## Release v1.19.0
### CLI
* Honor `CLAUDE_CONFIG_DIR` in `aitools` commands. ([#6838](#6838))
* Added `--ttl` and `--no-expiry` flags to `databricks postgres create-branch` so a branch's expiration can be set without hand-writing a `--json` spec. `--ttl` accepts the REST API duration form (`604800s`), a Go duration (`168h`), or day/week units (`7d`, `3w`); `--no-expiry` creates a branch that never expires. One of `--ttl`, `--no-expiry`, or a spec expiration in `--json` is required. ([#6313](#6313))
* `databricks ssh connect` serverless sessions now provide Claude Code and Codex configured with Unity Gateway out of the box. ([#6885](#6885))
### AI Runtime
* Add `databricks air images push` (Preview) to configure Docker authentication and push container images to Databricks Artifact Registry. ([#6869](#6869))
* `air run` now grants the configured `permissions` on the MLflow experiment as well as the job. ([#6870](#6870))
### Bundles
* Add libraries field to clusters. ([#6831](#6831))
* Error out when a configured `workspace_id` does not match the connected workspace, instead of silently using it in resource URLs emitted by `bundle summary`. ([#6754](#6754))
* Fix spurious recreation of Lakebase (Postgres) branches, roles, and catalogs when the referenced project is updated in place: an in-place project change (e.g. `display_name`) no longer forces a delete + create of resources that reference the project's or branch's `name`. ([#6865](#6865))
* Direct engine now detects and applies an explicitly configured integer zero (e.g. `gcp_attributes.local_ssd_count: 0`) added to a resource first deployed without the field. ([#6867](#6867))
* Migrate existing Terraform deployment state to the direct engine before deploying (previously done after a Terraform deploy), so the deploy runs on the direct engine. ([#6749](#6749))
* The `postgres_snapshot_schedules` resource (introduced in [v1.16.0](https://github.com/databricks/cli/releases/tag/v1.16.0)) is now marked Beta and is no longer available in PyDABs, matching the other `postgres_*` resources; configure it in YAML instead. ([#6887](#6887))
Changes
Fix incorrect ?w= workspace parameter in resource URLs
Why
PR #5369 changed to call auth.ResolveWorkspaceID() instead of CurrentWorkspaceID().
ResolveWorkspaceID has a fast-path that returns Config.WorkspaceID without hitting the API. That field is populated from multiple sources: the user's .databrickscfg profile workspace_id, a ?o=/?w= embedded in the host URL, the bundle's workspace.workspace_id, etc. Any of which can contain a value that doesn't match the workspace to which the bundle is actually deployed.
CurrentWorkspaceID() is always authoritative: it calls /api/2.0/preview/scim/v2/Me and reads X-Databricks-Org-Id from the response header of the actual connected workspace.
When the two diverge (e.g. a profile configured for workspace A is used with a bundle that targets workspace B), the old fast-path embedded the wrong workspace ID in ?w=, causing the Databricks UI to navigate to an unexpected workspace. This was compounded by a frontend bug in which a numeric ?w= value bypasses pub-conf reconciliation and immediately boots on the passed-in workspace, with no server-side correction.
Tests
Added a unit test