Louis_Frolio
Databricks Employee
Databricks Employee

Greetings @jpm2617 , I did some digging and would like to share my thoughts:

@szymon_dybczak nailed the root cause. Your [Errno -3] Temporary failure in name resolution when calling google.com is the classic symptom of a workspace attached to a restricted serverless egress policy, even when the policy is named default_policy and looks like the Databricks default. The name "default" does not guarantee full internet access.

A few clarifications and a clear set of next steps.

  1. You need the Account Console, not the workspace Admin page

The controls live at the account layer, not the workspace one:

Account Console → Security → Networking → Context-based ingress & egress control

If you only see workspace VPC options and no "Context-based ingress & egress control" section, one of two things is happening. You're still in the workspace UI, or you don't have account admin rights. Cluster VPC and secure cluster connectivity settings live in the workspace Network tab, but they're not what you need here.

  1. You need account admin rights to see or edit the policy

Only users with the account admin role (or equivalent) can open the network policy object and change its egress and internet access mode. If the "Context-based ingress & egress control" section is missing entirely, it's one of these:

  • You're not actually in the Account Console
  • Your user is not an account admin
  • Your account or plan does not expose the feature (some lightweight or free setups don't)

If it's the third case, I don't know of a supported way for you to override serverless egress on your own today. You'd need your account team or Databricks Support to confirm what's available on your specific tenant. I can't tell which account type you're on from the screenshot alone, so I won't guess at it.

  1. What to change once you're in the right place

Once you're in the Account Console as an account admin, do this in order:

a. Go to Security → Networking → Context-based ingress & egress control. b. Open the policy attached to your workspace (you've already identified it as default_policy). c. On the Egress tab, set Internet access to one of these:

  • "Allow access to all destinations" if you truly want unrestricted outbound internet so google.com and similar resolve.
  • "Allow access only to selected domains" and add the specific domains your serverless compute needs to reach. d. Restart your serverless compute so the new egress rules apply. e. Re-run your test GET against https://www.google.com to confirm.
  1. If you don't actually want public internet

Many customers deliberately keep serverless off the public internet and front required services through Private Link or NCC (Network Connectivity Configuration). All traffic stays on private cloud networks, which reduces exposure. Databricks engineering has written about this pattern for exactly this scenario. If that's your real goal, follow those patterns instead of opening full outbound internet.

Takeaway

If you can confirm you're in the Account Console as an account admin and you still don't see "Context-based ingress & egress control," this is almost certainly an account or plan configuration limit. Open a Databricks Support ticket or contact your account team to verify whether serverless egress policy management is enabled for your tenant, and if not, what your options are.

Hope this helps.

Regards, Louis.