<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Databricks shared workspace in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109184#M2957</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/148096"&gt;@nskiran1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, it is possible to have a 'shared' workspace that can be tied to multiple AWS accounts. This can be achieved by associating multiple VPCs (Virtual Private Clouds) across different AWS accounts with a single Databricks account&lt;/P&gt;
&lt;P&gt;You should associate your VPCs and create a cross account IAM role&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/admin/account-settings-e2/credentials.html#step-1-create-a-cross-account-iam-role" target="_blank"&gt;https://docs.databricks.com/en/admin/account-settings-e2/credentials.html#step-1-create-a-cross-account-iam-role&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/security/network/classic/customer-managed-vpc.html" target="_blank"&gt;https://docs.databricks.com/en/security/network/classic/customer-managed-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/admin/account-settings-e2/credentials.html" target="_blank"&gt;https://docs.databricks.com/en/admin/account-settings-e2/credentials.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2025 13:03:57 GMT</pubDate>
    <dc:creator>Alberto_Umana</dc:creator>
    <dc:date>2025-02-06T13:03:57Z</dc:date>
    <item>
      <title>Databricks shared workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109181#M2956</link>
      <description>&lt;DIV class=""&gt;We have a Self service portal through which users can launch databricks clusters of different configurations.&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;This portal is set up to work in Dev, Sandbox and Prod environments. We have configured databricks workspaces only for Sandbox and Prod portals only. So, users can launch databricks clusters through Sandbox and Prod portals. No databricks workspace available for Dev Portal.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Self service portal invokes different databricks APIs like list/delete/register instance profiles, create/delete clusters etc using Python. We have set up Service Principals for all the databricks workspaces and invoke databricks APIs with respective service principals.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Recently, our management decided to route databricks cluster launch requests from Dev portal to Sandbox databricks workspace on urgent basis as we do not have databricks workspace for Dev portal&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Is it possible to have databricks 'shared' workspace that can be tied to multiple AWS accounts? Can someone share documentation on IAM permissions policies on how to configure multiple AWS accounts for shared workspace please?&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Feb 2025 13:02:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109181#M2956</guid>
      <dc:creator>nskiran1</dc:creator>
      <dc:date>2025-02-06T13:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks shared workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109184#M2957</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/148096"&gt;@nskiran1&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Yes, it is possible to have a 'shared' workspace that can be tied to multiple AWS accounts. This can be achieved by associating multiple VPCs (Virtual Private Clouds) across different AWS accounts with a single Databricks account&lt;/P&gt;
&lt;P&gt;You should associate your VPCs and create a cross account IAM role&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/admin/account-settings-e2/credentials.html#step-1-create-a-cross-account-iam-role" target="_blank"&gt;https://docs.databricks.com/en/admin/account-settings-e2/credentials.html#step-1-create-a-cross-account-iam-role&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/security/network/classic/customer-managed-vpc.html" target="_blank"&gt;https://docs.databricks.com/en/security/network/classic/customer-managed-vpc.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.databricks.com/en/admin/account-settings-e2/credentials.html" target="_blank"&gt;https://docs.databricks.com/en/admin/account-settings-e2/credentials.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2025 13:03:57 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109184#M2957</guid>
      <dc:creator>Alberto_Umana</dc:creator>
      <dc:date>2025-02-06T13:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Databricks shared workspace</title>
      <link>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109572#M2963</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/106294"&gt;@Alberto_Umana&lt;/a&gt;&amp;nbsp;Thanks for sharing doc links&lt;/P&gt;&lt;P&gt;We have exact same set up to support shared databricks workspace. But still Im facing issue while adding instance profile&lt;/P&gt;&lt;P&gt;I am trying to add AWS Instance Profile created in source AWS Account (No databricks workspace) to a target AWS Account to which databricks workspace set up available. Is this possible?&lt;/P&gt;&lt;P&gt;I have added required IAM permissions for both instance profile as well as cross account role. What else am I missing here?&lt;/P&gt;&lt;P&gt;{"error_code":"DRY_RUN_FAILED","message":"Verification of the instance profile failed. AWS error: You are not authorized to perform this operation.","details":[{"@type":"type.googleapis.com/google.rpc.ErrorInfo","reason":"CM_API_ERROR_SOURCE_CALLER_ERROR","domain":""}]}&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 07:34:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/databricks-shared-workspace/m-p/109572#M2963</guid>
      <dc:creator>nskiran</dc:creator>
      <dc:date>2025-02-10T07:34:58Z</dc:date>
    </item>
  </channel>
</rss>

