<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article [Action required] [AWS] update outbound connectivity for classic workspaces in Product Platform Updates</title>
    <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/ba-p/70061</link>
    <description>&lt;P&gt;&lt;STRONG&gt;IMPORTANT NOTE: We have indefinitely delayed the automatic enforcement described below for workspaces that had enabled workspace IP access lists prior to July 29, 2024. We still recommend manually enforcing IP access lists on compute plane requests in these workspaces by taking the steps outlined below.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note: New IP access controls enabled on workspaces after July 29, 2024 are still enforced on data plane traffic, per the original communication below.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN&gt;---------------------------------&lt;/SPAN&gt;&lt;/H2&gt;
&lt;H2&gt;&lt;SPAN&gt;Communication&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;To enhance security, we are making a change to workspaces that use the &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/en/security/network/front-end/ip-access-list.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;workspace IP access lists&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; feature. For these workspaces, we will begin to apply workspace IP access controls to compute plane traffic. See &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;Action Required&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;Timeline&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN&gt; below for details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Action Required&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This change will impact all new workspaces on July 29 2024, and existing workspaces on August 26 2024.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To ensure your compute plane can continue to talk to the Databricks control plane - take action to add the &lt;/SPAN&gt;&lt;A href="https://docs.aws.amazon.com/appstream2/latest/developerguide/add-nat-gateway-existing-vpc.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;NAT gateway&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; IP addresses to your &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/en/security/network/front-end/ip-access-list-workspace.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;workspace IP access list&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;. Step-by-step instructions are available below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Timeline&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The required actions must be taken by the following dates:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Starting on July 29 2024, &lt;/SPAN&gt;&lt;STRONG&gt;all new workspaces&lt;/STRONG&gt;&lt;SPAN&gt; that use &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/en/security/network/front-end/ip-access-list.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;workspace IP access lists&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; will begin enforcing workspace IP access lists on compute plane traffic&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;By August 26 2024, &lt;/SPAN&gt;&lt;STRONG&gt;all existing workspaces&lt;/STRONG&gt;&lt;SPAN&gt; that use &lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/en/security/network/front-end/ip-access-list.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;workspace IP access lists&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; will begin enforcing workspace IP access lists on compute plane traffic&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;SPAN&gt;Step-by-Step Instructions&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Note: If your compute plane traffic egresses through a firewall/proxy appliance, ensure that the IPs of the appliance are added to the workspace IP ACL policy. If it does not, read on for NAT gateway deployment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Retrieve IPs for the NAT gateway (via AWS console)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Find your NAT gateway in&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;https://&amp;lt;REGION&amp;gt;&lt;/SPAN&gt;&lt;A href="http://.console.aws.amazon.com/vpcconsole/home?region=" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;.console.aws.amazon.com/vpcconsole/home?region=&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;lt;REGION&amp;gt;#NatGateways:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;You can identify the NAT gateway by filtering by your compute plane VPC ID.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Note down "Primary public IPv4 address". That is your public IP of your NAT gateway.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Adding the NAT Gateway IP addresses to the workspace IP access list&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Follow the steps outlined here to add the IP addresses for the NAT gateways collected above to your workspace IP ACL policy: &lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;A href="https://docs.databricks.com/en/security/network/front-end/ip-access-list-workspace.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.databricks.com/en/security/network/front-end/ip-access-list-workspace.html&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Test that your deployment was successful&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Log in to your workspace&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Navigate to "Preview" &amp;gt; "View All"&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Find "Enforce IP access list on Compute Plane Requests". On toggle on, IP ACL will be enforced on your NAT IP&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Wait for up to 10 minutes for the config to be applied to the workspace.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;Create and run a python notebook with a new cluster of any type except serverless.&lt;/SPAN&gt;&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Cell #1&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;%pip install databricks-sdk --upgrade
dbutils.library.restartPython()
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Cell #2&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;from databricks.sdk import WorkspaceClient

w = WorkspaceClient()
w.clusters.list()
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;SPAN&gt;If the code sample works, then your IP access list is set up correctly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="2"&gt;&lt;SPAN&gt;In case of failures, toggle off "Enforce IP access list on Compute Plane Requests". Wait for up to 10 minutes for the config to be applied to the workspace.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;</description>
    <pubDate>Wed, 16 Oct 2024 16:38:07 GMT</pubDate>
    <dc:creator>AlexEsibov</dc:creator>
    <dc:date>2024-10-16T16:38:07Z</dc:date>
    <item>
      <title>[Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/ba-p/70061</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The following blog post details action required for workspaces that use workspace IP access lists.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;The communication will also be sent out by email to users who Databricks determines might be affected.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:38:07 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/ba-p/70061</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-10-16T16:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/71070#M19</link>
      <description>&lt;P&gt;We are not using NAT gateway and using Enterprise proxy for the compute resources. What is the solution for our case?&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 04:56:34 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/71070#M19</guid>
      <dc:creator>SathwickKollipa</dc:creator>
      <dc:date>2024-05-30T04:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/71119#M20</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/341"&gt;@SathwickKollipa&lt;/a&gt;&amp;nbsp;&amp;nbsp;thanks for the question. You should allow the public IPs that are used for outbound traffic for your Databricks classic compute plane. If this goes through a proxy that obfuscates the IPs, then it makes sense to use the public IPs of that proxy.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 21:21:38 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/71119#M20</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-05-30T21:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/72015#M25</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/89926"&gt;@AlexEsibov&lt;/a&gt;&amp;nbsp;, we don't allow any outbound traffic from our VPC/subnets. By default, any cluster's we spin up don't have ability to talk to internet. If it needs internet connectivity, we set proxy thru init script of the cluster.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In route table, the traffic for internet is routed to TGW and from their it routes to proxy. How does it works in our case?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:25:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/72015#M25</guid>
      <dc:creator>SathwickKollipa</dc:creator>
      <dc:date>2024-06-07T09:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/73071#M27</link>
      <description>&lt;P&gt;we don't use the NAT Gateway IP at our VPC level which using customer managed VPC for the Databricks. we use the IP whitelisting in our environment , do we still needs to whitelist anything? or not required?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2024 19:59:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/73071#M27</guid>
      <dc:creator>krikotti</dc:creator>
      <dc:date>2024-06-12T19:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/74520#M28</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/89926"&gt;@AlexEsibov&lt;/a&gt;&amp;nbsp; Does this apply to Premium Tier?&lt;/P&gt;&lt;P&gt;As in the fix it says need to be in Enterprise Pricing tier.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 01:37:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/74520#M28</guid>
      <dc:creator>sactom</dc:creator>
      <dc:date>2024-06-17T01:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: [Action required] [AWS] update outbound connectivity for classic workspaces</title>
      <link>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/74910#M30</link>
      <description>&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/341"&gt;@SathwickKollipa&lt;/a&gt;&amp;nbsp;if I understood your set-up correctly, all compute plane traffic will egress through proxy before hitting the control plane. In this case, allow-listing the IPs of the proxy in the workspace IP ACL should be sufficient.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/99490"&gt;@krikotti&lt;/a&gt;&amp;nbsp;can you clarify what you mean by "IP whitelisting in our environment"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/108670"&gt;@sactom&lt;/a&gt;&amp;nbsp;the workspace IP ACL list is available on the enterprise license tier, so this comm is not applicable to customers using the premium tier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 22:53:06 GMT</pubDate>
      <guid>https://community.databricks.com/t5/product-platform-updates/action-required-aws-update-outbound-connectivity-for-classic/bc-p/74910#M30</guid>
      <dc:creator>AlexEsibov</dc:creator>
      <dc:date>2024-06-18T22:53:06Z</dc:date>
    </item>
  </channel>
</rss>

