github databricks/cli v1.13.0

3 hours ago

Release v1.13.0 (2026-08-20)

Notable Changes

  • bundle deploy now reports the per-resource actions it took, how many files it synced, and a summary of created/changed/deleted/unchanged resources; bundle destroy reports how many resources it deleted. -q prints only the summaries, -qq only warnings and errors. (#5720)

CLI

  • databricks aitools install now supports Goose, installing Databricks agent skills into its skills directory.
  • Error messages for failed key lookups and variable references now suggest the closest matching key if one is found. (#6208)
  • Released binaries are now built against the FIPS 140-3 validated Go Cryptographic Module, with FIPS 140-3 mode enabled by default. TLS connections negotiate only FIPS-approved cipher suites, which drops ChaCha20 and CBC from what the client offers. FIPS mode can be disabled at startup with GODEBUG=fips140=off, which restores the previous TLS behaviour (#6262).
  • databricks environments setup-local now removes a databricks-connect pin from [project].dependencies, an optional-dependency extra, or a dependency group when its version range conflicts with the compute target's databricks-connect version, so uv sync no longer fails with an unsatisfiable resolution when a template ships a conflicting pin. A pin that co-resolves, carries no version, or is marker-gated is left untouched, and each removed pin is reported with the new W_DBCONNECT_CONSOLIDATED warning. Wildcard version pins such as ==15.1.* are now also checked for conflicts with the environment's constraints.

Bundles

  • Allow dashes in the catalog and schema names prompted by databricks bundle init, and backtick-quote the catalog and schema identifiers in the SQL generated by the built-in templates so names with dashes work at runtime.
  • Fixed bundle.git.branch, bundle.git.commit, and bundle.git.origin_url being empty for bundles deployed from a workspace Git folder that has Git CLI access. The workspace API does not report git metadata for those folders, so it is now read from the Repos API instead.
  • direct: job_runs deploy progress lines now include the resource key (e.g. Output from job_runs.foo: id=123: ...) so concurrent runs are easier to tell apart.
  • direct: resources.job_runs can set lifecycle.triggers.on_bundle_deploy: true to re-fire the run on every bundle deploy. Removing the trigger does not recreate the existing run.
  • When migrating a bundle to the direct deployment engine, resources that only the direct engine supports (e.g. instance pools, catalogs) are now skipped by the deploy that migrates the state instead of failing it. They are created by the next deploy, which runs on the migrated state.
  • Warn on invalid secret_scopes permission levels (READ, WRITE, MANAGE); fail under bundle validate --strict.
  • Reject secret scope permissions that name no principal, instead of failing after the scope is created.
  • Write the deployment state atomically so an interrupted save cannot leave a state file that the CLI refuses to read.
  • Warn when the deployment state was last written by a newer CLI version than the one running.
  • Support pip extras (e.g. [train]) on local wheels in a job environment's dependencies (#1602).

Dependency Updates

  • Bump github.com/databricks/databricks-sdk-go from v0.170.0 to v0.171.0 (#6320).
  • Bump the Databricks Terraform provider to 1.127.0 (#6319).
  • Bump Go toolchain to 1.26.6 (#6266).
  • Bump Go toolchain to 1.26.7 (#6325).

Don't miss a new cli release

NewReleases is sending notifications on new releases.