databricks Databricks Blog ·

Databricks Private Link now supports account-level resources and custom URLs

blogsecuritydatabrickspreviewarchitect
feature

Databricks has enhanced Inbound Private Link to support account-level resources, including Genie One and the account console, alongside custom URLs. This update allows a single General Access endpoint to serve all workspace and account-level UIs and APIs across regions, simplifying management. It strengthens security by ensuring user-to-Databricks traffic remains on private cloud networks, crucial for enterprises with sensitive data. These new capabilities are available in Beta on AWS Enterprise and Azure Premium tiers, integrating with context-based ingress controls.

  • Inbound Private Link supports account-level resources
  • Custom URLs and Managed DR stable URLs supported
  • Consolidated General Access endpoint for all resources
  • Integrated with context-based ingress controls
Features (2)
  • Inbound Private Link supports account-level resources

    Databricks Inbound Private Link now extends to account-level resources such as Genie One, the account console, Governance Hub, and account-level APIs. This allows enterprises to apply the same network guarantees to these high-level services, ensuring private traffic routing.

  • Custom URLs and Managed DR stable URLs supported

    The service now works with custom URLs (e.g., acme.databricks.com) and Managed Disaster Recovery stable URLs. This provides greater flexibility and branding consistency for private access while maintaining network isolation.

Enhancements (1)
  • Consolidated General Access endpoint for all resources

    A single shared General Access endpoint in any region can now serve all workspace and account-level UIs and APIs. This eliminates the need for one endpoint per region or workspace, reducing manual effort and cost, though per-region configuration is still needed for service-direct and SCC relay endpoints.

Notes (1)
  • Integrated with context-based ingress controls

    These new capabilities are built into context-based ingress controls, allowing account admins to define fine-grained allow/deny rules based on identity, network source, and destination. Policies for account-level resources can be defined in a new account-policy.

Read the original announcement →

https://www.databricks.com/blog/inbound-private-link-now-supports-account-level-genie-one-account-console-and-custom-urls

Related releases