07 Defend and tear down
Make keep, federate, or materialize decisions from evidence, then remove participant resources.
Outcome
Your pair has defended a hybrid placement decision and confirmed that participant-owned MigrationRoom, Databricks, ClickHouse, and temporary credential resources are stopped or removed.
Complete the placement matrix
Copy this matrix into your workshop notes. Select one primary disposition per row and cite the dashboard checkpoint, query, or governance requirement that supports it.
| Workload or data | Keep in Databricks | Federate from ClickHouse | Materialize in ClickHouse | Evidence |
|---|---|---|---|---|
| Cold historical facts | ||||
| High-QPS serving aggregate | ||||
| Mutable or time-travel-sensitive data | ||||
| Small shared dimension | ||||
| Semi-structured hot attributes |
Use keep when source semantics and operations dominate, federate when avoiding a copy and retaining catalog-backed access matter most, and materialize when measured serving needs justify native ownership. There is no required all-native answer.
Your pair has three minutes to present and one minute to answer another pair's challenge. A claim without a correctness check or declared configuration is not evidence. Include rollback and the event that would make you revisit the decision.
Final UI review
Review the selected dashboard run and conversation from beginning to end. Your pair should have these redacted checkpoints:
- Step 1 source summary, challenged design decision, and DDL approval;
- completed Migration view and passing Validation view;
- final rewritten query set;
- Benchmark view before optimization;
- Unity/REST/native hybrid result;
- Step 6 reasoning, approved change, and Benchmark view after optimization; and
- the conversation link and run ID that connect them.
Do not add a success label to a missing or failed step. Record it as not executed or failed and explain the resulting architecture uncertainty.
Tear down in dependency order
Stop the local playground first:
cd "$MIGRATIONROOM_DIR"
make downBefore any Terraform destroy, confirm that the current directory is the module you
intend to remove and inspect both its selected Terraform workspace and planned targets.
Stop if terraform state list or terraform plan -destroy includes resources outside
this workshop. Remove the demo module after that review:
cd "$MIGRATIONROOM_DIR/sources/databricks/terraform/demo"
terraform workspace show
terraform state list
terraform plan -destroy
terraform destroyModule 00 created a disposable workspace for every learner. Destroy its workspace module only after the demo module is gone and the state/plan inspection shows exactly that module's expected targets:
cd ../workspace
terraform workspace show
terraform state list
terraform plan -destroy
terraform destroyThe account-level migrationroom-terraform service principal and its OAuth secret were
created manually, so Terraform does not remove them. After both destroys complete, open
the Databricks account console and either delete the workshop OAuth secret under
Credentials & secrets or delete the entire workshop service principal if nothing
else uses it. Confirm the exact principal name and client ID before deleting it.
Remove participant-created ClickHouse databases, dictionaries, materialized views, and
the participant ClickHouse service only when they were created for this workshop. The
instructor-owned REST fixture remains. Confirm in the Databricks and cloud consoles that
no participant warehouse, workspace, external location, bucket, service, or token was
orphaned. A successful terraform validate is never proof that an apply or destroy ran.
Evidence artifact
Use the provided architecture-decision template or your workshop notes as the final placement and teardown record. Keep the redacted dashboard checkpoints beside it.
Completion checklist
- Every matrix row has one defended disposition and cited evidence.
- The presentation states both governance boundaries and rollback triggers.
- Every required UI checkpoint belongs to the selected run/conversation.
- MigrationRoom is stopped.
- Terraform state and destroy targets were inspected before every applicable destroy.
- The demo module was removed if Terraform created it.
- The workshop-created workspace module was removed after its inspected destroy plan.
- The workshop OAuth secret was revoked, or its dedicated service principal was deleted.
- Participant ClickHouse resources and temporary credentials are removed.
- Account-console checks found no orphaned participant resources.