Your Databricks Workspace. Now in Terraform.

DataTF reads your existing Azure Databricks setup and generates Terraform inputs and import blocks. Review the plan. Import supported resources. Prepare for future changes through pull requests.

Quick start

databricks auth profiles
datatf auth status --profile analytics
datatf export --profile analytics --out ./export --scaffold

Install DataTF and the Databricks CLI first. Replace analytics with your saved profile.

  • Read-only
  • No secret values
  • Output stays local

Workflow

From your existing Databricks setup to configuration your team can review and version.

  1. Databricks

    Supported workspace and Unity Catalog configuration.

    Settings and permissions
  2. DataTF

    Reads your setup, selects the scope, and maps resource ownership.

    Read-only · your profile
  3. Terraform files

    Module inputs, import blocks, and an export report.

    Files stay local
  4. You + Terraform

    Approve an imports-only plan. Import existing resources into state.

    Then confirm a clean plan

Same resources. Ready for reviewed changes. DataTF prepares the files. Terraform imports only after your approval.

Try the quickstart

From existing resources to Terraform state.

Azure demo

Export catalogs, storage, compute settings, and permissions. Review the generated files, import the resources, and confirm a clean plan. Private identifiers are replaced. Wait times are shortened.

Features

Prepare existing configuration for review. No resource IDs to copy by hand.

A Terraform root

Add --scaffold to generate module calls and provider settings. Use the workspace pattern or individual resource modules.

terraform.tfvars + main.tf

Matching import blocks

DataTF maps existing resource IDs to module addresses. Terraform uses those blocks to import resources into state.

imports.tf

Unity Catalog scope

Separate workspace objects from shared catalogs and permissions. Select the scope before export.

workspace / shared

A report you can check

See what DataTF exports, skips, or cannot read. A partial export blocks Terraform output by default.

export-report.json

Your existing access

Use a saved Databricks profile. DataTF reads configuration without changing resources or reading secret values.

--profile analytics

Ready for coding agents

Give Codex or Claude structured JSON, exit codes, and a documented workflow. Keep human approval before Terraform apply.

Read the agent workflow

Catalogs and schemas

Export supported Unity Catalog definitions for workspace or shared scope.

Grants and bindings

Export direct grants and workspace bindings for supported Unity Catalog resources.

Storage credentials and external locations

Export storage access configuration and external location definitions.

Cluster policies and instance pools

Export compute policies, instance pool settings, and their permissions.

SQL warehouses

Export warehouse settings and permissions. DataTF does not export queries or stored data.

Secret scopes and ACLs

Export secret scope definitions and access rules. Secret values stay out of the export.

Workspace service principals

Export service principals at workspace scope. Account identities remain outside DataTF.

Terraform files and import blocks

Generate module inputs and matching import blocks. Add --scaffold for module calls and provider settings.

Cloud platforms

Azure — Supported
AWS — Coming soon
GCP — Coming soon

Accelerate GitOps adoption.

Unity Catalog provides governance controls. Your team defines the owners, access rules, and process for each change.

DataTF prepares supported configuration for Terraform adoption. After review and import, commit the configuration. Use pull requests for future changes. Your team supplies the deployment workflow, approvals, and ongoing reconciliation.

Further reading: Unity Catalog best practices.

Install DataTF

Follow the quickstart to connect and export. Release notes · SHA-256 checksums.

macOS and Linux
curl -fsSL https://datatf.io/install.sh | sh
Windows PowerShell
irm https://datatf.io/install.ps1 | iex

The script verifies the release checksum and installs one binary. Set DATATF_VERSION to pin a release.

Or download the archive

macOS marks browser downloads, so run xattr -d com.apple.quarantine ./datatf after you extract the archive. See the install guide.

FAQ

What does DataTF not export?
  • Jobs, pipelines, and notebooks
  • Clusters, tables, and stored data
  • Azure resources and workspace creation
  • Metastore setup and account identities
  • Secret values and ML artifacts

AWS and GCP are not supported or verified export targets. See the resource matrix for the exact Terraform resource types.

Does DataTF change the workspace or read secrets?

No. It reads configuration and writes local files. It never reads secret values or sends exports to a DataTF service.

What permissions do I need?

Your Databricks identity needs permission to read the resources you select. A failed read blocks Terraform output by default.

Can I use any Terraform module?

No. DataTF uses the workspace pattern by default. Use --module-layout resources to call individual 536 Technologies resource modules. Both layouts pin module versions and generate matching imports. See module layouts.

Can Codex or Claude use DataTF?

Yes. Use the agent workflow with a named profile and JSON reports. Check the report and exit code. Require human approval before Terraform apply.

What about shared Unity Catalog resources?

Workspace scope is the default. Use --scope shared once per metastore for shared resources, with a separate Terraform state. Each resource must belong to only one state. DataTF does not check your existing states.

Community and Enterprise

DataTF and its Terraform modules remain open source in both plans.

DataTF Community and Enterprise comparison
Feature Community Free Enterprise Starting at $2,999/month
Terraform export Included Included
Terraform modules Included Included
Updates and docs Included Included
Support SLA Not included Included
CI/CD support Not included Included

Prices are in USD. 536 Technologies provides support.