cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
Data Engineering
Join discussions on data engineering best practices, architectures, and optimization strategies within the Databricks Community. Exchange insights and solutions with fellow data engineers.
cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

Azure Databricks DBFS Root, Storage Account Networking

sintsan
New Contributor II

For an Azure Databricks with vnet injection, we would like to change the networking on the default managed Azure Databricks storage account (dbstorage) from Enabled from all networks to Enabled from selected virtual networks and IP addresses.

Can this be done and if not can you point to some docs describing how the managed storage account is secured?

Thanks!

3 REPLIES 3

karthik_p
Esteemed Contributor

@Sander Sintjorissenā€‹ As far as i know storage config for azure is different from aws. but it looks in azure during workspace configuration encryption is enabled by default for your storage, if you want to have more security you can go with "Double Encryption for DBFS Root"

https://learn.microsoft.com/en-us/azure/databricks/security/keys/double-encryption

sintsan
New Contributor II

@karthik pā€‹  Thank you for your answer, although it does not really answer my question. Reading this post https://community.databricks.com/s/question/0D53f00001mFBAkCAO/network-security-for-dbfs-storage-acc... I understand the current workaround is to create another Azure SA and then redirect logs, etc to that account.

Is there any descriptive documentation on Azure Databricks as to what the impact of having Allow All in networking on DBFS Root actually is?

Thanks!

karthik_p
Esteemed Contributor

@Sander Sintjorissenā€‹ usually root storage bucket has below directories present in article

https://learn.microsoft.com/en-us/azure/databricks/dbfs/root-locations

to store logs related to auditing you can create another storage and add that. hope this helps

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you wonā€™t want to miss the chance to attend and share knowledge.

If there isnā€™t a group near you, start one and help create a community that brings people together.

Request a New Group