Databricks MigrationRoomClickHouse Workshops

07 Defend and tear down — instructor notes

Assess evidence-backed placement decisions and remove only workshop-owned resources.

Timing

Budget 20 minutes: eight for matrix completion, eight for three-minute defenses plus one-minute challenges, and four to start verified teardown. Finish console checks after the session if cloud deletion is still converging.

Talk track

There is no required all-native answer. Grade whether each keep, federate, or materialize choice cites correctness, configuration, governance, cost, and a revisit trigger. Require the pair to state that Unity governs zero-copy reads while ClickHouse RBAC governs copied native rows. The final proof is the architecture decision beside the selected dashboard run, conversation link, and redacted UI checkpoints.

Teardown is ownership-sensitive. Stop MigrationRoom first, then destroy the demo module only after checking its workspace, state, and destroy plan. Every participant used make databricks-provision-workspace, so destroy the disposable workspace module next, again only when its inspected state/plan targets exactly those resources. Terraform does not own the manually created account service principal: revoke its OAuth secret or delete that dedicated principal after confirming its name and client ID. Leave the instructor REST fixture intact and confirm participant Databricks, ClickHouse, storage, identities, and tokens in their account consoles.

Common failures

  • A performance number has no matching query, timing type, failures, or configuration.
  • “Same governance” is used across zero-copy and copied-native data.
  • Terraform state points at shared or pre-existing resources.
  • A learner destroys the workspace module before the demo module.
  • The manually created service principal or OAuth secret remains active after teardown.
  • terraform validate or a submitted destroy command is treated as proof that resources are gone.

Reset steps

Pause every ambiguous destroy. Reconfirm repository, module directory, Terraform workspace, terraform state list, and terraform plan -destroy with the resource owner. Run the workspace destroy only after the demo module and only against its own inspected state. Then revoke the OAuth secret or delete the dedicated workshop principal in the account console. Complete account-console checks, record unresolved resources in evidence/architecture-decision.md, and escalate them to the owner rather than broadening the deletion scope.

Trên trang này

VI