Top Gradient

PrivateLink for Databricks Workspace on AWS

Organizations using Databricks with AWS PrivateLink can still use connect SELECT to their Databricks Workspace with a few extra steps. Please reach out to your SELECT account representative to start the process.

This guide walks you through enabling AWS PrivateLink between your Databricks workspace and SELECT.

Prerequisites

  • Databricks account on the Enterprise plan
  • Databricks account admin role
  • The AWS region of your Databricks workspace (for example, us-east-1)

Step 1 — Share your region and workspace URL with SELECT

Contact your SELECT representative and provide:

  • Your Databricks workspace's AWS region (for example, us-east-1)
  • Your Databricks workspace URL (for example, dbc-xxxx-xxxx.cloud.databricks.com)

In return, SELECT will give you the VPCE ID for your region, and will use your workspace URL to add a DNS entry so that traffic from SELECT's infrastructure resolves to your workspace via PrivateLink once setup is complete.

Step 2 — Register the VPC endpoint in Databricks

In your Databricks account console:

  1. Go to Security → Networking → VPC endpoints
  2. Click Register a VPC endpoint
  3. Enter a name (for example, select-privatelink-<region>) and select your AWS region
  4. Paste SELECT's VPCE ID from Step 1 into the AWS VPC endpoint ID field
  5. Click Register new VPC endpoint

Step 3 — Configure Private Access Settings

Go to Security → Networking → Private access settings.

If your workspace already has a private access setting, edit it and add the VPCE registered in Step 2 to the allowed endpoints.

If you don't have one yet, create a new one:

  1. Click Add private access setting
  2. Enter a name (for example, select-privatelink-<region>) and set the region to match your workspace's AWS region
  3. Set the Private access level to include the VPCE registered in Step 2
  4. Optionally keep public access enabled initially for testing, then disable it once confirmed working

Step 4 — Attach Private Access Settings to your workspace

  1. Go to Workspaces in the Databricks account console and click on your workspace
  2. Scroll to the Networking section and click Edit
  3. Under Private access setting, select the private access settings object from Step 3
  4. Save and wait for the workspace to update
Note: Once a private access setting is attached to a workspace, it cannot be removed — you can only change it to a different private access setting or modify the existing one. See Update a running or failed workspace.

Step 5 — Add your Databricks connection to SELECT

Once the workspace update completes, add your Databricks workspace to SELECT using your standard workspace URL:

1dbc-xxxx-xxxx.cloud.databricks.com

Use this as the Workspace URL in your SELECT connection settings. SELECT's infrastructure will route traffic to your workspace privately via the endpoint registered in Step 2.

Step 6 — Network policy (if applicable)

If your Databricks workspace has network policies restricting inbound connections, add SELECT's private IP ranges to the allowlist:

IP rangePurpose
`10.124.0.0/28`SELECT backend
`10.1.128.0/17`The periodic job that reads your Snowflake metadata

Get up and running in less than 15 minutes

Connect your Snowflake, Databricks, or BigQuery account and instantly understand your savings potential.

CTA Screen