Review Azure Databricks virtual-network placement

Match classic-compute networking to connectivity and isolation requirements.

Description

Azure Databricks VNet injection places classic compute in a customer-managed virtual network. Use it when the default managed network cannot meet required routing or private-connectivity policies.

Potential impact

An unsuitable deployment model can make required internal data connections or network isolation difficult to implement.

Remediation

When needed, configure the VNet, two delegated subnets, NSG associations, and routing. Changing an existing workspace’s VNet requires replacement, so plan migration first.

Examples

These excerpts show VNet-injection fields. Preconfigure both subnets and NSG associations and supply their IDs. Serverless networking is configured separately.

Before

hcl
resource "azurerm_databricks_workspace" "example" {
  name                        = "example-dbw"
  location                    = azurerm_resource_group.example.location
  resource_group_name         = azurerm_resource_group.example.name
  sku                         = "premium"
  managed_resource_group_name = "example-managed-rg"
}

After

hcl
resource "azurerm_databricks_workspace" "example" {
  name                        = "example-dbw"
  location                    = azurerm_resource_group.example.location
  resource_group_name         = azurerm_resource_group.example.name
  sku                         = "premium"
  managed_resource_group_name = "example-managed-rg"

  custom_parameters {
    virtual_network_id = azurerm_virtual_network.example.id
    public_subnet_name = var.databricks_public_subnet_name
    private_subnet_name = var.databricks_private_subnet_name
    public_subnet_network_security_group_association_id = var.public_subnet_nsg_association_id
    private_subnet_network_security_group_association_id = var.private_subnet_nsg_association_id
  }
}

References