<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Recommendations for Designing Cluster Policies Across Dev/QA/Prod Environments for DE and DA teams in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/recommendations-for-designing-cluster-policies-across-dev-qa/m-p/126714#M2550</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;We are working on implementing Databricks cluster policies across our organization and are seeking advice on best practices to enforce governance, security, and cost control across different environments.&lt;/P&gt;&lt;P&gt;We have two main teams using Databricks across multiple environments:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Data Engineering – Dev / QA / Prod&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Data &amp;amp; Analytics – Dev / QA / Prod&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Each environment has a separate Databricks workspace. Our goal is to define robust cluster policies that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;Enforce configuration standards (e.g., disallow public IPs, enforce autoscaling, fixed Spark configs)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Control costs (e.g., limit max workers/memory in dev/QA)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Ensure production stability (e.g., disallow in it scripts or spot instances in prod)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Allow safe experimentation in dev while keeping strong guardrails&lt;BR /&gt;&lt;BR /&gt;Trying to decide:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Should we define one policy per team per environment (e.g., data-engineering, analytics) or have general reusable policies for each environment type?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;What are common policy restrictions used in Dev/QA vs. Prod?&lt;BR /&gt;(e.g., disallowing public IPs, enforcing autoscaling, limiting worker sizes, etc.)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any example templates or reusable patterns followed in other large organizations?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Any tips for balancing developer flexibility with platform governance?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Please differentiate between data engineers and data analytics across all environments and provide the code for it.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;We appreciate any advice, templates, or governance experiences you can share!&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 28 Jul 2025 14:38:06 GMT</pubDate>
    <dc:creator>Charansai</dc:creator>
    <dc:date>2025-07-28T14:38:06Z</dc:date>
    <item>
      <title>Recommendations for Designing Cluster Policies Across Dev/QA/Prod Environments for DE and DA teams</title>
      <link>https://community.databricks.com/t5/data-governance/recommendations-for-designing-cluster-policies-across-dev-qa/m-p/126714#M2550</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;We are working on implementing Databricks cluster policies across our organization and are seeking advice on best practices to enforce governance, security, and cost control across different environments.&lt;/P&gt;&lt;P&gt;We have two main teams using Databricks across multiple environments:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Data Engineering – Dev / QA / Prod&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Data &amp;amp; Analytics – Dev / QA / Prod&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Each environment has a separate Databricks workspace. Our goal is to define robust cluster policies that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;Enforce configuration standards (e.g., disallow public IPs, enforce autoscaling, fixed Spark configs)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Control costs (e.g., limit max workers/memory in dev/QA)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Ensure production stability (e.g., disallow in it scripts or spot instances in prod)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Allow safe experimentation in dev while keeping strong guardrails&lt;BR /&gt;&lt;BR /&gt;Trying to decide:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Should we define one policy per team per environment (e.g., data-engineering, analytics) or have general reusable policies for each environment type?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;What are common policy restrictions used in Dev/QA vs. Prod?&lt;BR /&gt;(e.g., disallowing public IPs, enforcing autoscaling, limiting worker sizes, etc.)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any example templates or reusable patterns followed in other large organizations?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Any tips for balancing developer flexibility with platform governance?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Please differentiate between data engineers and data analytics across all environments and provide the code for it.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;We appreciate any advice, templates, or governance experiences you can share!&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:38:06 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/recommendations-for-designing-cluster-policies-across-dev-qa/m-p/126714#M2550</guid>
      <dc:creator>Charansai</dc:creator>
      <dc:date>2025-07-28T14:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendations for Designing Cluster Policies Across Dev/QA/Prod Environments for DE and DA tea</title>
      <link>https://community.databricks.com/t5/data-governance/recommendations-for-designing-cluster-policies-across-dev-qa/m-p/126773#M2552</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I believe these are a few suggestions that can help!&lt;BR /&gt;Start with environment-based policies: dev, qa, prod&lt;BR /&gt;These policies define the broadest guardrails (security, cost control, stability)&lt;BR /&gt;Add team-specific variants only if required&lt;BR /&gt;For example: prod cluster policy is shared, unless Data Engineering needs special Spark config&lt;/P&gt;&lt;P&gt;Use one base policy per environment, and define optional team-specific overlays when needed&lt;/P&gt;&lt;P&gt;Below are a few sample templates for policies -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
  "name": "qa-shared-policy",
  "definition": {
    "spark_version": { "type": "fixed", "value": "&amp;lt;DBR&amp;gt;" },
    "node_type_id": {
      "type": "allowlist",
      "values": ["Standard_D4s_v3"]
    },
    "autoscale.min_workers": { "type": "fixed", "value": 2 },
    "autoscale.max_workers": { "type": "fixed", "value": 6 },
    "enable_elastic_disk": { "type": "fixed", "value": true },
    "init_scripts": { "type": "forbidden" },
    "aws_attributes.availability": { "type": "fixed", "value": "SPOT" },
    "custom_tags.environment": { "type": "fixed", "value": "qa" }
  }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
  "name": "prod-data-engineering",
  "definition": {
    "spark_version": { "type": "fixed", "value": "&amp;lt;DBR&amp;gt;" },
    "node_type_id": {
      "type": "allowlist",
      "values": ["Standard_D8s_v3"]
    },
    "autoscale.min_workers": { "type": "fixed", "value": 2 },
    "autoscale.max_workers": { "type": "fixed", "value": 10 },
    "enable_elastic_disk": { "type": "fixed", "value": true },
    "init_scripts": { "type": "forbidden" },
    "aws_attributes.availability": { "type": "fixed", "value": "ON_DEMAND" },
    "data_security_mode": { "type": "fixed", "value": "USER_ISOLATION" },
    "custom_tags.team": { "type": "fixed", "value": "data-eng" },
    "custom_tags.environment": { "type": "fixed", "value": "prod" }
  }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each environment typically enforces a distinct set of restrictions based on its purpose. In Dev and QA, policies often allow greater flexibility to support experimentation and testing. Spot instances, for instance, are usually allowed in Dev to reduce cost, while in QA they might be optional depending on workload criticality. Public IPs are typically disallowed in all environments to maintain network security. Dev clusters generally enforce small, cost-effective node types with autoscaling enabled and worker limits kept low (e.g., 1–4 workers). Init scripts are usually permitted in Dev for experimentation but are tightly controlled or disabled altogether in QA and disallowed in Prod to ensure production stability.&lt;/P&gt;&lt;P&gt;In contrast, Prod policies are much more restrictive. Spot instances and user-defined init scripts are usually disabled to ensure reliability and reduce the risk of unexpected behavior. Node types are limited to high-performance, stable instances, and autoscaling is still enabled, but with a higher upper bound to handle larger workloads. Runtime versions are often pinned and reviewed to ensure compatibility and security, and data security modes are enforced (e.g., USER_ISOLATION or TABLE_ACL when using Unity Catalog). Additionally, mandatory tagging (such as team, environment, cost_center) is enforced across all environments to support cost attribution, auditing, and governance.&lt;/P&gt;&lt;P&gt;Please refer to these documentations below as well -&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/security" target="_blank"&gt;https://docs.databricks.com/aws/en/security&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.databricks.com/aws/en/data-governance/unity-catalog" target="_blank"&gt;https://docs.databricks.com/aws/en/data-governance/unity-catalog&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 08:39:10 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/recommendations-for-designing-cluster-policies-across-dev-qa/m-p/126773#M2552</guid>
      <dc:creator>Vidhi_Khaitan</dc:creator>
      <dc:date>2025-07-29T08:39:10Z</dc:date>
    </item>
  </channel>
</rss>

