Account Network Policy
AccountNetworkPolicy object
- network_policy_idstring
The unique identifier for the network policy.
- account_idstring
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstringBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstringBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstringBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstringBeta
The label for this ingress rule.
Get GA
GET
Gets a network policy.
API scopes: networking
Parameters
- network_policy_idstringpath
The unique identifier of the network policy to retrieve.
- account_idstringpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
Response
Returns the AccountNetworkPolicy object.
List GA
GET
Gets an array of network policies.
API scopes: networking
Parameters
- account_idstringpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- page_tokenstringquery
Pagination token to go to next page based on previous query.
Response
Returns a list of AccountNetworkPolicy objects.
Create GA
POST
Creates a new network policy to manage which network destinations can be accessed from the <Databricks> environment.
API scopes: networking
Parameters
- account_idstringpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
Request body
- network_policyobject
Network policy configuration details.
Show child attributesHide child attributes
- network_policy_idstring
The unique identifier for the network policy.
- account_idstring
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
- allow_rulesarray of object
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
- allow_rulesarray of object
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Response
Returns the AccountNetworkPolicy object.
Update GA
PUT
Updates a network policy. This allows you to modify the configuration of a network policy.
API scopes: networking
Parameters
- network_policy_idstringpath
The unique identifier for the network policy.
- account_idstringpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
Request body
- network_policyobject
Updated network policy configuration details.
Show child attributesHide child attributes
- network_policy_idstring
The unique identifier for the network policy.
- account_idstring
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
- allow_rulesarray of object
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
- deny_rulesarray of object
- allow_rulesarray of object
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Response
Returns the AccountNetworkPolicy object.
Delete GA
DELETE
Deletes a network policy. Cannot be called on 'default-policy'.
API scopes: networking
Parameters
- network_policy_idstringpath
The unique identifier of the network policy to delete.
- account_idstringpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.