Databricks IP allow-list permits all IPv4 addresses

Limit a Databricks IP allow-list to the public addresses that need access.

Description

An active Databricks IP allow-list containing 0.0.0.0/0 includes every IPv4 address in its allowed range. This weakens IP-based restrictions but does not remove user authentication.

Potential impact

Clients outside the intended office or VPN networks can attempt to access the workspace.

Remediation

Remove the unrestricted range from the ALLOW list and permit only the required public egress addresses of offices or VPNs. Verify that workspace IP access lists are enabled and that required connection paths still work.

Examples

The addresses below are examples. Replace them with actual public egress addresses and enable IP access lists for the workspace.

Before

hcl
resource "databricks_ip_access_list" "workspace_allowlist" {
  label      = "allow_in"
  list_type  = "ALLOW"
  ip_addresses = [
    "0.0.0.0/0",
    "1.2.5.0/24"
  ]
}

After

hcl
resource "databricks_ip_access_list" "workspace_allowlist" {
  label      = "allow_in"
  list_type  = "ALLOW"
  ip_addresses = [
    "1.2.3.0/24",
    "1.2.5.0/24"
  ]
}

References