Loading…
Inbound Private Link now supports account-level Genie One, the account console, and custom URLs
Robert Zhang, Manish Bansal, Chen He, Yankai Zhang
- Source
- Databricks
- Published
- Added to Yomu
Summary
Databricks has expanded Inbound Private Link in Beta on AWS and Azure to cover account-level resources, including account-level Genie One, the account console, Governance Hub, and account-level APIs. The update also supports custom URLs and Managed Disaster Recovery stable URLs, while one shared General Access endpoint in any region can serve workspace and account-level UI and API resources, removing the need for one endpoint per region or workspace. These capabilities use context-based ingress, where account admins define allow and deny rules by caller identity, network source, and destination through account and workspace policies. Enabling private access to account-level resources requires registering and allowlisting a General Access endpoint with the account-policy and resolving the custom URL to that endpoint. Existing workspace-specific URLs, private access settings, and IP access lists continue to work in parallel, while service-direct and SCC relay endpoints retain per-region requirements.
Context
Enterprises using Inbound Private Link to keep user-to-Databricks traffic off the public internet may operate many workspaces across multiple regions and use account-level products such as Genie One.
Approach / What changed
The update extends Inbound Private Link to account-level resources, custom URLs, and Managed Disaster Recovery stable URLs. A shared General Access endpoint can serve workspace and account-level resources across regions, with access governed by context-based ingress policies that evaluate identity, network source, and destination.
Takeaways
- Account-level Genie One, the account console, Governance Hub, and account-level APIs can now be placed behind Inbound Private Link in Beta on AWS and Azure.
- A single shared General Access endpoint in any region can serve workspace and account-level UIs and APIs; service-direct and SCC relay endpoints still require per-region configuration.
- Account-level private access requires allowlisting a General Access endpoint in the context-based ingress account-policy and resolving the custom URL to that endpoint.