<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: X_NHC_CONTROL_PLANE_UNREACHABLE in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165580#M5517</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247683"&gt;@taglud_dbw&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The first thing I would check: does the subnet actually have outbound Internet access?&lt;/P&gt;&lt;P&gt;This is especially important for a recently created VNet/workspace. Azure changed its default behavior: for new VNets, subnets now default to being private, so VMs do not automatically receive default outbound Internet connectivity. An explicit outbound mechanism such as a NAT Gateway is required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft specifically calls this out for Azure Databricks: new VNet-injected workspaces require explicit outbound connectivity, and NAT Gateway is the recommended approach.&lt;/P&gt;&lt;P&gt;"After March 31, 2026, new VNets require explicit outbound connectivity methods. See secure cluster connectivity."&lt;/P&gt;</description>
    <pubDate>Wed, 12 Aug 2026 21:42:54 GMT</pubDate>
    <dc:creator>szymon_dybczak</dc:creator>
    <dc:date>2026-08-12T21:42:54Z</dc:date>
    <item>
      <title>X_NHC_CONTROL_PLANE_UNREACHABLE</title>
      <link>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165576#M5516</link>
      <description>&lt;P&gt;I have this issue&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;[details] X_NHC_CONTROL_PLANE_UNREACHABLE: Instance failed network health check before bootstrapping with fatal error: X_NHC_CONTROL_PLANE_UNREACHABLE 2 failed component(s): control_plane internet Retryable: true Based on the failure results: List(entity: "**region**-c2.azuredatabricks.net" outcome: "unreachable" duration_sec: 281.2346 message: "curl: (28) Connection timed out after 10000 milliseconds" last_error_code: 28 , entity: "www.databricks.com" outcome: "unreachable" duration_sec: 225.03764 message: "curl: (28) Failed to connect to &amp;nbsp;www.databricks.com port 443 after 7603 ms: Connection timed out" last_error_code: 28 )(OnDemand)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i did all the network check recommanded by AI&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;No custom route tables&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;No custom DNS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;No failed Azure deployments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN&gt;Correct NSG rules&lt;BR /&gt;what could be the issue in your opinion ? should i recreate the resource ?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 12 Aug 2026 20:51:18 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165576#M5516</guid>
      <dc:creator>taglud_dbw</dc:creator>
      <dc:date>2026-08-12T20:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: X_NHC_CONTROL_PLANE_UNREACHABLE</title>
      <link>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165580#M5517</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/247683"&gt;@taglud_dbw&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The first thing I would check: does the subnet actually have outbound Internet access?&lt;/P&gt;&lt;P&gt;This is especially important for a recently created VNet/workspace. Azure changed its default behavior: for new VNets, subnets now default to being private, so VMs do not automatically receive default outbound Internet connectivity. An explicit outbound mechanism such as a NAT Gateway is required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft specifically calls this out for Azure Databricks: new VNet-injected workspaces require explicit outbound connectivity, and NAT Gateway is the recommended approach.&lt;/P&gt;&lt;P&gt;"After March 31, 2026, new VNets require explicit outbound connectivity methods. See secure cluster connectivity."&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2026 21:42:54 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165580#M5517</guid>
      <dc:creator>szymon_dybczak</dc:creator>
      <dc:date>2026-08-12T21:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: X_NHC_CONTROL_PLANE_UNREACHABLE</title>
      <link>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165591#M5520</link>
      <description>&lt;DIV&gt;&lt;FONT size="3"&gt;Recreating the workspace or VNet won't solve X_NHC_CONTROL_PLANE_UNREACHABLE as the&amp;nbsp;error indicates that the underlying instances are failing outbound health checks over HTTPS during the node bootstrap sequence. Issue mostly stems from a subtle egress path restriction or subnet-level misconfiguration.&lt;/FONT&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="3"&gt;Check for an upstream Firewall or Network Virtual Appliance. Even if you haven't assigned custom route tables directly, verify whether forced tunneling or an upstream firewall is intercepting internet traffic via an inherited 0.0.0.0/0 route and silently dropping outbound HTTPS traffic to the control plane.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="3"&gt;Check the subnet delegation and Service Endpoints. Verify that both the public and private subnets are correctly delegated to Microsoft.Databricks/workspaces. Check under Subnets → Service Endpoints to ensure Microsoft.AzureDatabricks is enabled where required.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="3"&gt;If you are using Azure Private Link, verify that private endpoint DNS resolution is running as expected. If its a standard deployment, ensure outbound internet egress isn't being blocked at a broader network boundary.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="3"&gt;Review NSG outbound rules to ensure you are utilizing the AzureDatabricks Service Tag rather than relying on individual static IP addresses, which can lead to connection timeouts if the underlying control plane infrastructure relies on dynamic ranges.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 13 Aug 2026 05:26:52 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/x-nhc-control-plane-unreachable/m-p/165591#M5520</guid>
      <dc:creator>balajij8</dc:creator>
      <dc:date>2026-08-13T05:26:52Z</dc:date>
    </item>
  </channel>
</rss>

