/generative-ai/building-an-agentic-hr-front-door-on-databricks/m-p/165225#M1998</guid>
      <dc:creator>kartikchoudhary</dc:creator>
      <dc:date>2026-08-10T06:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: What does "Agent-Ready Data Governance" actually mean in production?</title>
      <link>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165224#M2950</link>
      <description>&lt;P class=""&gt;One thing I’d be interested in hearing from teams running this across multiple business domains is how they handle &lt;STRONG&gt;business ownership and consistency of definitions&lt;/STRONG&gt;. Technical access controls can restrict what an agent can see or invoke, but how are organizations ensuring that the agent interprets metrics and business terms consistently across domains?&lt;/P&gt;&lt;P&gt;Especially when the same metric can have different definitions across finance, sales, or operations, is the business glossary becoming part of the governance process rather than just metadata?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 06:46:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/what-does-quot-agent-ready-data-governance-quot-actually-mean-in/m-p/165224#M2950</guid>
      <dc:creator>kartikchoudhary</dc:creator>
      <dc:date>2026-08-10T06:46:50Z</dc:date>
    </item>
  </channel>
</rss>

