Organizations using Databricks with AWS PrivateLink can still use connect SELECT to their Databricks Workspace with a few extra steps. Please reach out to your SELECT account representative to start the process.
This guide walks you through enabling AWS PrivateLink between your Databricks workspace and SELECT.
Prerequisites
- Databricks account on the Enterprise plan
- Databricks account admin role
- The AWS region of your Databricks workspace (for example,
us-east-1)
Step 1 — Share your region and workspace URL with SELECT
Contact your SELECT representative and provide:
- Your Databricks workspace's AWS region (for example,
us-east-1) - Your Databricks workspace URL (for example,
dbc-xxxx-xxxx.cloud.databricks.com)
In return, SELECT will give you the VPCE ID for your region, and will use your workspace URL to add a DNS entry so that traffic from SELECT's infrastructure resolves to your workspace via PrivateLink once setup is complete.
Step 2 — Register the VPC endpoint in Databricks
In your Databricks account console:
- Go to Security → Networking → VPC endpoints
- Click Register a VPC endpoint
- Enter a name (for example,
select-privatelink-<region>) and select your AWS region - Paste SELECT's VPCE ID from Step 1 into the AWS VPC endpoint ID field
- Click Register new VPC endpoint
Step 3 — Configure Private Access Settings
Go to Security → Networking → Private access settings.
If your workspace already has a private access setting, edit it and add the VPCE registered in Step 2 to the allowed endpoints.
If you don't have one yet, create a new one:
- Click Add private access setting
- Enter a name (for example,
select-privatelink-<region>) and set the region to match your workspace's AWS region - Set the Private access level to include the VPCE registered in Step 2
- Optionally keep public access enabled initially for testing, then disable it once confirmed working
Step 4 — Attach Private Access Settings to your workspace
- Go to Workspaces in the Databricks account console and click on your workspace
- Scroll to the Networking section and click Edit
- Under Private access setting, select the private access settings object from Step 3
- Save and wait for the workspace to update
Note: Once a private access setting is attached to a workspace, it cannot be removed — you can only change it to a different private access setting or modify the existing one. See Update a running or failed workspace.
Step 5 — Add your Databricks connection to SELECT
Once the workspace update completes, add your Databricks workspace to SELECT using your standard workspace URL:
Use this as the Workspace URL in your SELECT connection settings. SELECT's infrastructure will route traffic to your workspace privately via the endpoint registered in Step 2.
Step 6 — Network policy (if applicable)
If your Databricks workspace has network policies restricting inbound connections, add SELECT's private IP ranges to the allowlist:
| IP range | Purpose |
|---|---|
| `10.124.0.0/28` | SELECT backend |
| `10.1.128.0/17` | The periodic job that reads your Snowflake metadata |



