Description
An active Databricks IP allow-list containing 0.0.0.0/0 includes every IPv4 address in its allowed range. This weakens IP-based restrictions but does not remove user authentication.
Potential impact
Clients outside the intended office or VPN networks can attempt to access the workspace.
Remediation
Remove the unrestricted range from the ALLOW list and permit only the required public egress addresses of offices or VPNs. Verify that workspace IP access lists are enabled and that required connection paths still work.
Examples
The addresses below are examples. Replace them with actual public egress addresses and enable IP access lists for the workspace.
Before
hcl
resource "databricks_ip_access_list" "workspace_allowlist" {
label = "allow_in"
list_type = "ALLOW"
ip_addresses = [
"0.0.0.0/0",
"1.2.5.0/24"
]
}
After
hcl
resource "databricks_ip_access_list" "workspace_allowlist" {
label = "allow_in"
list_type = "ALLOW"
ip_addresses = [
"1.2.3.0/24",
"1.2.5.0/24"
]
}