Skip to main content

Networking

Databricks provides a secure networking environment by default. You can configure additional networking features to control access to workspaces, secure connectivity between the control plane and compute planes, and protect connections to your data sources.

note

Databricks charges for networking costs when serverless workloads connect to customer resources, and when performance-intensive services egress data cross-region back to clients. See Understand Databricks networking costs.

How Databricks networking fits together​

Databricks networking spans three connection points, each secured independently. The features in the sections below map to these connections:

  • Users and applications to Databricks: Control inbound access to workspaces and account-level resources with private connectivity, context-based ingress control, and IP access lists. See Users to Databricks networking.
  • The control plane and the classic compute plane: Deploy classic compute in your own virtual network and keep control plane traffic on private networking. See Classic compute plane networking.
  • The serverless compute plane and your resources: Govern how the Databricks-managed serverless compute plane reaches your data and services with egress controls, private connectivity, and firewall configurations. See Serverless compute plane networking.

For the control plane and compute plane architecture behind these connections, see Network reference architecture overview.

Get started​

Understand Databricks networking architecture and explore key concepts.

Connectivity​

Configure secure network connections for inbound access to workspaces and outbound connectivity from compute resources.

Network security​

Implement security controls to restrict and monitor network access.