Skip to main content

Instance Profile

View as Markdown

InstanceProfile object

instance_profile_arnstring

The AWS ARN of the instance profile to register with <Databricks>. This field is required.

Example: arn:aws:iam::<account-id>:instance-profile/<name>

is_meta_instance_profileboolean

Boolean flag indicating whether the instance profile should only be used in credential passthrough scenarios. If true, it means the instance profile contains an meta IAM role which could assume a wide range of roles. Therefore it should always be used with authorization. This field is optional, the default value is false.

Default: false

iam_role_arnstring

The AWS IAM role ARN of the role associated with the instance profile. This field is required if your role name and instance profile name do not match and you want to use the instance profile with Databricks SQL Serverless.

Otherwise, this field is optional.

Example: arn:aws:iam::<account-id>:role/<name>

List GA

GET /api/2.0/instance-profiles/list

List the instance profiles that the calling user can use to launch a cluster.

This API is available to all users.

API scopes: instance-profiles

Response

Returns a list of InstanceProfile objects.

Create GA

POST /api/2.0/instance-profiles/add

Registers an instance profile in <Databricks>. In the UI, you can then give users the permission to use this instance profile when launching clusters.

This API is only available to admin users.

API scopes: instance-profiles

Request body

skip_validationboolean

By default, <Databricks> validates that it has sufficient permissions to launch instances with the instance profile. This validation uses AWS dry-run mode for the RunInstances API. If validation fails with an error message that does not indicate an IAM related permission issue, (e.g. “Your requested instance type is not supported in your requested availability zone”), you can pass this flag to skip the validation and forcibly add the instance profile.

Default: false

instance_profile_arnstring

The AWS ARN of the instance profile to register with <Databricks>. This field is required.

Example: arn:aws:iam::<account-id>:instance-profile/<name>

is_meta_instance_profileboolean

Boolean flag indicating whether the instance profile should only be used in credential passthrough scenarios. If true, it means the instance profile contains an meta IAM role which could assume a wide range of roles. Therefore it should always be used with authorization. This field is optional, the default value is false.

Default: false

iam_role_arnstring

The AWS IAM role ARN of the role associated with the instance profile. This field is required if your role name and instance profile name do not match and you want to use the instance profile with Databricks SQL Serverless.

Otherwise, this field is optional.

Example: arn:aws:iam::<account-id>:role/<name>

Update GA

POST /api/2.0/instance-profiles/edit

The only supported field to change is the optional IAM role ARN associated with the instance profile. It is required to specify the IAM role ARN if both of the following are true:

  • Your role name and instance profile name do not match. The name is the part after the last slash in each ARN.
  • You want to use the instance profile with Databricks SQL Serverless.

To understand where these fields are in the AWS console, see Enable serverless SQL warehouses.

This API is only available to admin users.

API scopes: instance-profiles

Request body

instance_profile_arnstring

The AWS ARN of the instance profile to register with <Databricks>. This field is required.

Example: arn:aws:iam::<account-id>:instance-profile/<name>

is_meta_instance_profileboolean

Boolean flag indicating whether the instance profile should only be used in credential passthrough scenarios. If true, it means the instance profile contains an meta IAM role which could assume a wide range of roles. Therefore it should always be used with authorization. This field is optional, the default value is false.

Default: false

iam_role_arnstring

The AWS IAM role ARN of the role associated with the instance profile. This field is required if your role name and instance profile name do not match and you want to use the instance profile with Databricks SQL Serverless.

Otherwise, this field is optional.

Example: arn:aws:iam::<account-id>:role/<name>

Delete GA

POST /api/2.0/instance-profiles/remove

Remove the instance profile with the provided ARN. Existing clusters with this instance profile will continue to function.

This API is only accessible to admin users.

API scopes: instance-profiles

Request body

instance_profile_arnstring

The ARN of the instance profile to remove. This field is required.

Example: arn:aws:iam::<account-id>:instance-profile/<name>