Skip to main content

Configure private connectivity to AWS-managed resources

important

Private connectivity from serverless compute to Amazon S3 Federal Information Processing Standards (FIPS) endpoints is supported in US and Canada regions. If your workspace requires FIPS endpoints, including FedRAMP Moderate and FedRAMP High workspaces, select the S3 FIPS endpoint service when you create the private endpoint rule.

The S3 FIPS endpoint service must be in the same region as the network connectivity configuration (NCC). S3 FIPS doesn't support cross-region private connectivity. This FIPS support applies only to S3, not to the other AWS-managed resources on this page.

note

Databricks charges for networking costs when serverless workloads connect to customer resources, and when performance-intensive services egress data cross-region back to clients. See Understand Databricks networking costs.

This page explains how to configure private connectivity from serverless compute to AWS-managed resources using the Databricks account console UI.

Private connectivity to AWS-managed resources.

Configuring private connectivity for serverless compute provides:

  • A dedicated and private connection: Ensures secure and isolated access between your serverless workspaces and the AWS resource, limiting access to authorized connections only.
  • Enhanced data exfiltration mitigation: While serverless compute with Unity Catalog provides built-in data exfiltration protection, PrivateLink adds an extra layer of network defense. Using AWS PrivateLink, your data traffic remains entirely in the AWS network, never traversing the public internet. This architecture, combined with controlled access through VPC endpoints, reduces the attack surface for data exfiltration.
note

The dedicated VPC endpoint configured in this procedure handles serverless compute access to the AWS resource. The Databricks control plane also reaches some resources for metadata operations. For S3, Unity Catalog accesses your bucket from the control plane, so your bucket policy must allow Unity Catalog in addition to the serverless endpoint. See Step 3. If you also access the resource from within your company's network, include your corporate VPN IPs in the resource's policy.

note

When you access an S3 bucket through this private connection, such as from a notebook or query, use the DNS name that matches the endpoint service:

  • Standard S3: {your-s3-bucket}.s3.{region}.amazonaws.com
  • S3 FIPS: {your-s3-bucket}.s3-fips.{region}.amazonaws.com

Legacy global endpoints like {your-s3-bucket}.s3.amazonaws.com are not supported.

Supported resources​

Private connectivity from serverless compute supports the following AWS-managed resources:

Resource

Endpoint DNS

Bedrock

bedrock.{region}.amazonaws.com

Bedrock Agent

bedrock-agent.{region}.amazonaws.com

Bedrock Agent Runtime

bedrock-agent-runtime.{region}.amazonaws.com

Bedrock Runtime

bedrock-runtime.{region}.amazonaws.com

DynamoDB

dynamodb.{region}.amazonaws.com

EMR

elasticmapreduce.{region}.amazonaws.com

Glue

glue.{region}.amazonaws.com

Key Management Service (KMS)

kms.{region}.amazonaws.com

Lambda

lambda.{region}.amazonaws.com

RDS

rds.{region}.amazonaws.com

RDS Data API

rds-data.{region}.amazonaws.com

RDS Performance Insights

pi.{region}.amazonaws.com

Redshift

redshift.{region}.amazonaws.com

Redshift Data API

redshift-data.{region}.amazonaws.com

Redshift Serverless

redshift-serverless.{region}.amazonaws.com

S3 (same region or cross-region)

s3.{region}.amazonaws.com

S3 FIPS (same region only)

s3-fips.{region}.amazonaws.com

Secrets Manager

secretsmanager.{region}.amazonaws.com

Security Token Service (STS)

sts.{region}.amazonaws.com

Simple Notification Service (SNS)

sns.{region}.amazonaws.com

Simple Queue Service (SQS)

sqs.{region}.amazonaws.com

Resource

Endpoint DNS

Bedrock

bedrock.{region}.amazonaws.com

Bedrock Agent

bedrock-agent.{region}.amazonaws.com

Bedrock Agent Runtime

bedrock-agent-runtime.{region}.amazonaws.com

Bedrock Runtime

bedrock-runtime.{region}.amazonaws.com

DynamoDB

dynamodb.{region}.amazonaws.com

EMR

elasticmapreduce.{region}.amazonaws.com

Glue

glue.{region}.amazonaws.com

Key Management Service (KMS)

kms.{region}.amazonaws.com

Lambda

lambda.{region}.amazonaws.com

RDS

rds.{region}.amazonaws.com

RDS Data API

rds-data.{region}.amazonaws.com

RDS Performance Insights

pi.{region}.amazonaws.com

Redshift

redshift.{region}.amazonaws.com

Redshift Data API

redshift-data.{region}.amazonaws.com

Redshift Serverless

redshift-serverless.{region}.amazonaws.com

S3 (same region or cross-region)

s3.{region}.amazonaws.com

S3 FIPS (same region only)

s3-fips.{region}.amazonaws.com

Secrets Manager

secretsmanager.{region}.amazonaws.com

Security Token Service (STS)

sts.{region}.amazonaws.com

Simple Notification Service (SNS)

sns.{region}.amazonaws.com

Simple Queue Service (SQS)

sqs.{region}.amazonaws.com

note
  • S3 and S3 FIPS support per-bucket scoping. Standard S3 supports same-region and cross-region private connectivity. S3 FIPS supports same-region private connectivity only. For all other resources, the private endpoint applies to all traffic from workspaces attached to the NCC that targets the resource type. There is no per-instance scoping.
  • When you access your S3 bucket through this private connection, use {your-s3-bucket}.s3.{region}.amazonaws.com for standard S3 or {your-s3-bucket}.s3-fips.{region}.amazonaws.com for S3 FIPS. Legacy endpoints like {your-s3-bucket}.s3.amazonaws.com are not supported.

Requirements​

  • The workspace is on the Enterprise plan.
  • You are the account administrator of your Databricks account.
  • You have at least one functional workspace using serverless compute.
  • You have appropriate AWS IAM permissions to create and modify the AWS resource's policy and to create VPC endpoints.
  • Each Databricks account can have up to 10 NCCs per region.
  • Each region can have 30 private endpoints, distributed as needed across 1-10 NCCs.
  • Each NCC can be attached to up to 50 workspaces.
  • For S3, each NCC can have one S3 private endpoint rule per region, and each rule can include up to 100 bucket names.

Configure private connectivity​

Create a network connectivity configurations (NCC) object​

You can skip this step if you have an existing NCC in the same region and AWS account that you want to use.

  1. In the account console, click Security.
  2. Select the Network connectivity configurations tab.
  3. Select Add network configuration.
  4. Enter a name for the NCC.
  5. Select the region. This must match your workspace region.
  6. Click Add.

Create an AWS interface endpoint​

important

Do not enable your private endpoint until you have updated the resource policy.

  1. Go to the Private endpoint rules section in your NCC.
  2. Select Add private endpoint rule.
  3. Under Resource type, select the AWS resource you want to connect to (for example, S3 bucket, Bedrock, or RDS). For the full list, see Supported resources.
  4. Configure the rule settings:
    • Endpoint Service: For an S3 bucket, select the endpoint service from the drop-down menu. To use S3 FIPS, select com.amazonaws.<NCC-region>.s3-fips. For other resource types, this field is automatically populated.
    • S3 bucket names (S3 only): Enter the bucket names for your destination resources. For all other resource types, no bucket or resource name field appears. The private endpoint applies to all traffic to the selected resource type.
    • Region (S3 only): For standard S3, optionally specify the region of the destination S3 buckets. If you don't specify a region, the NCC's region is used. For S3 FIPS, the destination bucket and the endpoint service must be in the NCC's region.

Restrict access to the private endpoint​

Before you enable the private endpoint, restrict access to the AWS resource so that only traffic from the VPC endpoint returned in the previous step, and any other sources you approve, can reach it. Where you apply this restriction depends on whether the resource supports resource-based policies:

How to restrict access

Resources

Add a Deny statement to the resource's own policy. See the Resource-based policy tab.

DynamoDB, Glue, KMS, Lambda, Secrets Manager, SNS, SQS

Add a Deny statement to a bucket policy, and also allow the Databricks control plane. See the S3 bucket tab.

S3

Add a Deny statement as an inline policy on the IAM role that the resource's service credential uses. See the IAM role policy tab.

Bedrock, Bedrock Agent, Bedrock Agent Runtime, Bedrock Runtime, EMR, RDS, RDS Data API, RDS Performance Insights, Redshift, Redshift Data API, Redshift Serverless, STS

How to restrict access

Resources

Add a Deny statement to the resource's own policy. See the Resource-based policy tab.

DynamoDB, Glue, KMS, Lambda, Secrets Manager, SNS, SQS

Add a Deny statement to a bucket policy, and also allow the Databricks control plane. See the S3 bucket tab.

S3

Add a Deny statement as an inline policy on the IAM role that the resource's service credential uses. See the IAM role policy tab.

Bedrock, Bedrock Agent, Bedrock Agent Runtime, Bedrock Runtime, EMR, RDS, RDS Data API, RDS Performance Insights, Redshift, Redshift Data API, Redshift Serverless, STS

In every case, use an explicit Deny rather than an Allow. In AWS, access is denied by default, so an Allow statement only grants access. Allow statements can't confine access to a specific path. To limit access to the private endpoint, deny every request whose source is not the VPC endpoint, because an explicit Deny overrides any Allow.

warning

A Deny statement with "Principal": "*" blocks every request that doesn't carry a matching aws:SourceVpce key, including access from the AWS console, the AWS CLI, and IAM identities in your account. Before you enable the endpoint, add every source you still need, such as administrative IAM roles or corporate VPN IP ranges, to the policy. Otherwise, you can lose console and administrative access to the resource. Enabling the endpoint manually in the next step gives you time to update these policies before serverless traffic starts routing through the endpoint.

These resources let you attach a policy directly to the resource. Add a Deny statement that denies any request whose source is not the VPC endpoint returned in the previous step. The following example denies all access to a DynamoDB table unless the request comes through that endpoint:

JSON
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyAccessOutsideVpcEndpoint",
"Effect": "Deny",
"Principal": "*",
"Action": "dynamodb:*",
"Resource": "arn:aws:dynamodb:{region}:{account-id}:table/{table-name}",
"Condition": {
"StringNotEquals": {
"aws:SourceVpce": "vpce-12345"
}
}
}
]
}

Replace vpce-12345 with the VPC endpoint returned in the previous step. The policy mechanism and the Action values depend on the resource. For example, KMS uses key policies and Secrets Manager uses secret resource policies. Refer to the AWS documentation for your resource.

note

These private endpoints cover each AWS service's API: management operations and, for the Data API variants (rds-data and redshift-data), HTTP-based SQL queries. They do not cover direct JDBC or ODBC database connections to RDS or Redshift instances, which use separate instance DNS names.

Refresh the UI or make an API call to confirm the rule's status changes to ESTABLISHED.

Enable private endpoint rule​

  1. Click the kebab menu button.
  2. Click Update rule.
  3. Select Enable rule.
important

This step routes traffic for the configured AWS resource through PrivateLink for any workspace attached to the NCC. Before proceeding, verify you have updated the resource policy to allow resource access from the VPC endpoint.

Attach the NCC to one or more workspaces​

This step associates your configured private connectivity with your serverless workspaces. Skip this step if your workspace is already attached to the desired NCC. To attach the NCC to a workspace:

  1. Go to Workspaces in the left-hand navigation.
  2. Select an existing workspace.
  3. Select Update Workspace.
  4. Under Network connectivity configurations, select the drop-down menu and select the NCC you've created.
  5. Repeat for all workspaces you'd like this NCC to apply to.

Verify connectivity​

The way you verify connectivity depends on the resource type. For resources other than S3, simulate traffic from a notebook by making a call to the resource through the appropriate AWS SDK (for example, a Bedrock model invocation or a Lambda function call), then check the resource's access logs to confirm that the request arrives through the VPC endpoint.

The following example tests connectivity to an S3 bucket by registering it as an external location and running a query:

  1. Register your bucket as an external location. See external locations.

  2. Open the SQL editor.

  3. Run:

    SQL
    CREATE TABLE {catalog}.{schema}.test_connectivity LOCATION 's3://{your-s3-bucket}/test_connectivity'

It can take ten minutes for the connection to fully establish.

note

If your network policy restricts external access, direct connections to your AWS S3 bucket's DNS names are blocked. Add {your-s3-bucket}.s3.{region}.amazonaws.com for standard S3 or {your-s3-bucket}.s3-fips.{region}.amazonaws.com for S3 FIPS to your network policy's Allowed domains. See Manage network policies for serverless egress control.

Access to your S3 buckets must use the regional endpoint that matches the configured endpoint service. Legacy endpoints like {your-s3-bucket}.s3.amazonaws.com are not supported.

To verify connectivity for a resource that you cannot register as a Unity Catalog external location, such as a Delta Sharing endpoint, run a DNS lookup against the resource's endpoint from a notebook and confirm that it resolves to a private IP address:

%sh nslookup <resource-endpoint>

Next steps​