Skip to main content

Roll out coding agents

Use device management (MDM) and the Unity Gateway CLI to distribute your team's coding agent setup. Admins publish the configuration once, and developers use their familiar agents with the configured models, MCP servers, and skills.

Before you begin​

Roll out with MDM​

1. Prepare the rollout automation​

Your deployment automation needs:

  • The URL of a Databricks workspace with Unity Gateway enabled and a published coding agent configuration.
  • A dedicated Databricks service principal with an OAuth secret (a client ID and secret) for machine-to-machine (M2M) authentication. Grant it access to the published models, MCP servers, skills, and other securables, including the required Unity Catalog privileges. See Grant access to models, MCP servers, and skills.
  • An MDM workflow that securely delivers the workspace URL and the service principal's client ID and secret before handoff.

Configure the automation to:

  1. Install ug, its prerequisites, and the enabled agent CLIs.
  2. Generate a short-lived M2M OAuth token from the service principal's client ID and secret, and provide it to ug through the DATABRICKS_BEARER_COMMAND environment variable. ug requests a fresh token on demand, so no long-lived credential is written to the machine.
  3. Run ug configure --workspace <workspace-url> noninteractively to apply the published models, MCP servers, and skills. ug configure persists the workspace and model lists only, not a token.
  4. Confirm that developers can run ug with the configured agent settings, MCP servers, and skills from their terminal session.

2. Roll out to developer machines​

Use your company's MDM to install and configure the software and agent settings before handing each machine to the developer. The service-principal token is only a provisioning credential and is never stored on the machine. After handoff, developers authenticate with their own OAuth tokens when they run ug from their normal terminal session, so coding agent activity is attributed to the individual developer, not the service principal. No installation or additional configuration is required.

Before handoff, verify the rollout on a pilot device.

3. Maintain credentials and configuration​

Rotate the service principal's OAuth secret according to your security policy, and update the secret in your MDM configuration so new provisioning runs use it. Because the provisioning token is short-lived and never stored on developer machines, there is no per-device credential to revoke. If the secret is compromised, rotate it immediately and revoke the old secret.

Publish configuration updates in the workspace. Use the deployment automation to run ug configure and sync managed MCP servers and skills. See Sync configuration updates.

Offer self-service setup​

For developers outside your MDM rollout, share the workspace URL and the coding agent quickstart. Developers follow the quickstart to install ug, apply the workspace configuration, and launch their agent.

Verify the rollout​

On a pilot device, use the developer's operating-system account and check that:

  • The agent opens and responds using a configured model.
  • The configured MCP servers and skills are available, and the developer can use them.
  • Requests appear in Unity Gateway usage tracking, and traces appear if tracing is enabled. See Monitor coding agent activity.

Repeat these checks after changing the deployment package or published configuration.