Published: November 1, 2023
by Kelly Albano, Bhavin Kukadia and Samrat Ray
We are excited to announce the general availability (GA) of several key security features for Databricks on Google Cloud:
At Databricks, we recognize that data is your most valuable asset. With the GA of these critical security capabilities, you can protect your data at rest, keep your data private, and mitigate data exfiltration risks on the Databricks Data Intelligence Platform.
In this blog, we will address commonly asked security questions and walk you through the new security features and capabilities that are now generally available on Google Cloud.
Most enterprise customers want to ensure that their users and workloads can process their security data in a private and isolated environment. With Databricks, you can secure the network perimeter and configure end-to-end private connectivity with the customer-managed virtual private cloud (VPC) and Private Service Connect (PSC). This includes:
Now in Limited Availability with GA-level functionality, Private Service Connect can now be leveraged by Google Cloud customers for their Databricks workspaces with the recommendation for production use, full support, and SLAs. A PSC-enabled private workspace helps you mitigate several data exfiltration risks, such as access from unauthorized networks using leaked credentials or exposure of data on the internet.
Our recent Databricks on Google Cloud Security Best Practices blog explains how you can isolate your Databricks environment and secure your data using capabilities such as customer-managed VPCs, Private Service Connect and IP ACLs.
Databricks encrypts all data at rest by default within our managed services. For added control and visibility, several enterprise customers also need the ability to protect their data with encryption keys managed by them in Cloud KMS.
Now generally available on Google Cloud, Databricks customer-managed keys for encryption feature enables you to bring your own encryption keys to protect data at rest in Databricks managed services and workspace storage:
IP access lists (IP ACLs) allow you to control the networks permitted to access your Databricks resources over the internet. IP ACLs help you reduce the risk of unauthorized access using stolen credentials and meet compliance requirements. For example, specific industries and regulatory frameworks require organizations to restrict access to data or applications based on geographical locations or specific IPs.
There are two types of IP ACLs on Databricks now generally available on Google Cloud:
Private Service Connect, customer-managed keys, and IP ACLs are available on the Premium Tier of Google Cloud. For step-by-step instructions on configuring these features for your Databricks workspaces, refer to our documentation (Private Service Connect | CMK | IP ACLs). Please note that Databricks support for private connectivity using Private Service Connect (PSC) is in Limited Availability, with GA-level functionality. Contact your Databricks representative to request access.
Please visit our Security and Trust Center for more information about Databricks security practices and features available to customers.