๐ก๏ธ Azure Databricks Workspace Secure Cluster Connectivity is not enabled๐ข
- Contextual name: ๐ก๏ธ Databricks Workspace Secure Cluster Connectivity is not enabled๐ข
- ID:
/ce/ca/azure/databricks/no-public-ip - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Descriptionโ
Descriptionโ
Enable secure cluster connectivity (also known as no public IP) on Azure Databricks workspaces to ensure that clusters do not have public IP addresses and communicate with the control plane over a secure connection.
Rationaleโ
Enabling secure cluster connectivity limits exposure to the public internet, improving security and reducing the risk of external attacks.
Impactโ
Enabling secure cluster connectivity requires careful network configuration. Before secure cluster connectivity can be enabled, Azure Databricks workspaces must be deployed in a customer-managed virtual network (VNet injection), refer to the policy
Azure Databricks Workspace is not deployed in a customer-managed virtual network (VNet).Auditโ
This policy flags an Azure Databricks Workspace as
INCOMPLAINTif theParameters JSONfield does not contain the enableNoPublicIp parameter set to true.Default Valueโ
No Public IPis set toEnabledby default.Referencesโ
... see more
Remediationโ
Remediationโ
From Azure Portalโ
- Go to
Azure Databricks.- Click the name of a workspace.
- Under
Settings, clickNetworking.- Under
Network access, next toDeploy Azure Databricks workspace with Secure Cluster Connectivity (No Public IP), click the radio button next toEnabled.- Click
Save.- Repeat steps 1-5 for each workspace requiring remediation.
From Azure CLIโ
For each workspace requiring remediation, run the following command to set
enableNoPublicIptotrue:az databricks workspace update /
--resource-group {{resource-group}} /
--name {{workspace}} /
--enable-no-public-ip trueFrom PowerShellโ
For each workspace requiring remediation, run the following command to set
EnableNoPublicIPtoTrue:Update-AzDatabricksWorkspace `
-ResourceGroupName {{resource-group}} `
-Name {{workspace}} `
-EnableNoPublicIP
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS Azure v5.0.0 โ ๐ผ 2.1.9 Ensure 'No Public IP' is set to 'Enabled' (Automated) | 1 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Public and Anonymous Access | 110 | no data |