Databricks releases, every cloud
- Private network gateway is in Beta
Connects serverless compute to VNet and on-premises systems through a managed gateway. Enabled from account console Previews page.
- Private network gateway is in Private Preview
Connects serverless compute to VPC and on-premises systems through a managed gateway, reusing existing network connectivity configuration.
- Inbound Private Service Connect for performance-intensive services (Beta)
Enables private connectivity to services like Zerobus Ingest and Lakebase Autoscaling on Google Cloud.
- Cross-workspace access for serverless (Beta)
Controls serverless network traffic between workspaces with ingress and egress rules.
- Custom URL access to workspaces over inbound Private Link (Beta)
Uses general_access private endpoint, serves workspaces and account-level resources across regions.
- Serverless outbound Private Service Connect to customer-managed resources (Public Preview)
Keeps traffic off the public internet, adding network-layer defense against data exfiltration through customer-managed Google Cloud service attachment.
- Run the change, do not just read it. Hands-on labs in your own Databricks workspace, graded when you submit. Browse labs
- Networking charges for performance-intensive products
Charges apply to cross-region and public-internet egress for Lakebase, OpenSharing SecureConnect, Zerobus, and Files API.
- Context-based ingress control for workspaces public access is now generally available
Uses allow and deny rules to control access based on identities, network sources, and request types.
- Allowlist partner platform IPs in context-based ingress control (Beta)
Supports Power BI, Tableau Cloud, and dbt platform, with automatic IP list updates.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Serverless compute is now available in the Azure UK West region
Supports notebooks, jobs, pipelines, and SQL warehouses, with private connectivity.
- Block specific internet destinations in network policies (Public Preview)
Blocks destinations regardless of network access mode, enforced through REST API.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Private Link for account-level resources (Beta)
Connects account console through VPC interface endpoint instead of public internet. Requires configuration.
- Inbound Private Link for performance-intensive services is now generally available
Supports Lakebase Autoscaling and Zerobus Ingest.
- Declarative Automation Bundles will soon default to use the direct deployment engine Coming soon
Replaces Terraform deployment engine, migrating bundles automatically on July 24, 2026.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Intra-VNet NSG rule hardening for Azure Databricks is now in Public Preview
Restricts workspace traffic to host and worker subnet CIDRs. Applies to classic compute plane workspaces.
- Edits to resources in the UI now automatically update YAML
Applies to jobs and pipeline settings, see Edit bundle resources.
- Azure UK South now has a dedicated regional control plane
New workspaces require firewall allowlist entries for SCC relay tunnel and other IPs. Existing workspaces use UK West control plane unless migrated.
- Connect Azure Databricks to on-premises resources using an SSH reverse tunnel
Replaces inbound firewall access, works with classic and serverless compute.
- Get this table by email. One Monday mail covering the week, filtered to the clouds and products you run. Weekly digest
- Connect Databricks to on-premises resources using an SSH reverse tunnel
Uses proxy VMs in AWS, replacing inbound firewall access.
- Databricks Asset Bundles is now Declarative Automation Bundles
Replaces Databricks Asset Bundles.
AWS, read it on their docsAzure, read it on their docsGCP, read it on their docsSAP(not on this cloud) - Inbound Private Link for performance-intensive services (Public Preview)
Enables private connectivity for Zerobus Ingest and Lakebase Autoscaling.
- Update workspace network configuration to VNet injection is now GA
Migrates from Databricks-managed VNet to customer-owned VNet.
- Serverless outbound IPs available through public JSON endpoint (Public Preview)
Replaces existing stable IPs, requires Public Preview enrollment.
- Azure virtual network service endpoint policies are now generally available
Apply to classic compute for outbound storage access filtering. Requires configuration.
- Inbound Private Link for performance-intensive services (Beta)
Enables private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- Serverless egress control is now generally available
Manages outbound connections with restricted access and FQDN filtering.
- Front-end PrivateLink for performance-intensive services (Beta)
Supports private connectivity to Zerobus Ingest and Lakebase Autoscaling.
- GCP Private Service Connect generally available
No account team request needed to enable.
- Declarative Automation Bundles in the workspace is GA
Allows collaborative editing and deployment of bundle updates through the UI.
- Configure Azure virtual network service policies for storage access (Public Preview)
Filters outbound traffic from classic compute to specific Azure Storage accounts. Requires Azure virtual network service endpoint policies.
- Updates for customer-managed VPC workspaces (Public Preview)
Adds Private Service Connect conversion and network config changes.
- Updating workspace virtual network configurations is now in Public Preview
Allows migration to custom VNet or changes to existing VNet injection setups.
- Spark Declarative Pipelines on Lakeflow template in bundles in the workspace (Public Preview)
Creates ETL pipelines in workspace bundles using Lakeflow template. Requires New ETL pipeline setup.
- Azure Private Link from serverless compute to resources in your virtual network (VNet) via a standard load balancer (SLB) is now generally available
Enables private connectivity via standard load balancer. Requires configuration.
- PrivateLink connections from serverless compute to resources in your VPC through an NLB is generally available
Uses an NLB, requires AWS PrivateLink configuration.
Headlines, dates and product areas are Databricks' own, from the release notes published for each cloud, and every item links to the note it came from. The one-line summaries are ours. Not a Databricks product and not affiliated with Databricks, Inc.