cancel
Showing results forย 
Search instead forย 
Did you mean:ย 
Data Engineering
Join discussions on data engineering best practices, architectures, and optimization strategies within the Databricks Community. Exchange insights and solutions with fellow data engineers.
cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Is there a way that admins can restrict users to install libraries on clusters and notebooks?

morganmazouchi
Contributor
 
1 ACCEPTED SOLUTION

Accepted Solutions

morganmazouchi
Contributor

I found the answer to my question for how to restrict library installation both on clusters and notebooks and posting it here for others reference: we can restrict outbound access to the public pypi at the workspace level using these instructions https://docs.databricks.com/administration-guide/cloud-configurations/aws/customer-managed-vpc.html#...

View solution in original post

6 REPLIES 6

-werners-
Esteemed Contributor III

you can assign permissions to (existing) clusters.

There are 4 kinds of permissions:

  • no permission (says enough I think)
  • Can Attach To: attach a notebook (and display logs)
  • Can Restart: same as above with stop/start/restart
  • Can Manage: same as Restart but with cluster resize and library install

So basically if you assign Attach or Restart permissions, the user is not allowed to install libraries.

That is only allowed with the Manage permission.

https://docs.microsoft.com/en-us/azure/databricks/security/access-control/cluster-acl#cluster-level-...

morganmazouchi
Contributor

I found the answer to my question for how to restrict library installation both on clusters and notebooks and posting it here for others reference: we can restrict outbound access to the public pypi at the workspace level using these instructions https://docs.databricks.com/administration-guide/cloud-configurations/aws/customer-managed-vpc.html#...

With it being restricted at the cluster level as well how are you installing libraries that need to be added adhoc? Did you block the entire pypi domain?

Admin can set up a connection to Azure Artifactory/Jfrog Artifactory or other artifactories of required libraries for the workloads.

Anonymous
Not applicable

@Mojgan Mazouchiโ€‹ - I'm so glad you found the answer and shared it with us. Thank you!

Sebastian
Contributor

one way to manage is make the cluster permission only to can restart and then use an init script to install libraries on start up so that users wont install libraries on the fly.

Connect with Databricks Users in Your Area

Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you wonโ€™t want to miss the chance to attend and share knowledge.

If there isnโ€™t a group near you, start one and help create a community that brings people together.

Request a New Group