Databricks

Access-control and protection-setting guidance for Databricks managed with Terraform.

Documentation

Article Path
Review Databricks AWS node allocation terraform/databricks/cluster_aws_attributes
Review Databricks Azure node allocation terraform/databricks/cluster_azure_attributes
Review Databricks GCP node allocation terraform/databricks/cluster_gcp_attributes
Databricks OBO token lifetime is unspecified terraform/databricks/indefinitely_obo_token
Review Databricks group membership and permissions terraform/databricks/group_without_user_or_instance_profile
Review Databricks spark_submit_task usage terraform/databricks/use_spark_submit_task
Databricks autoscaling bounds are incomplete terraform/databricks/autoscale_badly_setup
Databricks personal access token lifetime is unspecified terraform/databricks/indefinitely_token
Review Databricks Runtime support policy terraform/databricks/use_lts_spark_version
Review Databricks job and cluster permissions terraform/databricks/databricks_permissions
Databricks IP allow-list permits all IPv4 addresses terraform/databricks/unrestricted_acl

Related pages11

Review Databricks AWS node allocation

Check whether spot nodes, on-demand nodes and availability-zone selection meet the recovery needs of a Databricks AWS cluster.

Review Databricks Azure node allocation

Match Databricks Azure spot VM use and on-demand fallback to the workload’s tolerance for interruption.

Review Databricks GCP node allocation

Match preemptible nodes and fallback capacity in a Databricks GCP cluster to its recovery requirements.

Databricks OBO token lifetime is unspecified

Limit the lifetime of Databricks tokens issued on behalf of service principals.

Review Databricks group membership and permissions

Review Databricks group membership, purpose and permissions together to avoid retaining unnecessary access.

Review Databricks spark_submit_task usage

Use a task type suited to the Databricks workload where possible.

Databricks autoscaling bounds are incomplete

Specify both the minimum and maximum worker counts for Databricks autoscaling.

Databricks personal access token lifetime is unspecified

Limit Databricks personal access tokens to the time needed for their purpose.

Review Databricks Runtime support policy

Check Databricks Runtime support dates and plan version selection and updates for long-running operations.

Review Databricks job and cluster permissions

Limit Databricks job and cluster permissions to the users, groups, and service principals that need them.

Databricks IP allow-list permits all IPv4 addresses

Limit a Databricks IP allow-list to the public addresses that need access.