A Terraform root
Add --scaffold to generate module calls and provider
settings. Use the workspace pattern or individual resource modules.
terraform.tfvars + main.tf
DataTF reads your existing Azure Databricks setup and generates Terraform inputs and import blocks. Review the plan. Import supported resources. Prepare for future changes through pull requests.
databricks auth profiles
datatf auth status --profile analytics
datatf export --profile analytics --out ./export --scaffold
Install DataTF and the Databricks CLI first.
Replace analytics with your saved profile.
From your existing Databricks setup to configuration your team can review and version.
Supported workspace and Unity Catalog configuration.
Settings and permissionsReads your setup, selects the scope, and maps resource ownership.
Read-only · your profileModule inputs, import blocks, and an export report.
Files stay localApprove an imports-only plan. Import existing resources into state.
Then confirm a clean planSame resources. Ready for reviewed changes. DataTF prepares the files. Terraform imports only after your approval.
Try the quickstartExport catalogs, storage, compute settings, and permissions. Review the generated files, import the resources, and confirm a clean plan. Private identifiers are replaced. Wait times are shortened.
Prepare existing configuration for review. No resource IDs to copy by hand.
Add --scaffold to generate module calls and provider
settings. Use the workspace pattern or individual resource modules.
terraform.tfvars + main.tf
DataTF maps existing resource IDs to module addresses. Terraform uses those blocks to import resources into state.
imports.tf
Separate workspace objects from shared catalogs and permissions. Select the scope before export.
workspace / shared
See what DataTF exports, skips, or cannot read. A partial export blocks Terraform output by default.
export-report.json
Use a saved Databricks profile. DataTF reads configuration without changing resources or reading secret values.
--profile analytics
Give Codex or Claude structured JSON, exit codes, and a documented workflow. Keep human approval before Terraform apply.
Read the agent workflowExport supported Unity Catalog definitions for workspace or shared scope.
Export direct grants and workspace bindings for supported Unity Catalog resources.
Export storage access configuration and external location definitions.
Export compute policies, instance pool settings, and their permissions.
Export warehouse settings and permissions. DataTF does not export queries or stored data.
Export secret scope definitions and access rules. Secret values stay out of the export.
Export service principals at workspace scope. Account identities remain outside DataTF.
Generate module inputs and matching import blocks. Add --scaffold for module calls and provider settings.
Azure — Supported
AWS — Coming soon
GCP — Coming soon
Unity Catalog provides governance controls. Your team defines the owners, access rules, and process for each change.
DataTF prepares supported configuration for Terraform adoption. After review and import, commit the configuration. Use pull requests for future changes. Your team supplies the deployment workflow, approvals, and ongoing reconciliation.
Further reading: Unity Catalog best practices.
Follow the quickstart to connect and export. Release notes · SHA-256 checksums.
curl -fsSL https://datatf.io/install.sh | sh
irm https://datatf.io/install.ps1 | iex
The script verifies the release checksum and installs one binary.
Set DATATF_VERSION to pin a release.
macOS marks browser downloads, so run
xattr -d com.apple.quarantine ./datatf after you extract the archive.
See the install guide.
AWS and GCP are not supported or verified export targets. See the resource matrix for the exact Terraform resource types.
No. It reads configuration and writes local files. It never reads secret values or sends exports to a DataTF service.
Your Databricks identity needs permission to read the resources you select. A failed read blocks Terraform output by default.
No. DataTF uses the
workspace pattern by default. Use --module-layout resources to call
individual 536 Technologies resource modules. Both layouts pin
module versions and generate matching imports. See
module layouts.
Yes. Use the agent workflow with a named profile and JSON reports. Check the report and exit code. Require human approval before Terraform apply.
Workspace scope is the default. Use --scope shared
once per metastore for shared resources, with a separate Terraform
state. Each resource must belong to only one state. DataTF does
not check your existing states.
DataTF and its Terraform modules remain open source in both plans.
| Feature | Community Free | Enterprise Starting at $2,999/month |
|---|---|---|
| Terraform export | Included | Included |
| Terraform modules | Included | Included |
| Updates and docs | Included | Included |
| Support SLA | Not included | Included |
| CI/CD support | Not included | Included |
Prices are in USD. 536 Technologies provides support.