Account Network Policy
AccountNetworkPolicy object
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Get a network policy GA
GET
Gets a network policy.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier of the network policy to retrieve.
Response
Returns the AccountNetworkPolicy object.
List network policies GA
GET
Gets an array of network policies.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- page_tokenstringquery
Pagination token to go to next page based on previous query.
Response
Returns a list of AccountNetworkPolicy objects.
Create a network policy GA
POST
Creates a new network policy to manage which network destinations can be accessed from the <Databricks> environment.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
Request body
Network policy configuration details.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Response
Returns the AccountNetworkPolicy object.
Update a network policy GA
PUT
Updates a network policy. This allows you to modify the configuration of a network policy.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier for the network policy.
Request body
Updated network policy configuration details.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
Show child attributesHide child attributes
- all_ip_rangesboolean
Matches all IPv4 and IPv6 ranges (both public and private).
- included_ip_rangesobject
Will not allow IP ranges with private IPs.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- excluded_ip_rangesobject
Excluded means: all public IP ranges except this one.
Show child attributesHide child attributes
- ip_rangesarray of string
We only support IPv4 and IPv4 CIDR notation for now.
- destinationobject
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobject
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
Show child attributesHide child attributes
- endpointsobjectBeta
Matches requests arriving through any of the specified registered endpoints.
Show child attributesHide child attributes
- endpoint_idsarray of stringBeta
The IDs of the registered endpoints. Must contain at least one endpoint ID.
- all_registered_endpointsbooleanBeta
Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
- azure_workspace_private_linkbooleanBeta
Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- all_private_accessbooleanBeta
Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
Show child attributesHide child attributes
- all_source_workspacesbooleanBeta
Matches all source workspaces.
- selected_workspacesobjectBeta
Specific source workspace IDs to match.
Show child attributesHide child attributes
- workspace_idsarray of int64Beta
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
Show child attributesHide child attributes
- all_destinationsboolean
When true, match all destinations, no other destination fields can be set. When not set or false, at least one specific destination must be provided.
- workspace_uiobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- workspace_apiobject
Show child attributesHide child attributes
- scopesarray of string
- scope_qualifierstring
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- excluded_scopesarray of string
Inverse of
scopes: matches every API scope EXCEPT those listed here ("allow all except"). Mutually exclusive withscopes— a single destination may set at most one of the two.
- apps_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- lakebase_runtimeobject
Show child attributesHide child attributes
- all_destinationsboolean
Must be set to true.
- account_uiobjectBeta
Matches requests to the account console UI. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- all_destinationsbooleanBeta
Must be set to true.
- account_apiobjectBeta
Matches requests to account-level APIs. Can only be used in the account-level network policy.
Show child attributesHide child attributes
- scopesarray of stringBeta
The API scopes to match. Use "all-apis" to match any account-level API.
- scope_qualifierstringBeta
Qualifies the breadth of API access for the listed scopes. See ApiScopeQualifier.
API_SCOPE_QUALIFIER_READAPI_SCOPE_QUALIFIER_ALL
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
Show child attributesHide child attributes
- identity_typestring
IDENTITY_TYPE_UNSPECIFIEDIDENTITY_TYPE_ALL_USERSIDENTITY_TYPE_ALL_SERVICE_PRINCIPALSIDENTITY_TYPE_SELECTED_IDENTITIES
- identitiesarray of object
Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Show child attributesHide child attributes
- principal_typestring
PRINCIPAL_TYPE_UNSPECIFIEDPRINCIPAL_TYPE_USERPRINCIPAL_TYPE_SERVICE_PRINCIPAL
- principal_idint64
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Response
Returns the AccountNetworkPolicy object.
Delete a network policy GA
DELETE
Deletes a network policy. Cannot be called on 'default-policy'.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier of the network policy to delete.