Account Network Policy
AccountNetworkPolicy object
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Get a network policy GA
GET
Gets a network policy.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier of the network policy to retrieve.
Response
Returns the AccountNetworkPolicy object.
List network policies GA
GET
Gets an array of network policies.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- page_tokenstringquery
Pagination token to go to next page based on previous query.
Response
Returns a list of AccountNetworkPolicy objects.
Create a network policy GA
POST
Creates a new network policy to manage which network destinations can be accessed from the <Databricks> environment.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
Request body
Network policy configuration details.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Response
Returns the AccountNetworkPolicy object.
Update a network policy GA
PUT
Updates a network policy. This allows you to modify the configuration of a network policy.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier for the network policy.
Request body
Updated network policy configuration details.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$
The unique identifier for the network policy.
- account_idstringuuid
The associated account ID for this Network Policy object.
- egressobject
The network policies applying for egress traffic.
Show child attributesHide child attributes
- network_accessobject
The access policy enforced for egress traffic to the internet.
Show child attributesHide child attributes
- restriction_modestring
The restriction mode that controls how serverless workloads can access the internet.
RESTRICTION_MODE_UNSPECIFIEDFULL_ACCESSRESTRICTED_ACCESS
- allowed_internet_destinationsarray of object
List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- allowed_storage_destinationsarray of object
List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.
Show child attributesHide child attributes
- bucket_namestring
- AWS
The name of the S3 storage bucket.
GCPThe name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.
- regionstring
- AWS
The region in which the S3 bucket is located.
GCPThe AWS region in which the cross-cloud S3 bucket is located.
- storage_destination_typestring
The type of storage destination.
GCPIn addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access
STORAGE_DESTINATION_TYPE_UNSPECIFIEDAWS_S3AZURE_STORAGEGOOGLE_CLOUD_STORAGE
- azure_storage_accountstring
The Azure storage account name.
- azure_storage_servicestring
The Azure storage service type (blob, dfs, etc.).
- policy_enforcementobject
Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES
Show child attributesHide child attributes
- enforcement_modestring
The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.
ENFORCEMENT_MODE_UNSPECIFIEDENFORCEDDRY_RUN
- dry_run_mode_product_filterarray of string
When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.
DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIEDDBSQLML_SERVING
- blocked_internet_destinationsarray of objectBeta
List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.
Show child attributesHide child attributes
- destinationstring
The internet destination to which access will be allowed. Format dependent on the destination type.
- internet_destination_typestring
The type of internet destination. Currently only DNS_NAME is supported.
INTERNET_DESTINATION_TYPE_UNSPECIFIEDDNS_NAME
- ingressobject
The network policies applying for ingress traffic.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- ingress_dry_runobject
The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.
Show child attributesHide child attributes
- public_accessobject
The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.
Show child attributesHide child attributes
- restriction_modestring
FULL_ACCESSRESTRICTED_ACCESS
- deny_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- allow_rulesarray of object
Show child attributesHide child attributes
- originobject
- destinationobject
- authenticationobject
- labelstring<= 255 characters
The label for this ingress rule.
- private_accessobjectBeta
The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for private access.
ALLOW_ALL_REGISTERED_ENDPOINTSRESTRICTED_ACCESS
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
AzureAllow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- cross_workspace_accessobjectBeta
Show child attributesHide child attributes
- restriction_modestringBeta
The restriction mode for cross-workspace access.
FULL_ACCESSRESTRICTED_ACCESSLEGACY_MODE
- deny_rulesarray of objectBeta
Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
- allow_rulesarray of objectBeta
Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.
Show child attributesHide child attributes
- originobjectBeta
The origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
- destinationobjectBeta
The destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
- authenticationobjectBeta
The authenticated identity the request must match. When unset, the rule matches all users and service principals.
- labelstring<= 255 charactersBeta
The label for this ingress rule.
Response
Returns the AccountNetworkPolicy object.
Delete a network policy GA
DELETE
Deletes a network policy. Cannot be called on 'default-policy'.
API scopes: networking
Parameters
- account_idstringuuidRequiredpath
Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.
- network_policy_idstring^[a-zA-Z0-9_.-]{1,32}$Requiredpath
The unique identifier of the network policy to delete.