Databricks has expanded Inbound Private Link support to cover account-level resources such as account-level Genie One, the account console, Governance Hub, and account-level APIs. It now also supports custom URLs and Managed Disaster Recovery stable URLs end to end. A single shared General Access endpoint can serve all workspace and account-level UI and API resources in any region, removing the need for per-region or per-workspace endpoints (service-direct and SCC relay endpoints still require per-region setup). These capabilities integrate with context-based ingress controls, letting admins define allow/deny rules based on identity, network source, and destination, with a new account-policy option for account-level resources. The update is in Beta on AWS Enterprise tier and Azure Premium tier, and is additive and non-disruptive to existing configurations.

3m read timeFrom databricks.com
Post cover image
Table of contents
What's new in Inbound Private LinkBuilt on context-based ingressMinimal setup, no disruption for existing customersGet started

Questions this post answers

Does Databricks Inbound Private Link support account-level Genie One and the account console?

Yes, Inbound Private Link now supports account-level resources including account-level Genie One, the account console, Governance Hub, and account-level APIs. This lets customers put account-level Genie One behind Inbound Private Link with the same network guarantees applied to other resources. The feature is in Beta on AWS Enterprise tier and Azure Premium tier. daily.dev surfaces updates like this for teams locking down private network access to Databricks.

Can I use one Private Link endpoint across multiple regions in Databricks?

Yes, a single shared General Access endpoint in any region can now serve all workspace and account-level UI and API resources, removing the need to create one endpoint per region or workspace. Teams with hard isolation requirements can still use multiple endpoints, and those are no longer restricted to serving resources in the same region. Service-direct and SCC relay endpoints still require per-region configuration. Engineers cutting private endpoint sprawl can track Databricks networking changes on daily.dev.

Does Databricks Inbound Private Link work with custom URLs like acme.databricks.com?

Yes, Inbound Private Link now works end to end with custom URLs such as acme.databricks.com, including managed disaster recovery stable URLs like acme.databricks.com/?c=stable-ws-id. Existing non-custom workspace-specific URLs continue to work in parallel, so the change is additive and non-disruptive for current users. daily.dev helps teams evaluating custom domain and DR setups for Databricks stay current.

691 Impressions