<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Workspace deployed via AWS Marketplace. in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154643#M5146</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;Databricks TLS validation requires SNI with the correct hostname for certificate verification - Check if you are connecting to the metastore via IP &lt;/SPAN&gt;&lt;SPAN class=""&gt;instead of hostname.&amp;nbsp;&lt;SPAN&gt;Always use the documented metastore hostname.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ensure the Databricks Private Link VPC endpoints are configured (*.cloud.databricks.com &amp;amp; meta store) with "&lt;/SPAN&gt;&lt;STRONG&gt;Enable Private DNS&lt;/STRONG&gt;&lt;SPAN&gt;" checked so hostnames resolve to private IPs &amp;amp; not public. Verify the endpoint status is In Service in AWS VPC Console. Exclude *.cloud.databricks.com from interception i&lt;SPAN&gt;f using a proxy/TLS inspection appliance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Apr 2026 12:09:59 GMT</pubDate>
    <dc:creator>balajij8</dc:creator>
    <dc:date>2026-04-15T12:09:59Z</dc:date>
    <item>
      <title>Workspace deployed via AWS Marketplace.</title>
      <link>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154459#M5143</link>
      <description>&lt;P&gt;Workspace deployed via AWS Marketplace.&lt;BR /&gt;Internal endpoint 10.53.215.1 exists in VPC but&lt;BR /&gt;SSL handshake fails. Cannot connect to metastore.&lt;BR /&gt;Workspace URL: dbc-bb08dd2f-f142.cloud.databricks.com&lt;BR /&gt;AWS Account: 452456948535&lt;BR /&gt;Region: us-east-1"&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 14:19:45 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154459#M5143</guid>
      <dc:creator>KrumIT</dc:creator>
      <dc:date>2026-04-14T14:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace deployed via AWS Marketplace.</title>
      <link>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154509#M5144</link>
      <description>&lt;P&gt;Can you try using the hostname for your endpoint instead of IP address .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 17:50:23 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154509#M5144</guid>
      <dc:creator>pradeep_singh</dc:creator>
      <dc:date>2026-04-14T17:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace deployed via AWS Marketplace.</title>
      <link>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154643#M5146</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Databricks TLS validation requires SNI with the correct hostname for certificate verification - Check if you are connecting to the metastore via IP &lt;/SPAN&gt;&lt;SPAN class=""&gt;instead of hostname.&amp;nbsp;&lt;SPAN&gt;Always use the documented metastore hostname.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ensure the Databricks Private Link VPC endpoints are configured (*.cloud.databricks.com &amp;amp; meta store) with "&lt;/SPAN&gt;&lt;STRONG&gt;Enable Private DNS&lt;/STRONG&gt;&lt;SPAN&gt;" checked so hostnames resolve to private IPs &amp;amp; not public. Verify the endpoint status is In Service in AWS VPC Console. Exclude *.cloud.databricks.com from interception i&lt;SPAN&gt;f using a proxy/TLS inspection appliance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 12:09:59 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154643#M5146</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-04-15T12:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Workspace deployed via AWS Marketplace.</title>
      <link>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154679#M5147</link>
      <description>&lt;P&gt;Databricks endpoints present certificates for hostnames like *.cloud.databricks.com (or *.privatelink.cloud.databricks.com when PrivateLink is enabled). If your client connects to &lt;A href="https://10.53.215.1" target="_blank"&gt;https://10.53.215.1&lt;/A&gt; directly, the TLS ClientHello typically lacks the right SNI hostname, and the server returns a cert that doesn’t match the IP → handshake fails.&lt;BR /&gt;Fix: Always connect using the workspace URL hostname, not the IP:&lt;/P&gt;&lt;P&gt;dbc-bb08dd2f-f142.cloud.databricks.com (public DNS)&lt;BR /&gt;or dbc-bb08dd2f-f142.privatelink.cloud.databricks.com (if private access settings force PrivateLink)&lt;/P&gt;&lt;P&gt;Databricks explicitly recommends allowlisting FQDNs (not IPs) because IPs can change and are not the stable contract for SCC relay / endpoints.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 18:42:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/workspace-deployed-via-aws-marketplace/m-p/154679#M5147</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2026-04-15T18:42:29Z</dc:date>
    </item>
  </channel>
</rss>

