Skip to main content

Users to Databricks networking

This guide introduces features to customize network access between users and their Databricks workspaces and account-level resources.

By default, users and applications can connect to Databricks from any IP address. Users might access critical data sources using Databricks. If a user's credentials are compromised through phishing or a similar attack, securing network access dramatically reduces the risk of an account takeover. Configurations like private connectivity, IP access lists, and firewalls help keep critical data secure.

You can also configure authentication and access control features to protect your users' credentials, see Authentication and access control.

The features on this page secure how users and applications connect to Databricks, one of the three connection points in the Databricks networking architecture.

See Network reference architecture overview.

note

Users to Databricks secure networking features require the Enterprise plan.

Private connectivity​

Between Databricks users and the control plane, PrivateLink provides strong controls that limit the source for inbound requests. If your organization routes traffic through an AWS environment, you can use PrivateLink to ensure the communication between users and the Databricks control plane does not traverse public IP addresses. See Configure inbound PrivateLink for workspaces.

Context-based ingress control​

Context-based ingress control uses account-configured policies that combine identity, request type, and network source to determine who can reach your workspaces and account-level resources. Workspace-level policies govern access to workspaces, and a single account-level policy (account-policy) governs access to account-level resources, such as the account console.

For the access types, network sources, and identities you can match, along with enforcement modes and how ingress interacts with IP access lists and private connectivity, see Context-based ingress control.

To configure policies, see Manage workspace context-based ingress policies and Manage account context-based ingress policies.

IP access lists​

Authentication proves user identity, but it does not enforce the users' network location. Accessing a cloud service from an unsecured network poses security risks, especially when the user may have authorized access to sensitive or personal data. Using IP access lists, you can configure Databricks workspaces so that users connect to the service only through existing networks with a secure perimeter.

You can also use IP access lists to control access to account-level resources.

Admins can specify the IP addresses that are allowed access to Databricks. You can also specify IP addresses or subnets to block. For details, see Manage IP access lists.

You can also use PrivateLink to block all public internet access to a Databricks workspace.

Firewall rules​

Many organizations use firewall to block traffic based on domain names. You must allow list Databricks domain names to ensure access to Databricks resources. For more information, see Configure domain name firewall rules.

Databricks also performs host header validation to ensure requests use authorized Databricks domains like .cloud.databricks.com. Requests using domains outside of the Databricks network will be blocked. This security measure protects against potential HTTP host header attacks.