Skip to main content

Account Network Policy

View as Markdown

AccountNetworkPolicy object

network_policy_idstring

The unique identifier for the network policy.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstring

The associated account ID for this Network Policy object.

Example: 123e4567-e89b-12d3-a456-426614174000

egressobject

The network policies applying for egress traffic.

Show child attributesHide child attributes
network_accessobject

The access policy enforced for egress traffic to the internet.

Show child attributesHide child attributes
restriction_modestring

The restriction mode that controls how serverless workloads can access the internet.

Values: RESTRICTION_MODE_UNSPECIFIED, FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

allowed_internet_destinationsarray of object

List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

Show child attributesHide child attributes
destinationstring

The internet destination to which access will be allowed. Format dependent on the destination type.

Example: example.dest.domain.com

internet_destination_typestring

The type of internet destination. Currently only DNS_NAME is supported.

Values: INTERNET_DESTINATION_TYPE_UNSPECIFIED, DNS_NAME

Example: DNS_NAME

allowed_storage_destinationsarray of object

List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

Show child attributesHide child attributes
bucket_namestring
AWS

The name of the S3 storage bucket.

GCP

The name of the GGS bucket or S3 storage bucket for cross-cloud access to AWS S3.

Example: my-cloud-storage

regionstring
AWS

The region in which the S3 bucket is located.

GCP

The AWS region in which the cross-cloud S3 bucket is located.

Example: us-west-1

storage_destination_typestring

The type of storage destination.

GCP

In addition to GOOGLE_CLOUD_STORAGE, AWS_S3 can be used for cross-cloud access

Values: STORAGE_DESTINATION_TYPE_UNSPECIFIED, AWS_S3, AZURE_STORAGE, GOOGLE_CLOUD_STORAGE

Example: AWS_S3

azure_storage_accountstring

The Azure storage account name.

Example: example

azure_storage_servicestring

The Azure storage service type (blob, dfs, etc.).

Example: blob

policy_enforcementobject

Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES

Show child attributesHide child attributes
enforcement_modestring

The mode of policy enforcement. ENFORCED blocks traffic that violates policy, while DRY_RUN only logs violations without blocking. When not specified, defaults to ENFORCED.

Values: ENFORCEMENT_MODE_UNSPECIFIED, ENFORCED, DRY_RUN

Example: DRY_RUN

dry_run_mode_product_filterarray of string

When empty, it means dry run for all products. When non-empty, it means dry run for specific products and for the other products, they will run in enforced mode.

Values: DRY_RUN_MODE_PRODUCT_FILTER_UNSPECIFIED, DBSQL, ML_SERVING

Example: DBSQL

blocked_internet_destinationsarray of objectBeta

List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.

Show child attributesHide child attributes
destinationstring

The internet destination to which access will be allowed. Format dependent on the destination type.

Example: example.dest.domain.com

internet_destination_typestring

The type of internet destination. Currently only DNS_NAME is supported.

Values: INTERNET_DESTINATION_TYPE_UNSPECIFIED, DNS_NAME

Example: DNS_NAME

ingressobject

The network policies applying for ingress traffic.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
Show child attributesHide child attributes
originobject
destinationobject
authenticationobject
labelstring

The label for this ingress rule.

Constraints: <= 255 characters

allow_rulesarray of object
Show child attributesHide child attributes
originobject
destinationobject
authenticationobject
labelstring

The label for this ingress rule.

Constraints: <= 255 characters

private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

Show child attributesHide child attributes
originobjectBeta

The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.

destinationobjectBeta

The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.

authenticationobjectBeta

The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).

labelstringBeta

The label for this ingress rule.

Constraints: <= 255 characters

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

Show child attributesHide child attributes
originobjectBeta

The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.

destinationobjectBeta

The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.

authenticationobjectBeta

The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).

labelstringBeta

The label for this ingress rule.

Constraints: <= 255 characters

ingress_dry_runobject

The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
Show child attributesHide child attributes
originobject
destinationobject
authenticationobject
labelstring

The label for this ingress rule.

Constraints: <= 255 characters

allow_rulesarray of object
Show child attributesHide child attributes
originobject
destinationobject
authenticationobject
labelstring

The label for this ingress rule.

Constraints: <= 255 characters

private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

Show child attributesHide child attributes
originobjectBeta

The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.

destinationobjectBeta

The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.

authenticationobjectBeta

The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).

labelstringBeta

The label for this ingress rule.

Constraints: <= 255 characters

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

Show child attributesHide child attributes
originobjectBeta

The origin the request must match — the private connectivity the request arrives through, for example a specific set of registered endpoints or any endpoint registered to the account. See PrivateRequestOrigin.

destinationobjectBeta

The destination the request must match — the resource being accessed, for example the workspace UI, workspace APIs, or account-level APIs. See RequestDestination.

authenticationobjectBeta

The authenticated identity the request must match. When unset, the rule matches all users and service principals. On the account-level network policy, scoping to specific identities is not currently supported, so this field must be unset (the rule matches all users and service principals).

labelstringBeta

The label for this ingress rule.

Constraints: <= 255 characters

Get GA

GET /api/2.0/accounts/{account_id}/network-policies/{network_policy_id}

Gets a network policy.

API scopes: networking

Parameters

network_policy_idstringpath

The unique identifier of the network policy to retrieve.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstringpath

Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.

Example: 123e4567-e89b-12d3-a456-426614174000

Response

Returns the AccountNetworkPolicy object.

List GA

GET /api/2.0/accounts/{account_id}/network-policies

Gets an array of network policies.

API scopes: networking

Parameters

account_idstringpath

Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.

Example: 123e4567-e89b-12d3-a456-426614174000

page_tokenstringquery

Pagination token to go to next page based on previous query.

Response

Returns a list of AccountNetworkPolicy objects.

Create GA

POST /api/2.0/accounts/{account_id}/network-policies

Creates a new network policy to manage which network destinations can be accessed from the <Databricks> environment.

API scopes: networking

Parameters

account_idstringpath

Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.

Example: 123e4567-e89b-12d3-a456-426614174000

Request body

network_policyobject

Network policy configuration details.

Show child attributesHide child attributes
network_policy_idstring

The unique identifier for the network policy.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstring

The associated account ID for this Network Policy object.

Example: 123e4567-e89b-12d3-a456-426614174000

egressobject

The network policies applying for egress traffic.

Show child attributesHide child attributes
network_accessobject

The access policy enforced for egress traffic to the internet.

Show child attributesHide child attributes
restriction_modestring

The restriction mode that controls how serverless workloads can access the internet.

Values: RESTRICTION_MODE_UNSPECIFIED, FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

allowed_internet_destinationsarray of object

List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

allowed_storage_destinationsarray of object

List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

policy_enforcementobject

Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES

blocked_internet_destinationsarray of objectBeta

List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.

ingressobject

The network policies applying for ingress traffic.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
allow_rulesarray of object
private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

ingress_dry_runobject

The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
allow_rulesarray of object
private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

Response

Returns the AccountNetworkPolicy object.

Update GA

PUT /api/2.0/accounts/{account_id}/network-policies/{network_policy_id}

Updates a network policy. This allows you to modify the configuration of a network policy.

API scopes: networking

Parameters

network_policy_idstringpath

The unique identifier for the network policy.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstringpath

Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.

Example: 123e4567-e89b-12d3-a456-426614174000

Request body

network_policyobject

Updated network policy configuration details.

Show child attributesHide child attributes
network_policy_idstring

The unique identifier for the network policy.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstring

The associated account ID for this Network Policy object.

Example: 123e4567-e89b-12d3-a456-426614174000

egressobject

The network policies applying for egress traffic.

Show child attributesHide child attributes
network_accessobject

The access policy enforced for egress traffic to the internet.

Show child attributesHide child attributes
restriction_modestring

The restriction mode that controls how serverless workloads can access the internet.

Values: RESTRICTION_MODE_UNSPECIFIED, FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

allowed_internet_destinationsarray of object

List of internet destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

allowed_storage_destinationsarray of object

List of storage destinations that serverless workloads are allowed to access when in RESTRICTED_ACCESS mode.

policy_enforcementobject

Optional. When policy_enforcement is not provided, we default to ENFORCE_MODE_ALL_SERVICES

blocked_internet_destinationsarray of objectBeta

List of internet destinations that serverless workloads are blocked from accessing. These destinations are enforced when restriction mode is RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE support is planned.

ingressobject

The network policies applying for ingress traffic.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
allow_rulesarray of object
private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

ingress_dry_runobject

The ingress policy for dry run mode. Dry run will always run even if the request is allowed by the ingress policy. When this field is set, the policy will be evaluated and emit logs only without blocking requests.

Show child attributesHide child attributes
public_accessobject

The network policy restrictions for public access to the workspace. Configures how public internet traffic is allowed or denied access.

Show child attributesHide child attributes
restriction_modestring

Values: FULL_ACCESS, RESTRICTED_ACCESS

Example: RESTRICTED_ACCESS

deny_rulesarray of object
allow_rulesarray of object
private_accessobjectBeta

The network policy restrictions for private access. Configures how requests arriving over private connectivity are governed.

Show child attributesHide child attributes
restriction_modestringBeta

The restriction mode for private access.

Values: ALLOW_ALL_REGISTERED_ENDPOINTS, RESTRICTED_ACCESS

Example: ALLOW_ALL_REGISTERED_ENDPOINTS

deny_rulesarray of objectBeta

Deny rules are evaluated first. A request matching any deny rule is denied, regardless of allow rules. Only applies when restriction_mode is RESTRICTED_ACCESS.

allow_rulesarray of objectBeta

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS.

Azure

Allow rules are evaluated after deny rules. A request matching any allow rule is allowed; a request matching no rule is denied by default. Only applies when restriction_mode is RESTRICTED_ACCESS. Requests arriving through the workspace's Azure Private Link (ui-api) endpoints are allowed even without a matching allow rule, unless explicitly denied by a deny rule whose origin is azure_workspace_private_link or all_private_access.

Response

Returns the AccountNetworkPolicy object.

Delete GA

DELETE /api/2.0/accounts/{account_id}/network-policies/{network_policy_id}

Deletes a network policy. Cannot be called on 'default-policy'.

API scopes: networking

Parameters

network_policy_idstringpath

The unique identifier of the network policy to delete.

Example: example-policy-name

Constraints: ^[a-zA-Z0-9_.-]{1,32}$

account_idstringpath

Your <Databricks> account ID. You can find your account ID in your <Databricks> accounts console.

Example: 123e4567-e89b-12d3-a456-426614174000