Skip to main content

Resolve Databricks config variables from literals, environment variables, and Azure Key Vault secrets, and substitute them into JSON config files.

Project description

brickvar

Resolve configuration variables for Databricks jobs from literals, environment variables, and Azure Key Vault secrets, and substitute them into JSON config files.

brickvar reads a JSON "variables" file in which each entry is one of:

  • a literal string (which may reference other variables with ${VAR}),
  • null, which substitutes a JSON null into the config file,
  • an environment variable reference — {"env": "NAME"}, or
  • a Databricks / Azure Key Vault secret{"scope": ..., "key": ..., "base"?: ...}, read through the Databricks dbutils.secrets API.

Resolution is two-pass, so a secret's scope/key can themselves reference already-resolved literal or environment values. It can also substitute ${VAR} placeholders into any JSON file, leaving unknown placeholders intact.

A null variable substitutes a real JSON null. Because substitution is textual, its placeholder must be a complete string value — "${VAR}" becomes null (quotes and all). A null variable embedded in a larger string ("prefix-${VAR}") cannot become null and is left intact with a warning.

Install

pip install brickvar

Usage

from brickvar import configure_json

# Read a JSON file and substitute its ${VAR} placeholders from a variables file,
# in one call. dbutils is provided by the Databricks runtime and is required only
# when the variables file contains Key Vault secret entries.
spec = configure_json("spec.json", dbutils=dbutils, var_filepath="variables.json")

For finer-grained control, use the ConfigManager class directly:

from brickvar import ConfigManager

cfg = ConfigManager(dbutils=dbutils)

# Resolve a variables file to a dict.
variables = cfg.read_variables("variables.json")

# Read a JSON file and substitute its ${VAR} placeholders from a variables file.
spec = cfg.read_json("spec.json", "variables.json")

Example variables.json:

{
  "SECRET_SCOPE": { "env": "SECRET_SCOPE" },
  "HOST": "example.documents.azure.us",
  "PROXY": null,
  "CLIENT_ID": { "scope": "${SECRET_SCOPE}", "key": "SP-CLIENT-ID" },
  "STORAGE": { "scope": "kv", "key": "ACCOUNT", "base": "abfss://data@{}/curated" }
}
  • HOST is a literal.
  • SECRET_SCOPE comes from the SECRET_SCOPE environment variable.
  • PROXY is null — a "${PROXY}" placeholder becomes a JSON null.
  • CLIENT_ID is a secret whose scope is filled from the resolved SECRET_SCOPE.
  • STORAGE is a secret wrapped by its base format string.

Development

python -m venv venv && source venv/bin/activate
pip install -e ".[dev]"
pytest

License

Apache-2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

brickvar-0.0.3.tar.gz (10.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

brickvar-0.0.3-py3-none-any.whl (9.4 kB view details)

Uploaded Python 3

File details

Details for the file brickvar-0.0.3.tar.gz.

File metadata

  • Download URL: brickvar-0.0.3.tar.gz
  • Upload date:
  • Size: 10.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for brickvar-0.0.3.tar.gz
Algorithm Hash digest
SHA256 4d644a01aaa33a47a11d7b78cc618c1772e218f5aa760febf82c4b15578116b4
MD5 9b7e21457d82ea152788507076e7db11
BLAKE2b-256 c81727c8fb6962be25c8e5cc02eafa8531d12e93c821adca0b8e20b2e5b8838a

See more details on using hashes here.

Provenance

The following attestation bundles were made for brickvar-0.0.3.tar.gz:

Publisher: release.yml on amida-tech/brickvar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file brickvar-0.0.3-py3-none-any.whl.

File metadata

  • Download URL: brickvar-0.0.3-py3-none-any.whl
  • Upload date:
  • Size: 9.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for brickvar-0.0.3-py3-none-any.whl
Algorithm Hash digest
SHA256 288f8f2c8255bc6a5c08e6471ded521ef5085df1a15056a36853a8f82dc65386
MD5 e4ef7cd3c7ff019f8cb206cb865cc8bb
BLAKE2b-256 e853b0a8ac9504a9b5ca22b916083bb482104d86510a392e8931dbd63c52fc98

See more details on using hashes here.

Provenance

The following attestation bundles were made for brickvar-0.0.3-py3-none-any.whl:

Publisher: release.yml on amida-tech/brickvar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page