Documentation
¶
Index ¶
- type AccountIpAccessList
- type AccountIpAccessListType
- type AccountIpAccessListType_IpAccessListType
- type AccountNetworkPolicy
- type AwsVpcEndpointInfo
- type AzurePrivateEndpointInfo
- type Client
- func (c *Client) CreateAccountIpAccessList(ctx context.Context, req CreateAccountIpAccessListRequest, opts ...call.Option) (*CreateAccountIpAccessListResponse, error)
- func (c *Client) CreateEndpoint(ctx context.Context, req CreateEndpointRequest, opts ...call.Option) (*Endpoint, error)
- func (c *Client) CreateIpAccessList(ctx context.Context, req CreateIpAccessListRequest, opts ...call.Option) (*CreateIpAccessListResponse, error)
- func (c *Client) CreateNccPrivateEndpointRule(ctx context.Context, req CreateNccPrivateEndpointRuleRequest, ...) (*NccPrivateEndpointRule, error)
- func (c *Client) CreateNetworkConnectivityConfigPublic(ctx context.Context, req CreateNetworkConnectivityConfigRequest, ...) (*NetworkConnectivityConfig, error)
- func (c *Client) CreateNetworkPolicyRpc(ctx context.Context, req CreateNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
- func (c *Client) CreateNetworkPublic(ctx context.Context, req CreateNetworkRequest, opts ...call.Option) (*Network, error)
- func (c *Client) CreatePrivateAccessSettingsPublic(ctx context.Context, req CreatePrivateAccessSettingsRequest, ...) (*PrivateAccessSettings, error)
- func (c *Client) CreateVpcEndpointPublic(ctx context.Context, req CreateVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
- func (c *Client) DeleteAccountIpAccessList(ctx context.Context, req DeleteAccountIpAccessListRequest, opts ...call.Option) (*DeleteAccountIpAccessListResponse, error)
- func (c *Client) DeleteEndpoint(ctx context.Context, req DeleteEndpointRequest, opts ...call.Option) error
- func (c *Client) DeleteIpAccessList(ctx context.Context, req DeleteIpAccessListRequest, opts ...call.Option) (*DeleteIpAccessListResponse, error)
- func (c *Client) DeleteNccPrivateEndpointRule(ctx context.Context, req DeleteNccPrivateEndpointRuleRequest, ...) (*NccPrivateEndpointRule, error)
- func (c *Client) DeleteNetworkConnectivityConfigPublic(ctx context.Context, req DeleteNetworkConnectivityConfigRequest, ...) error
- func (c *Client) DeleteNetworkPolicyRpc(ctx context.Context, req DeleteNetworkPolicyRequest, opts ...call.Option) error
- func (c *Client) DeleteNetworkPublic(ctx context.Context, req DeleteNetworkRequest, opts ...call.Option) (*Network, error)
- func (c *Client) DeletePrivateAccessSettingsPublic(ctx context.Context, req DeletePrivateAccessSettingsRequest, ...) (*PrivateAccessSettings, error)
- func (c *Client) DeleteVpcEndpointPublic(ctx context.Context, req DeleteVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
- func (c *Client) GetAccountIpAccessList(ctx context.Context, req GetAccountIpAccessListRequest, opts ...call.Option) (*GetAccountIpAccessListResponse, error)
- func (c *Client) GetEndpoint(ctx context.Context, req GetEndpointRequest, opts ...call.Option) (*Endpoint, error)
- func (c *Client) GetIpAccessList(ctx context.Context, req GetIpAccessListRequest, opts ...call.Option) (*GetIpAccessListResponse, error)
- func (c *Client) GetNccPrivateEndpointRule(ctx context.Context, req GetNccPrivateEndpointRuleRequest, opts ...call.Option) (*NccPrivateEndpointRule, error)
- func (c *Client) GetNetworkConnectivityConfigPublic(ctx context.Context, req GetNetworkConnectivityConfigRequest, ...) (*NetworkConnectivityConfig, error)
- func (c *Client) GetNetworkPolicyRpc(ctx context.Context, req GetNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
- func (c *Client) GetNetworkPublic(ctx context.Context, req GetNetworkRequest, opts ...call.Option) (*Network, error)
- func (c *Client) GetPrivateAccessSettingsPublic(ctx context.Context, req GetPrivateAccessSettingsRequest, opts ...call.Option) (*PrivateAccessSettings, error)
- func (c *Client) GetVpcEndpointPublic(ctx context.Context, req GetVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
- func (c *Client) GetWorkspaceNetworkOptionRpc(ctx context.Context, req GetWorkspaceNetworkOptionRequest, opts ...call.Option) (*WorkspaceNetworkOption, error)
- func (c *Client) ListAccountIpAccessLists(ctx context.Context, req ListAccountIpAccessListsRequest, opts ...call.Option) (*ListAccountIpAccessListsResponse, error)
- func (c *Client) ListEndpoints(ctx context.Context, req ListEndpointsRequest, opts ...call.Option) (*ListEndpointsResponse, error)
- func (c *Client) ListEndpointsIter(ctx context.Context, req ListEndpointsRequest, opts ...call.Option) iter.Seq2[*Endpoint, error]
- func (c *Client) ListIpAccessLists(ctx context.Context, req ListIpAccessLists, opts ...call.Option) (*ListIpAccessListsResponse, error)
- func (c *Client) ListNccPrivateEndpointRules(ctx context.Context, req ListNccPrivateEndpointRulesRequest, ...) (*ListNccPrivateEndpointRulesResponse, error)
- func (c *Client) ListNccPrivateEndpointRulesIter(ctx context.Context, req ListNccPrivateEndpointRulesRequest, ...) iter.Seq2[*NccPrivateEndpointRule, error]
- func (c *Client) ListNetworkConnectivityConfigsPublic(ctx context.Context, req ListNetworkConnectivityConfigsRequest, ...) (*ListNetworkConnectivityConfigsResponse, error)
- func (c *Client) ListNetworkConnectivityConfigsPublicIter(ctx context.Context, req ListNetworkConnectivityConfigsRequest, ...) iter.Seq2[*NetworkConnectivityConfig, error]
- func (c *Client) ListNetworkPoliciesRpc(ctx context.Context, req ListNetworkPoliciesRequest, opts ...call.Option) (*ListNetworkPoliciesResponse, error)
- func (c *Client) ListNetworkPoliciesRpcIter(ctx context.Context, req ListNetworkPoliciesRequest, opts ...call.Option) iter.Seq2[*AccountNetworkPolicy, error]
- func (c *Client) ListNetworkPublic(ctx context.Context, req ListNetworkRequest, opts ...call.Option) (*ListNetworkResponse, error)
- func (c *Client) ListPrivateAccessSettingsPublic(ctx context.Context, req ListPrivateAccessSettingsRequest, opts ...call.Option) (*ListPrivateAccessSettingsResponse, error)
- func (c *Client) ListVpcEndpointPublic(ctx context.Context, req ListVpcEndpointRequest, opts ...call.Option) (*ListVpcEndpointResponse, error)
- func (c *Client) ReplaceAccountIpAccessList(ctx context.Context, req ReplaceAccountIpAccessListRequest, ...) (*ReplaceAccountIpAccessListResponse, error)
- func (c *Client) ReplaceIpAccessList(ctx context.Context, req ReplaceIpAccessListRequest, opts ...call.Option) (*ReplaceIpAccessListResponse, error)
- func (c *Client) UpdateAccountIpAccessList(ctx context.Context, req UpdateAccountIpAccessListRequest, opts ...call.Option) (*UpdateAccountIpAccessListResponse, error)
- func (c *Client) UpdateIpAccessList(ctx context.Context, req UpdateIpAccessListRequest, opts ...call.Option) (*UpdateIpAccessListResponse, error)
- func (c *Client) UpdateNccPrivateEndpointRule(ctx context.Context, req UpdateNccPrivateEndpointRuleRequest, ...) (*NccPrivateEndpointRule, error)
- func (c *Client) UpdateNetworkPolicyRpc(ctx context.Context, req UpdateNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
- func (c *Client) UpdatePrivateAccessSettingsPublic(ctx context.Context, req UpdatePrivateAccessSettingsRequest, ...) (*PrivateAccessSettings, error)
- func (c *Client) UpdateWorkspaceNetworkOptionRpc(ctx context.Context, req UpdateWorkspaceNetworkOptionRequest, ...) (*WorkspaceNetworkOption, error)
- type CreateAccountIpAccessListRequest
- type CreateAccountIpAccessListResponse
- type CreateEndpointRequest
- type CreateIpAccessListRequest
- type CreateIpAccessListResponse
- type CreateNccPrivateEndpointRuleRequest
- type CreateNetworkConnectivityConfigRequest
- type CreateNetworkConnectivityConfiguration
- type CreateNetworkPolicyRequest
- type CreateNetworkRequest
- type CreatePrivateAccessSettingsRequest
- type CreatePrivateEndpointRule
- type CreatePrivateEndpointRule_Endpoint_GcpEndpoint
- type CreateVpcEndpointRequest
- type CreateVpcEndpointRequest_VpcEndpointInfo_GcpVpcEndpointInfo
- type CustomerFacingNetworkConnectivityConfigEgressConfig
- type CustomerFacingNetworkConnectivityConfigEgressConfig_CustomerFacingTargetRule
- type DeleteAccountIpAccessListRequest
- type DeleteAccountIpAccessListResponse
- type DeleteEndpointRequest
- type DeleteIpAccessListRequest
- type DeleteIpAccessListResponse
- type DeleteNccPrivateEndpointRuleRequest
- type DeleteNetworkConnectivityConfigRequest
- type DeleteNetworkPolicyRequest
- type DeleteNetworkRequest
- type DeletePrivateAccessSettingsRequest
- type DeleteVpcEndpointRequest
- type EgressNetworkPolicy
- type EgressNetworkPolicy_NetworkAccessPolicy
- type EgressNetworkPolicy_NetworkAccessPolicy_DatabricksDestination
- type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination
- type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType
- type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement
- type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter
- type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode
- type EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode
- type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination
- type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType
- type EgressResourceType
- type Endpoint
- type EndpointState
- type EndpointUseCase
- type EndpointUseCase_EndpointUseCase
- type Endpoint_EndpointInfo_AwsVpcEndpointInfo
- type Endpoint_EndpointInfo_AzurePrivateEndpointInfo
- type Endpoint_EndpointInfo_GcpPscEndpointInfo
- type GcpEndpoint
- type GcpEndpoint_TargetServices_AllVpcScServices
- type GcpEndpoint_TargetServices_GoogleApiEndpoints
- type GcpEndpoint_TargetServices_ServiceAttachment
- type GcpNetworkInfo
- type GcpPscEndpointInfo
- type GcpVpcEndpointInfo
- type GetAccountIpAccessListRequest
- type GetAccountIpAccessListResponse
- type GetEndpointRequest
- type GetIpAccessListRequest
- type GetIpAccessListResponse
- type GetNccPrivateEndpointRuleRequest
- type GetNetworkConnectivityConfigRequest
- type GetNetworkPolicyRequest
- type GetNetworkRequest
- type GetPrivateAccessSettingsRequest
- type GetVpcEndpointRequest
- type GetWorkspaceNetworkOptionRequest
- type GoogleApiEndpoints
- type IngressNetworkPolicy
- type IngressNetworkPolicy_AccountApiDestination
- type IngressNetworkPolicy_AccountDatabricksOneDestination
- type IngressNetworkPolicy_AccountUiDestination
- type IngressNetworkPolicy_ApiScopeQualifier
- type IngressNetworkPolicy_AppsRuntimeDestination
- type IngressNetworkPolicy_Authentication
- type IngressNetworkPolicy_AuthenticationIdentity
- type IngressNetworkPolicy_AuthenticationIdentity_PrincipalType
- type IngressNetworkPolicy_Authentication_IdentityType
- type IngressNetworkPolicy_CrossWorkspaceAccess
- type IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode
- type IngressNetworkPolicy_CrossWorkspaceIngressRule
- type IngressNetworkPolicy_CrossWorkspaceRequestOrigin
- type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_AllSourceWorkspaces
- type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_SelectedWorkspaces
- type IngressNetworkPolicy_Endpoints
- type IngressNetworkPolicy_IpRanges
- type IngressNetworkPolicy_LakebaseRuntimeDestination
- type IngressNetworkPolicy_PrivateAccess
- type IngressNetworkPolicy_PrivateAccess_RestrictionMode
- type IngressNetworkPolicy_PrivateIngressRule
- type IngressNetworkPolicy_PrivateRequestOrigin
- type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllPrivateAccess
- type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllRegisteredEndpoints
- type IngressNetworkPolicy_PrivateRequestOrigin_Source_AzureWorkspacePrivateLink
- type IngressNetworkPolicy_PrivateRequestOrigin_Source_Endpoints
- type IngressNetworkPolicy_PublicAccess
- type IngressNetworkPolicy_PublicAccess_RestrictionMode
- type IngressNetworkPolicy_PublicIngressRule
- type IngressNetworkPolicy_PublicRequestOrigin
- type IngressNetworkPolicy_PublicRequestOrigin_Source_AllIpRanges
- type IngressNetworkPolicy_PublicRequestOrigin_Source_ExcludedIpRanges
- type IngressNetworkPolicy_PublicRequestOrigin_Source_IncludedIpRanges
- type IngressNetworkPolicy_RequestDestination
- type IngressNetworkPolicy_WorkspaceApiDestination
- type IngressNetworkPolicy_WorkspaceIdList
- type IngressNetworkPolicy_WorkspaceUiDestination
- type IpAccessList
- type IpAccessListType
- type ListAccountIpAccessListsRequest
- type ListAccountIpAccessListsResponse
- type ListEndpointsRequest
- type ListEndpointsResponse
- type ListIpAccessLists
- type ListIpAccessListsResponse
- type ListNccPrivateEndpointRulesRequest
- type ListNccPrivateEndpointRulesResponse
- type ListNetworkConnectivityConfigsRequest
- type ListNetworkConnectivityConfigsResponse
- type ListNetworkPoliciesRequest
- type ListNetworkPoliciesResponse
- type ListNetworkRequest
- type ListNetworkResponse
- type ListPrivateAccessSettingsRequest
- type ListPrivateAccessSettingsResponse
- type ListVpcEndpointRequest
- type ListVpcEndpointResponse
- type NccPrivateEndpointRule
- type NccPrivateEndpointRule_Endpoint_GcpEndpoint
- type NccPrivateEndpointRule_PrivateLinkConnectionState
- type Network
- type NetworkConnectivityConfig
- type NetworkConnectivityConfigAwsPrivateEndpointRule
- type NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState
- type NetworkConnectivityConfigAzurePrivateEndpointRule
- type NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState
- type NetworkConnectivityConfigEgressConfig
- type NetworkConnectivityConfigEgressConfig_DefaultRule
- type NetworkConnectivityConfigEgressConfig_DefaultRule_AwsStableIpRule
- type NetworkConnectivityConfigEgressConfig_DefaultRule_AzureServiceEndpointRule
- type NetworkHealth
- type NetworkVpcEndpoints
- type NetworkWarning
- type Network_NetworkInfo_GcpNetworkInfo
- type PrivateAccessLevel
- type PrivateAccessSettings
- type ReplaceAccountIpAccessListRequest
- type ReplaceAccountIpAccessListResponse
- type ReplaceIpAccessListRequest
- type ReplaceIpAccessListResponse
- type UpdateAccountIpAccessListRequest
- type UpdateAccountIpAccessListResponse
- type UpdateIpAccessListRequest
- type UpdateIpAccessListResponse
- type UpdateNccPrivateEndpointRuleRequest
- type UpdateNetworkPolicyRequest
- type UpdatePrivateAccessSettingsRequest
- type UpdatePrivateEndpointRule
- type UpdatePrivateEndpointRule_Endpoint_GcpEndpoint
- type UpdateWorkspaceNetworkOptionRequest
- type VpcEndpoint
- type VpcEndpointUseCase
- type VpcEndpoint_VpcEndpointInfo_GcpVpcEndpointInfo
- type VpcStatus
- type WorkspaceNetworkOption
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AccountIpAccessList ¶
type AccountIpAccessList struct {
// Universally unique identifier (UUID) of the IP access list.
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
IpAddresses []string
// Total number of IP or CIDR values.
AddressCount *int
ListType AccountIpAccessListType_IpAccessListType
// Creation timestamp in milliseconds.
CreatedAt *int64
// The ID of the user that created this list.
CreatedBy *int64
// Update timestamp in milliseconds.
UpdatedAt *int64
// The ID of the user that last updated this list.
UpdatedBy *int64
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Definition of an IP Access list.
type AccountIpAccessListType ¶
type AccountIpAccessListType struct {
}
type AccountIpAccessListType_IpAccessListType ¶
type AccountIpAccessListType_IpAccessListType string
Type of IP access list. Valid values are as follows and are case-sensitive:
* `ALLOW`: An allow list. Include this IP or range. * `BLOCK`: A block list. Exclude this IP or range. IP addresses in the block list are excluded even if they are included in an allow list.
const ( AccountIpAccessListType_IpAccessListType_Unspecified AccountIpAccessListType_IpAccessListType = "" // Allows the associated CIDRs. AccountIpAccessListType_IpAccessListType_Allow AccountIpAccessListType_IpAccessListType = "ALLOW" // Blocks the associated CIDRs. AccountIpAccessListType_IpAccessListType_Block AccountIpAccessListType_IpAccessListType = "BLOCK" )
type AccountNetworkPolicy ¶
type AccountNetworkPolicy struct {
// The unique identifier for the network policy.
NetworkPolicyId *string
// The associated account ID for this Network Policy object.
AccountId *string
// The network policies applying for egress traffic.
Egress *EgressNetworkPolicy
// The network policies applying for ingress traffic.
Ingress *IngressNetworkPolicy
// The ingress policy for dry run mode. Dry run will always run even if the
// request is allowed by the ingress policy. When this field is set, the policy
// will be evaluated and emit logs only without blocking requests.
IngressDryRun *IngressNetworkPolicy
}
type AwsVpcEndpointInfo ¶
type AwsVpcEndpointInfo struct {
// The ID of the underlying VPC endpoint in AWS. Provided by the customer when
// registering an existing AWS VPC endpoint.
AwsVpcEndpointId *string
// The ID of the Databricks VPC endpoint service that this endpoint connects to.
AwsEndpointServiceId *string
// The AWS account ID in which this VPC endpoint lives.
AwsAccountId *string
}
type AzurePrivateEndpointInfo ¶
type AzurePrivateEndpointInfo struct {
// The name of the Private Endpoint in the Azure subscription.
PrivateEndpointName *string
// The GUID of the Private Endpoint resource in the Azure subscription. This is
// assigned by Azure when the user sets up the Private Endpoint.
PrivateEndpointResourceGuid *string
// The full resource ID of the Private Endpoint.
PrivateEndpointResourceId *string
// The resource ID of the Databricks Private Link Service that this Private
// Endpoint connects to.
PrivateLinkServiceId *string
}
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
func (*Client) CreateAccountIpAccessList ¶
func (c *Client) CreateAccountIpAccessList(ctx context.Context, req CreateAccountIpAccessListRequest, opts ...call.Option) (*CreateAccountIpAccessListResponse, error)
Creates an IP access list for the account.
A list can be an allow list or a block list. See the top of this file for a description of how the server treats allow lists and block lists at runtime.
When creating or updating an IP access list:
* For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the new list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`.
It can take a few minutes for the changes to take effect. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreateEndpoint ¶
func (c *Client) CreateEndpoint(ctx context.Context, req CreateEndpointRequest, opts ...call.Option) (*Endpoint, error)
Creates a new network connectivity endpoint that enables private connectivity between your network resources and <Databricks> services.
After creation, the endpoint is initially in the PENDING state. The <Databricks> endpoint service automatically reviews and approves the endpoint within a few minutes. Use the GET method to retrieve the latest endpoint state.
An endpoint can be used only after it reaches the APPROVED state.
func (*Client) CreateIpAccessList ¶
func (c *Client) CreateIpAccessList(ctx context.Context, req CreateIpAccessListRequest, opts ...call.Option) (*CreateIpAccessListResponse, error)
Creates an IP access list for this workspace.
A list can be an allow list or a block list. See the top of this file for a description of how the server treats allow lists and block lists at runtime.
When creating or updating an IP access list:
* For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the new list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`.
It can take a few minutes for the changes to take effect. **Note**: Your new IP access list has no effect until you enable the feature. See workspaceconf/setStatus
func (*Client) CreateNccPrivateEndpointRule ¶
func (c *Client) CreateNccPrivateEndpointRule(ctx context.Context, req CreateNccPrivateEndpointRuleRequest, opts ...call.Option) (*NccPrivateEndpointRule, error)
Create a private endpoint rule for the specified network connectivity config object. Once the object is created, <Databricks> asynchronously provisions a new Azure private endpoint to your specified Azure resource.
**IMPORTANT**: You must use Azure portal or other Azure tools to approve the private endpoint to complete the connection. To get the information of the private endpoint created, make a `GET` request on the new private endpoint rule. See [serverless private link].
[serverless private link]: https://learn.microsoft.com/azure/databricks/security/network/serverless-network-security/serverless-private-link Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreateNetworkConnectivityConfigPublic ¶
func (c *Client) CreateNetworkConnectivityConfigPublic(ctx context.Context, req CreateNetworkConnectivityConfigRequest, opts ...call.Option) (*NetworkConnectivityConfig, error)
Creates a network connectivity configuration (NCC), which provides stable Azure service subnets when accessing your Azure Storage accounts. You can also use a network connectivity configuration to create <Databricks> managed private endpoints so that <Databricks> serverless compute resources privately access your resources.
**IMPORTANT**: After you create the network connectivity configuration, you must assign one or more workspaces to the new network connectivity configuration. You can share one network connectivity configuration with multiple workspaces from the same Azure region within the same <Databricks> account. See [configure serverless secure connectivity].
[configure serverless secure connectivity]: https://learn.microsoft.com/azure/databricks/security/network/serverless-network-security Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreateNetworkPolicyRpc ¶
func (c *Client) CreateNetworkPolicyRpc(ctx context.Context, req CreateNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
Creates a new network policy to manage which network destinations can be accessed from the <Databricks> environment. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreateNetworkPublic ¶
func (c *Client) CreateNetworkPublic(ctx context.Context, req CreateNetworkRequest, opts ...call.Option) (*Network, error)
Creates a <Databricks> network configuration that represents an VPC and its resources. The VPC will be used for new <Databricks> clusters. This requires a pre-existing VPC and subnets. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreatePrivateAccessSettingsPublic ¶
func (c *Client) CreatePrivateAccessSettingsPublic(ctx context.Context, req CreatePrivateAccessSettingsRequest, opts ...call.Option) (*PrivateAccessSettings, error)
Creates a private access settings configuration, which represents network access restrictions for workspace resources. Private access settings configure whether workspaces can be accessed from the public internet or only from private endpoints. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) CreateVpcEndpointPublic ¶
func (c *Client) CreateVpcEndpointPublic(ctx context.Context, req CreateVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
Creates a VPC endpoint configuration, which represents a [VPC endpoint] object in AWS used to communicate privately with <Databricks> over [AWS PrivateLink].
After you create the VPC endpoint configuration, the <Databricks> [endpoint service] automatically accepts the VPC endpoint.
Before configuring PrivateLink, read the [<Databricks> article about PrivateLink].
[<Databricks> article about PrivateLink]: https://docs.databricks.com/administration-guide/cloud-configurations/aws/privatelink.html [AWS PrivateLink]: https://aws.amazon.com/privatelink [VPC endpoint]: https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints.html [endpoint service]: https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-share-your-services.html Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteAccountIpAccessList ¶
func (c *Client) DeleteAccountIpAccessList(ctx context.Context, req DeleteAccountIpAccessListRequest, opts ...call.Option) (*DeleteAccountIpAccessListResponse, error)
Deletes an IP access list, specified by its list ID. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteEndpoint ¶
func (c *Client) DeleteEndpoint(ctx context.Context, req DeleteEndpointRequest, opts ...call.Option) error
Deletes a network endpoint. This will remove the endpoint configuration from <Databricks>. Depending on the endpoint type and use case, you may also need to delete corresponding network resources in your cloud provider account.
func (*Client) DeleteIpAccessList ¶
func (c *Client) DeleteIpAccessList(ctx context.Context, req DeleteIpAccessListRequest, opts ...call.Option) (*DeleteIpAccessListResponse, error)
Deletes an IP access list, specified by its list ID.
func (*Client) DeleteNccPrivateEndpointRule ¶
func (c *Client) DeleteNccPrivateEndpointRule(ctx context.Context, req DeleteNccPrivateEndpointRuleRequest, opts ...call.Option) (*NccPrivateEndpointRule, error)
Initiates deleting a private endpoint rule. If the connection state is PENDING or EXPIRED, the private endpoint is immediately deleted. Otherwise, the private endpoint is deactivated and will be deleted after one day of deactivation. When a private endpoint is deactivated, the `deactivated` field is set to `true` and the private endpoint is not available to your serverless compute resources. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteNetworkConnectivityConfigPublic ¶
func (c *Client) DeleteNetworkConnectivityConfigPublic(ctx context.Context, req DeleteNetworkConnectivityConfigRequest, opts ...call.Option) error
Deletes a network connectivity configuration. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteNetworkPolicyRpc ¶
func (c *Client) DeleteNetworkPolicyRpc(ctx context.Context, req DeleteNetworkPolicyRequest, opts ...call.Option) error
Deletes a network policy. Cannot be called on 'default-policy'. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteNetworkPublic ¶
func (c *Client) DeleteNetworkPublic(ctx context.Context, req DeleteNetworkRequest, opts ...call.Option) (*Network, error)
Deletes a <Databricks> network configuration, which represents a cloud VPC and its resources. You cannot delete a network that is associated with a workspace.
This operation is available only if your account is on the E2 version of the platform. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeletePrivateAccessSettingsPublic ¶
func (c *Client) DeletePrivateAccessSettingsPublic(ctx context.Context, req DeletePrivateAccessSettingsRequest, opts ...call.Option) (*PrivateAccessSettings, error)
Deletes a <Databricks> private access settings configuration, both specified by ID. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) DeleteVpcEndpointPublic ¶
func (c *Client) DeleteVpcEndpointPublic(ctx context.Context, req DeleteVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
Deletes a Databricks VPC endpoint configuration. You cannot delete a VPC endpoint configuration that is associated with any workspace. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetAccountIpAccessList ¶
func (c *Client) GetAccountIpAccessList(ctx context.Context, req GetAccountIpAccessListRequest, opts ...call.Option) (*GetAccountIpAccessListResponse, error)
Gets an IP access list, specified by its list ID. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetEndpoint ¶
func (c *Client) GetEndpoint(ctx context.Context, req GetEndpointRequest, opts ...call.Option) (*Endpoint, error)
Gets details of a specific network endpoint.
func (*Client) GetIpAccessList ¶
func (c *Client) GetIpAccessList(ctx context.Context, req GetIpAccessListRequest, opts ...call.Option) (*GetIpAccessListResponse, error)
Gets an IP access list, specified by its list ID.
func (*Client) GetNccPrivateEndpointRule ¶
func (c *Client) GetNccPrivateEndpointRule(ctx context.Context, req GetNccPrivateEndpointRuleRequest, opts ...call.Option) (*NccPrivateEndpointRule, error)
Gets the private endpoint rule. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetNetworkConnectivityConfigPublic ¶
func (c *Client) GetNetworkConnectivityConfigPublic(ctx context.Context, req GetNetworkConnectivityConfigRequest, opts ...call.Option) (*NetworkConnectivityConfig, error)
Gets a network connectivity configuration. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetNetworkPolicyRpc ¶
func (c *Client) GetNetworkPolicyRpc(ctx context.Context, req GetNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
Gets a network policy. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetNetworkPublic ¶
func (c *Client) GetNetworkPublic(ctx context.Context, req GetNetworkRequest, opts ...call.Option) (*Network, error)
Gets a <Databricks> network configuration, which represents a cloud VPC and its resources. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetPrivateAccessSettingsPublic ¶
func (c *Client) GetPrivateAccessSettingsPublic(ctx context.Context, req GetPrivateAccessSettingsRequest, opts ...call.Option) (*PrivateAccessSettings, error)
Gets a <Databricks> private access settings configuration, both specified by ID. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetVpcEndpointPublic ¶
func (c *Client) GetVpcEndpointPublic(ctx context.Context, req GetVpcEndpointRequest, opts ...call.Option) (*VpcEndpoint, error)
Gets a VPC endpoint configuration, which represents a [VPC endpoint] object in AWS used to communicate privately with <Databricks> over [AWS PrivateLink].
[AWS PrivateLink]: https://aws.amazon.com/privatelink [VPC endpoint]: https://docs.aws.amazon.com/vpc/latest/privatelink/concepts.html Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) GetWorkspaceNetworkOptionRpc ¶
func (c *Client) GetWorkspaceNetworkOptionRpc(ctx context.Context, req GetWorkspaceNetworkOptionRequest, opts ...call.Option) (*WorkspaceNetworkOption, error)
Gets the network option for a workspace. Every workspace has exactly one network policy binding, with 'default-policy' used if no explicit assignment exists. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListAccountIpAccessLists ¶
func (c *Client) ListAccountIpAccessLists(ctx context.Context, req ListAccountIpAccessListsRequest, opts ...call.Option) (*ListAccountIpAccessListsResponse, error)
Gets all IP access lists for the specified account. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListEndpoints ¶
func (c *Client) ListEndpoints(ctx context.Context, req ListEndpointsRequest, opts ...call.Option) (*ListEndpointsResponse, error)
Lists all network connectivity endpoints for the account.
func (*Client) ListEndpointsIter ¶
func (c *Client) ListEndpointsIter(ctx context.Context, req ListEndpointsRequest, opts ...call.Option) iter.Seq2[*Endpoint, error]
ListEndpointsIter returns an iterator that iterates over the results of ListEndpoints.
For example:
for item, err := range c.ListEndpointsIter(ctx, ListEndpointsRequest{}) {
if err != nil {
return err
}
fmt.Println(item)
}
Options opts are passed to each ListEndpoints call made by the iterator under the hood.
Callers who need custom pagination logic should use ListEndpoints directly.
func (*Client) ListIpAccessLists ¶
func (c *Client) ListIpAccessLists(ctx context.Context, req ListIpAccessLists, opts ...call.Option) (*ListIpAccessListsResponse, error)
Gets all IP access lists for the specified workspace.
func (*Client) ListNccPrivateEndpointRules ¶
func (c *Client) ListNccPrivateEndpointRules(ctx context.Context, req ListNccPrivateEndpointRulesRequest, opts ...call.Option) (*ListNccPrivateEndpointRulesResponse, error)
Gets an array of private endpoint rules. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListNccPrivateEndpointRulesIter ¶
func (c *Client) ListNccPrivateEndpointRulesIter(ctx context.Context, req ListNccPrivateEndpointRulesRequest, opts ...call.Option) iter.Seq2[*NccPrivateEndpointRule, error]
ListNccPrivateEndpointRulesIter returns an iterator that iterates over the results of ListNccPrivateEndpointRules.
For example:
for item, err := range c.ListNccPrivateEndpointRulesIter(ctx, ListNccPrivateEndpointRulesRequest{}) {
if err != nil {
return err
}
fmt.Println(item)
}
Options opts are passed to each ListNccPrivateEndpointRules call made by the iterator under the hood.
Callers who need custom pagination logic should use ListNccPrivateEndpointRules directly.
func (*Client) ListNetworkConnectivityConfigsPublic ¶
func (c *Client) ListNetworkConnectivityConfigsPublic(ctx context.Context, req ListNetworkConnectivityConfigsRequest, opts ...call.Option) (*ListNetworkConnectivityConfigsResponse, error)
Gets an array of network connectivity configurations. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListNetworkConnectivityConfigsPublicIter ¶
func (c *Client) ListNetworkConnectivityConfigsPublicIter(ctx context.Context, req ListNetworkConnectivityConfigsRequest, opts ...call.Option) iter.Seq2[*NetworkConnectivityConfig, error]
ListNetworkConnectivityConfigsPublicIter returns an iterator that iterates over the results of ListNetworkConnectivityConfigsPublic.
For example:
for item, err := range c.ListNetworkConnectivityConfigsPublicIter(ctx, ListNetworkConnectivityConfigsRequest{}) {
if err != nil {
return err
}
fmt.Println(item)
}
Options opts are passed to each ListNetworkConnectivityConfigsPublic call made by the iterator under the hood.
Callers who need custom pagination logic should use ListNetworkConnectivityConfigsPublic directly.
func (*Client) ListNetworkPoliciesRpc ¶
func (c *Client) ListNetworkPoliciesRpc(ctx context.Context, req ListNetworkPoliciesRequest, opts ...call.Option) (*ListNetworkPoliciesResponse, error)
Gets an array of network policies. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListNetworkPoliciesRpcIter ¶
func (c *Client) ListNetworkPoliciesRpcIter(ctx context.Context, req ListNetworkPoliciesRequest, opts ...call.Option) iter.Seq2[*AccountNetworkPolicy, error]
ListNetworkPoliciesRpcIter returns an iterator that iterates over the results of ListNetworkPoliciesRpc.
For example:
for item, err := range c.ListNetworkPoliciesRpcIter(ctx, ListNetworkPoliciesRequest{}) {
if err != nil {
return err
}
fmt.Println(item)
}
Options opts are passed to each ListNetworkPoliciesRpc call made by the iterator under the hood.
Callers who need custom pagination logic should use ListNetworkPoliciesRpc directly.
func (*Client) ListNetworkPublic ¶
func (c *Client) ListNetworkPublic(ctx context.Context, req ListNetworkRequest, opts ...call.Option) (*ListNetworkResponse, error)
Lists <Databricks> network configurations for an account. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListPrivateAccessSettingsPublic ¶
func (c *Client) ListPrivateAccessSettingsPublic(ctx context.Context, req ListPrivateAccessSettingsRequest, opts ...call.Option) (*ListPrivateAccessSettingsResponse, error)
Lists <Databricks> private access settings for an account. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ListVpcEndpointPublic ¶
func (c *Client) ListVpcEndpointPublic(ctx context.Context, req ListVpcEndpointRequest, opts ...call.Option) (*ListVpcEndpointResponse, error)
Lists Databricks VPC endpoint configurations for an account. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ReplaceAccountIpAccessList ¶
func (c *Client) ReplaceAccountIpAccessList(ctx context.Context, req ReplaceAccountIpAccessListRequest, opts ...call.Option) (*ReplaceAccountIpAccessListResponse, error)
Replaces an IP access list, specified by its ID.
A list can include allow lists and block lists. See the top of this file for a description of how the server treats allow lists and block lists at run time. When replacing an IP access list: * For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the resulting list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`. It can take a few minutes for the changes to take effect. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) ReplaceIpAccessList ¶
func (c *Client) ReplaceIpAccessList(ctx context.Context, req ReplaceIpAccessListRequest, opts ...call.Option) (*ReplaceIpAccessListResponse, error)
Replaces an IP access list, specified by its ID.
A list can include allow lists and block lists. See the top of this file for a description of how the server treats allow lists and block lists at run time. When replacing an IP access list: * For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the resulting list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`. It can take a few minutes for the changes to take effect. Note that your resulting IP access list has no effect until you enable the feature. See workspaceconf/setStatus.
func (*Client) UpdateAccountIpAccessList ¶
func (c *Client) UpdateAccountIpAccessList(ctx context.Context, req UpdateAccountIpAccessListRequest, opts ...call.Option) (*UpdateAccountIpAccessListResponse, error)
Updates an existing IP access list, specified by its ID.
A list can include allow lists and block lists. See the top of this file for a description of how the server treats allow lists and block lists at run time.
When updating an IP access list:
* For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the updated list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`.
It can take a few minutes for the changes to take effect. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) UpdateIpAccessList ¶
func (c *Client) UpdateIpAccessList(ctx context.Context, req UpdateIpAccessListRequest, opts ...call.Option) (*UpdateIpAccessListResponse, error)
Updates an existing IP access list, specified by its ID.
A list can include allow lists and block lists. See the top of this file for a description of how the server treats allow lists and block lists at run time.
When updating an IP access list:
* For all allow lists and block lists combined, the API supports a maximum of 1000 IP/CIDR values, where one CIDR counts as a single value. Attempts to exceed that number return error 400 with `error_code` value `QUOTA_EXCEEDED`. * If the updated list would block the calling user's current IP, error 400 is returned with `error_code` value `INVALID_STATE`.
It can take a few minutes for the changes to take effect. Note that your resulting IP access list has no effect until you enable the feature. See workspaceconf/setStatus.
func (*Client) UpdateNccPrivateEndpointRule ¶
func (c *Client) UpdateNccPrivateEndpointRule(ctx context.Context, req UpdateNccPrivateEndpointRuleRequest, opts ...call.Option) (*NccPrivateEndpointRule, error)
Updates a private endpoint rule. Currently only a private endpoint rule to customer-managed resources is allowed to be updated. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) UpdateNetworkPolicyRpc ¶
func (c *Client) UpdateNetworkPolicyRpc(ctx context.Context, req UpdateNetworkPolicyRequest, opts ...call.Option) (*AccountNetworkPolicy, error)
Updates a network policy. This allows you to modify the configuration of a network policy. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) UpdatePrivateAccessSettingsPublic ¶
func (c *Client) UpdatePrivateAccessSettingsPublic(ctx context.Context, req UpdatePrivateAccessSettingsRequest, opts ...call.Option) (*PrivateAccessSettings, error)
Updates an existing private access settings object, which specifies how your workspace is accessed over AWS PrivateLink. To use AWS PrivateLink, a workspace must have a private access settings object referenced by ID in the workspace's private_access_settings_id property. This operation completely overwrites your existing private access settings object attached to your workspaces. All workspaces attached to the private access settings are affected by any change. If public_access_enabled, private_access_level, or allowed_vpc_endpoint_ids are updated, effects of these changes might take several minutes to propagate to the workspace API. You can share one private access settings object with multiple workspaces in a single account. However, private access settings are specific to AWS regions, so only workspaces in the same AWS region can use a given private access settings object. Before configuring PrivateLink, read the <Databricks> article about PrivateLink. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
func (*Client) UpdateWorkspaceNetworkOptionRpc ¶
func (c *Client) UpdateWorkspaceNetworkOptionRpc(ctx context.Context, req UpdateWorkspaceNetworkOptionRequest, opts ...call.Option) (*WorkspaceNetworkOption, error)
Updates the network option for a workspace. This operation associates the workspace with the specified network policy. To revert to the default policy, specify 'default-policy' as the network_policy_id. Account-level method. Uses the Client's accountID, overridable per call via req.AccountId.
type CreateAccountIpAccessListRequest ¶
type CreateAccountIpAccessListRequest struct {
AccountId *string
Label *string
ListType AccountIpAccessListType_IpAccessListType
IpAddresses []string
}
Details required to configure a block list or allow list..
type CreateAccountIpAccessListResponse ¶
type CreateAccountIpAccessListResponse struct {
IpAccessList *AccountIpAccessList
}
An IP access list was successfully created..
type CreateEndpointRequest ¶
type CreateIpAccessListRequest ¶
type CreateIpAccessListRequest struct {
// Label for the IP access list. This **cannot** be empty.
Label *string
ListType IpAccessListType
IpAddresses []string
}
Details required to configure a block list or allow list..
type CreateIpAccessListResponse ¶
type CreateIpAccessListResponse struct {
IpAccessList *IpAccessList
}
An IP access list was successfully created..
type CreateNccPrivateEndpointRuleRequest ¶
type CreateNccPrivateEndpointRuleRequest struct {
// Your Network Connectivity Configuration ID.
NetworkConnectivityConfigId *string
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
PrivateEndpointRule *CreatePrivateEndpointRule
}
Properties of the new private endpoint rule..
type CreateNetworkConnectivityConfigRequest ¶
type CreateNetworkConnectivityConfigRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
NetworkConnectivityConfig *CreateNetworkConnectivityConfiguration
}
Properties of the new network connectivity configuration..
type CreateNetworkConnectivityConfiguration ¶
type CreateNetworkConnectivityConfiguration struct {
// <Databricks> network connectivity configuration ID.
NetworkConnectivityConfigId *string
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// The name of the network connectivity configuration. The name can contain
// alphanumeric characters, hyphens, and underscores. The length must be between
// 3 and 30 characters. The name must match the regular expression
// ^[0-9a-zA-Z-_]{3,30}$
Name *string
// The region for the network connectivity configuration. Only workspaces in the
// same region can be attached to the network connectivity configuration.
Region *string
// The network connectivity rules that apply to network traffic from your
// serverless compute resources.
EgressConfig *CustomerFacingNetworkConnectivityConfigEgressConfig
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Time in epoch milliseconds when this object was created.
CreationTime *int64
}
Properties of the new network connectivity configuration..
type CreateNetworkPolicyRequest ¶
type CreateNetworkPolicyRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Network policy configuration details.
NetworkPolicy *AccountNetworkPolicy
}
type CreateNetworkRequest ¶
type CreateNetworkRequest struct {
AccountId *string
// The human-readable name of the network configuration.
NetworkName *string
// The ID of the VPC associated with this network configuration. VPC IDs can be
// used in multiple networks.
VpcId *string
// IDs of at least two subnets associated with this network. Subnet IDs
// **cannot** be used in multiple network configurations.
SubnetIds []string
// IDs of one to five security groups associated with this network. Security
// group IDs **cannot** be used in multiple network configurations.
SecurityGroupIds []string
VpcEndpoints *NetworkVpcEndpoints
GcpNetworkInfo *GcpNetworkInfo
}
type CreatePrivateAccessSettingsRequest ¶
type CreatePrivateAccessSettingsRequest struct {
AccountId *string
// The human-readable name of the private access settings object.
PrivateAccessSettingsName *string
// The AWS region for workspaces attached to this private access settings
// object.
Region *string
// Determines if the workspace can be accessed over public internet. For fully
// private workspaces, you can optionally specify false, but only if you
// implement both the front-end and the back-end PrivateLink connections.
// Otherwise, specify true, which means that public access is enabled.
PublicAccessEnabled *bool
// The private access level controls which VPC endpoints can connect to the UI
// or API of any workspace that attaches this private access settings object.
// `ACCOUNT` level access (the default) allows only VPC endpoints that are
// registered in your <Databricks> account connect to your workspace. `ENDPOINT`
// level access allows only specified VPC endpoints connect to your workspace.
// For details, see allowed_vpc_endpoint_ids.
PrivateAccessLevel PrivateAccessLevel
// An array of Databricks VPC endpoint IDs. This is the <Databricks> ID returned
// when registering the VPC endpoint configuration in your <Databricks> account.
// This is not the ID of the VPC endpoint in AWS. Only used when
// private_access_level is set to ENDPOINT. This is an allow list of VPC
// endpoints registered in your <Databricks> account that can connect to your
// workspace over AWS PrivateLink. Note: If hybrid access to your workspace is
// enabled by setting public_access_enabled to true, this control only works for
// PrivateLink connections. To control how your workspace is accessed via public
// internet, see IP access lists.
AllowedVpcEndpointIds []string
}
type CreatePrivateEndpointRule ¶
type CreatePrivateEndpointRule struct {
// The ID of a private endpoint rule.
RuleId *string
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string
// The current status of this private endpoint. The private endpoint rules are
// effective only if the connection state is ESTABLISHED. Remember that you must
// approve new endpoints on your resources in the Cloud console before they take
// effect. The possible values are: - PENDING: The endpoint has been created and
// pending approval. - ESTABLISHED: The endpoint has been approved and is ready
// to use in your serverless compute resources. - REJECTED: Connection was
// rejected by the private link resource owner. - DISCONNECTED: Connection was
// removed by the private link resource owner, the private endpoint becomes
// informative and should be deleted for clean-up. - EXPIRED: If the endpoint
// was created but not approved in 14 days, it will be EXPIRED. - CREATING: The
// endpoint creation is in progress. Once successfully created, the state will
// transition to PENDING. - CREATE_FAILED: The endpoint creation failed. You can
// check the error_message field for more details.
ConnectionState NccPrivateEndpointRule_PrivateLinkConnectionState
// Only used by private endpoints to customer-managed private endpoint services.
//
// Domain names of target private link service. When updating this field, the
// full list of target domain_names must be specified.
DomainNames []string
// Time in epoch milliseconds when this object was created.
CreationTime *int64
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Whether this private endpoint is deactivated.
Deactivated *bool
// Time in epoch milliseconds when this object was deactivated.
DeactivatedAt *int64
ErrorMessage *string
// The Azure resource ID of the target resource.
ResourceId *string
// Not used by customer-managed private endpoint services.
//
// The sub-resource type (group ID) of the target resource. Note that to connect
// to workspace root storage (root DBFS), you need two endpoints, one for blob
// and one for dfs.
GroupId *string
// The name of the Azure private endpoint resource.
EndpointName *string
// <Databricks> account ID. You can find your account ID from the Accounts
// Console.
AccountId *string
// The full target AWS endpoint service name that connects to the destination
// resources of the private endpoint.
EndpointService *string
// Only used by private endpoints towards AWS S3 service.
//
// The globally unique S3 bucket names that will be accessed via the VPC
// endpoint. The bucket names must be in the same region as the NCC/endpoint
// service. When updating this field, we perform full update on this field.
// Please ensure a full list of desired resource_names is provided.
ResourceNames []string
// The AWS VPC endpoint ID. You can use this ID to identify the VPC endpoint
// created by <Databricks>.
VpcEndpointId *string
// Update this field to activate/deactivate this private endpoint to allow
// egress access from serverless compute resources. Only honored for first-party
// services on each cloud (e.g. AWS S3).
Enabled *bool
Endpoint isCreatePrivateEndpointRule_Endpoint
}
Properties of the new private endpoint rule. Note that you must approve the endpoint in Azure portal after initialization..
type CreatePrivateEndpointRule_Endpoint_GcpEndpoint ¶
type CreatePrivateEndpointRule_Endpoint_GcpEndpoint struct {
GcpEndpoint GcpEndpoint
}
CreatePrivateEndpointRule_Endpoint_GcpEndpoint selects GcpEndpoint for CreatePrivateEndpointRule.Endpoint.
type CreateVpcEndpointRequest ¶
type CreateVpcEndpointRequest struct {
AccountId *string
// The human-readable name of the storage configuration.
VpcEndpointName *string
// The region in which this VPC endpoint object exists.
Region *string
// The ID of the VPC endpoint object in AWS.
AwsVpcEndpointId *string
VpcEndpointInfo isCreateVpcEndpointRequest_VpcEndpointInfo
}
type CreateVpcEndpointRequest_VpcEndpointInfo_GcpVpcEndpointInfo ¶
type CreateVpcEndpointRequest_VpcEndpointInfo_GcpVpcEndpointInfo struct {
GcpVpcEndpointInfo GcpVpcEndpointInfo
}
CreateVpcEndpointRequest_VpcEndpointInfo_GcpVpcEndpointInfo selects GcpVpcEndpointInfo for CreateVpcEndpointRequest.VpcEndpointInfo. The cloud info of this vpc endpoint.
type CustomerFacingNetworkConnectivityConfigEgressConfig ¶
type CustomerFacingNetworkConnectivityConfigEgressConfig struct {
// The network connectivity rules that are applied by default without resource
// specific configurations. You can find the stable network information of your
// serverless compute resources here.
DefaultRules *NetworkConnectivityConfigEgressConfig_DefaultRule
// The network connectivity rules that configured for each destinations. These
// rules override default rules.
TargetRules *CustomerFacingNetworkConnectivityConfigEgressConfig_CustomerFacingTargetRule
}
type CustomerFacingNetworkConnectivityConfigEgressConfig_CustomerFacingTargetRule ¶
type CustomerFacingNetworkConnectivityConfigEgressConfig_CustomerFacingTargetRule struct {
AzurePrivateEndpointRules []NetworkConnectivityConfigAzurePrivateEndpointRule
// AWS private endpoint rule controls the AWS private endpoint based egress
// rules.
AwsPrivateEndpointRules []NetworkConnectivityConfigAwsPrivateEndpointRule
}
Target rule controls the egress rules that are dedicated to specific resources..
type DeleteAccountIpAccessListResponse ¶
type DeleteAccountIpAccessListResponse struct {
}
The IP access list was successfully deleted..
type DeleteEndpointRequest ¶
type DeleteEndpointRequest struct {
Name *string
}
type DeleteIpAccessListRequest ¶
type DeleteIpAccessListRequest struct {
// The ID for the corresponding IP access list
ListId *string
}
type DeleteIpAccessListResponse ¶
type DeleteIpAccessListResponse struct {
}
The IP access list was successfully deleted..
type DeleteNccPrivateEndpointRuleRequest ¶
type DeleteNccPrivateEndpointRuleRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Your Network Connectvity Configuration ID.
NetworkConnectivityConfigId *string
// Your private endpoint rule ID.
PrivateEndpointRuleId *string
}
Initiates deleting a private endpoint rule. If the connection state is PENDING or EXPIRED, the private endpoint is immediately deleted. Otherwise, the private endpoint is deactivated and will be deleted after one day of deactivation. When a private endpoint is deactivated, the deactivated field is set to true and the private endpoint is not available to your serverless compute resources..
type DeleteNetworkRequest ¶
type EgressNetworkPolicy ¶
type EgressNetworkPolicy struct {
// The access policy enforced for egress traffic to the internet.
NetworkAccess *EgressNetworkPolicy_NetworkAccessPolicy
}
The network policies applying for egress traffic..
type EgressNetworkPolicy_NetworkAccessPolicy ¶
type EgressNetworkPolicy_NetworkAccessPolicy struct {
// The restriction mode that controls how serverless workloads can access the
// internet.
RestrictionMode EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode
// List of internet destinations that serverless workloads are allowed to access
// when in RESTRICTED_ACCESS mode.
AllowedInternetDestinations []EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination
// List of storage destinations that serverless workloads are allowed to access
// when in RESTRICTED_ACCESS mode.
AllowedStorageDestinations []EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination
// Optional. When policy_enforcement is not provided, we default to
// ENFORCE_MODE_ALL_SERVICES
PolicyEnforcement *EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement
// List of internet destinations that serverless workloads are blocked from
// accessing. These destinations are enforced when restriction mode is
// RESTRICTED_ACCESS or DRY_RUN. Currently supports DNS_NAME type only; IP_RANGE
// support is planned.
BlockedInternetDestinations []EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination
// List of <Databricks> workspace destinations that serverless workloads are
// allowed to access when in RESTRICTED_ACCESS mode.
AllowedDatabricksDestinations []EgressNetworkPolicy_NetworkAccessPolicy_DatabricksDestination
}
type EgressNetworkPolicy_NetworkAccessPolicy_DatabricksDestination ¶
type EgressNetworkPolicy_NetworkAccessPolicy_DatabricksDestination struct {
// The workspace IDs to allow egress traffic to.
WorkspaceIds []int64
}
type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination ¶
type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination struct {
// The internet destination to which access will be allowed. Format dependent on
// the destination type.
Destination *string
// The type of internet destination. Currently only DNS_NAME is supported.
InternetDestinationType EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType
}
Users can specify accessible internet destinations when outbound access is restricted. We only support DNS_NAME (FQDN format) destinations for the time being. Going forward we may extend support to host names and IP addresses..
type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType ¶
type EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType string
const ( EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType_Unspecified EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType = "" // This is defined as `FQDN` in settings-policy/api/proto/messages.proto. // Translation is done in // accounts-lake-net-manager/src/util/NetworkPolicySettingUtil.scala. EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType_DnsName EgressNetworkPolicy_NetworkAccessPolicy_InternetDestination_InternetDestinationType = "DNS_NAME" )
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement ¶
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement struct {
// The mode of policy enforcement. ENFORCED blocks traffic that violates policy,
// while DRY_RUN only logs violations without blocking. When not specified,
// defaults to ENFORCED.
EnforcementMode EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode
// When empty, it means dry run for all products. When non-empty, it means dry
// run for specific products and for the other products, they will run in
// enforced mode.
DryRunModeProductFilter []EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter
}
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter ¶
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter string
The values should match the list of workloads used in networkconfig.proto
const ( EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter_Unspecified EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter = "" // SQL Warehouse product EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter_Dbsql EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter = "DBSQL" // Machine Learning serving product EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter_MlServing EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_DryRunModeProductFilter = "ML_SERVING" )
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode ¶
type EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode string
const ( EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode_Unspecified EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode = "" // Blocks traffic that violates network policy. This is the default mode. EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode_Enforced EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode = "ENFORCED" // Logs violations without blocking traffic. Useful for testing policies before // enforcement. EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode_DryRun EgressNetworkPolicy_NetworkAccessPolicy_PolicyEnforcement_EnforcementMode = "DRY_RUN" )
type EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode ¶
type EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode string
At which level can <Databricks> and <Databricks> managed compute access Internet. FULL_ACCESS: <Databricks> can access Internet. No blocking rules will apply. RESTRICTED_ACCESS: <Databricks> can only access explicitly allowed internet and storage destinations, as well as UC connections and external locations.
const ( EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode_Unspecified EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode = "" EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode_FullAccess EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode = "FULL_ACCESS" EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode_RestrictedAccess EgressNetworkPolicy_NetworkAccessPolicy_RestrictionMode = "RESTRICTED_ACCESS" )
type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination ¶
type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination struct {
BucketName *string
Region *string
// The type of storage destination.
StorageDestinationType EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType
// The Azure storage account name.
AzureStorageAccount *string
// The Azure storage service type (blob, dfs, etc.).
AzureStorageService *string
}
Users can specify accessible storage destinations..
type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType ¶
type EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType string
const ( EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType_Unspecified EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType = "" // AWS_S3 can be used both for direct AWS S3 access and for cross-cloud access // from Azure and GCP When used in an Azure/GCP context, this indicates // cross-cloud access from Azure/GCP to the specified S3 bucket EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType_AwsS3 EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType = "AWS_S3" EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType_AzureStorage EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType = "AZURE_STORAGE" EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType_GoogleCloudStorage EgressNetworkPolicy_NetworkAccessPolicy_StorageDestination_StorageDestinationType = "GOOGLE_CLOUD_STORAGE" )
type EgressResourceType ¶
type EgressResourceType string
The target resources that are supported by Network Connectivity Config. Note: some egress types can support general types that are not defined in EgressResourceType. E.g.: Azure private endpoint supports private link enabled Azure services.
const ( EgressResourceType_Unspecified EgressResourceType = "" EgressResourceType_AzureBlobStorage EgressResourceType = "AZURE_BLOB_STORAGE" )
type Endpoint ¶
type Endpoint struct {
// The resource name of the endpoint, which uniquely identifies the endpoint.
Name *string
// The unique identifier for this endpoint under the account. This field is a
// UUID generated by <Databricks>.
EndpointId *string
// The Databricks Account in which the endpoint object exists.
AccountId *string
// The human-readable display name of this endpoint. The input should conform to
// RFC-1034, which restricts to letters, numbers, and hyphens, with the first
// character a letter, the last a letter or a number, and a 63 character
// maximum.
DisplayName *string
// The use case that determines the type of network connectivity this endpoint
// provides. This field is automatically determined based on the endpoint
// configuration and cloud-specific settings.
UseCase EndpointUseCase_EndpointUseCase
// The cloud provider region where this endpoint is located.
Region *string
// The state of the endpoint. The endpoint can only be used if the state is
// `APPROVED`.
State EndpointState
// The cloud info of this endpoint. (-- Azure is GA; AWS and GCP added for
// PLAT-165656 (Private Preview). --)
EndpointInfo isEndpoint_EndpointInfo
// The timestamp when the endpoint was created. The timestamp is in RFC 3339
// format in UTC timezone.
CreateTime *types.Time
}
Endpoint represents a cloud networking resource in a user's cloud account and binds it to the <Databricks> account..
type EndpointState ¶
type EndpointState string
const ( EndpointState_Unspecified EndpointState = "" // The endpoint is pending approval. EndpointState_Pending EndpointState = "PENDING" // The endpoint has been approved and is ready for use. EndpointState_Approved EndpointState = "APPROVED" // The endpoint encountered some issues during setup. EndpointState_Failed EndpointState = "FAILED" // The endpoint was once established but later disconnected. This endpoint // doesn't provide connectivity. EndpointState_Disconnected EndpointState = "DISCONNECTED" )
type EndpointUseCase ¶
type EndpointUseCase struct {
}
type EndpointUseCase_EndpointUseCase ¶
type EndpointUseCase_EndpointUseCase string
const ( EndpointUseCase_EndpointUseCase_Unspecified EndpointUseCase_EndpointUseCase = "" // service-direct frontend private link connectivity. EndpointUseCase_EndpointUseCase_ServiceDirect EndpointUseCase_EndpointUseCase = "SERVICE_DIRECT" )
type Endpoint_EndpointInfo_AwsVpcEndpointInfo ¶
type Endpoint_EndpointInfo_AwsVpcEndpointInfo struct {
AwsVpcEndpointInfo AwsVpcEndpointInfo
}
Endpoint_EndpointInfo_AwsVpcEndpointInfo selects AwsVpcEndpointInfo for Endpoint.EndpointInfo. Info for an AWS VPC endpoint.
type Endpoint_EndpointInfo_AzurePrivateEndpointInfo ¶
type Endpoint_EndpointInfo_AzurePrivateEndpointInfo struct {
AzurePrivateEndpointInfo AzurePrivateEndpointInfo
}
Endpoint_EndpointInfo_AzurePrivateEndpointInfo selects AzurePrivateEndpointInfo for Endpoint.EndpointInfo. Info for an Azure private endpoint.
type Endpoint_EndpointInfo_GcpPscEndpointInfo ¶
type Endpoint_EndpointInfo_GcpPscEndpointInfo struct {
GcpPscEndpointInfo GcpPscEndpointInfo
}
Endpoint_EndpointInfo_GcpPscEndpointInfo selects GcpPscEndpointInfo for Endpoint.EndpointInfo. Info for a GCP Private Service Connect endpoint.
type GcpEndpoint ¶
type GcpEndpoint struct {
// Output only. The URI of the created PSC endpoint.
PscEndpointUri *string `fieldmask:"psc_endpoint_uri"`
// Selects which target services this private endpoint reaches.
TargetServices isGcpEndpoint_TargetServices
// contains filtered or unexported fields
}
type GcpEndpoint_TargetServices_AllVpcScServices ¶
type GcpEndpoint_TargetServices_AllVpcScServices struct {
AllVpcScServices bool `fieldmask:"all_vpc_sc_services"`
}
GcpEndpoint_TargetServices_AllVpcScServices selects AllVpcScServices for GcpEndpoint.TargetServices. All Google APIs that support VPC Service Controls (a subset of all Google APIs).
type GcpEndpoint_TargetServices_GoogleApiEndpoints ¶
type GcpEndpoint_TargetServices_GoogleApiEndpoints struct {
GoogleApiEndpoints GoogleApiEndpoints `fieldmask:"google_api_endpoints"`
}
GcpEndpoint_TargetServices_GoogleApiEndpoints selects GoogleApiEndpoints for GcpEndpoint.TargetServices. Selected Google API hostnames, e.g. "storage.googleapis.com", "bigquery.googleapis.com".
type GcpEndpoint_TargetServices_ServiceAttachment ¶
type GcpEndpoint_TargetServices_ServiceAttachment struct {
ServiceAttachment string `fieldmask:"service_attachment"`
}
GcpEndpoint_TargetServices_ServiceAttachment selects ServiceAttachment for GcpEndpoint.TargetServices. The full url of the target service attachment. Example: projects/my-gcp-project/regions/us-east4/serviceAttachments/my-service-attachment
type GcpNetworkInfo ¶
type GcpNetworkInfo struct {
// The GCP project ID for network resources. This project is where the VPC and
// subnet resides.
NetworkProjectId *string
// The customer-provided VPC ID.
VpcId *string
// The customer-provided Subnet ID that will be available to Clusters in
// Workspaces using this Network.
SubnetId *string
SubnetRegion *string
// Name of the secondary range within the subnet that will be used by GKE as Pod
// IP range. This is BYO VPC specific. DB VPC uses
// network.getGcpManagedNetworkConfig.getGkeClusterPodIpRange
PodIpRangeName *string
// Name of the secondary range within the subnet that will be used by GKE as
// Service IP range.
ServiceIpRangeName *string
}
type GcpPscEndpointInfo ¶
type GcpPscEndpointInfo struct {
// The ID of the underlying Private Service Connect connection in the GCP
// consumer project, assigned by GCP when the PSC connection is created.
PscConnectionId *string
// The GCP consumer project ID in which this PSC endpoint is created. Provided
// by the customer when registering an existing PSC endpoint.
ProjectId *string
// The name of this PSC connection in the GCP consumer project. Provided by the
// customer when registering an existing PSC endpoint.
PscEndpoint *string
// The GCP region of the PSC connection endpoint. Provided by the customer when
// registering an existing PSC endpoint. GCP supports only same-region PSC, so
// this must match the workspace region.
EndpointRegion *string
// The ID of the <Databricks> service attachment this PSC endpoint connects to.
ServiceAttachmentId *string
}
type GcpVpcEndpointInfo ¶
type GetAccountIpAccessListResponse ¶
type GetAccountIpAccessListResponse struct {
IpAccessList *AccountIpAccessList
}
type GetEndpointRequest ¶
type GetEndpointRequest struct {
Name *string
}
type GetIpAccessListRequest ¶
type GetIpAccessListRequest struct {
// The ID for the corresponding IP access list
ListId *string
}
type GetIpAccessListResponse ¶
type GetIpAccessListResponse struct {
IpAccessList *IpAccessList
}
An IP access list was successfully returned..
type GetNccPrivateEndpointRuleRequest ¶
type GetNccPrivateEndpointRuleRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Your Network Connectvity Configuration ID.
NetworkConnectivityConfigId *string
// Your private endpoint rule ID.
PrivateEndpointRuleId *string
}
type GetNetworkConnectivityConfigRequest ¶
type GetNetworkConnectivityConfigRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Your Network Connectivity Configuration ID.
NetworkConnectivityConfigId *string
}
***************************** Public facing RPC requests and responses *****************************//.
type GetNetworkPolicyRequest ¶
type GetNetworkRequest ¶
type GetVpcEndpointRequest ¶
type GoogleApiEndpoints ¶
type GoogleApiEndpoints struct {
// Google API hostnames, e.g. "storage.googleapis.com",
// "bigquery.googleapis.com". Use "googleapis.com" to cover all Google APIs.
Endpoints []string `fieldmask:"endpoints"`
}
Wrapper for a list of Google API hostnames. Wrapped in a message because proto3 oneof does not support repeated fields directly..
type IngressNetworkPolicy ¶
type IngressNetworkPolicy struct {
// The network policy restrictions for public access to the workspace.
// Configures how public internet traffic is allowed or denied access.
PublicAccess *IngressNetworkPolicy_PublicAccess
// The network policy restrictions for private access. Configures how requests
// arriving over private connectivity are governed.
PrivateAccess *IngressNetworkPolicy_PrivateAccess
CrossWorkspaceAccess *IngressNetworkPolicy_CrossWorkspaceAccess
}
The network policies applying for ingress traffic..
type IngressNetworkPolicy_AccountApiDestination ¶
type IngressNetworkPolicy_AccountApiDestination struct {
// The API scopes to match. Use "all-apis" to match any account-level API.
Scopes []string
// Qualifies the breadth of API access for the listed scopes. See
// ApiScopeQualifier.
ScopeQualifier IngressNetworkPolicy_ApiScopeQualifier
}
Matches account-level Databricks API endpoints for an ingress network policy rule..
type IngressNetworkPolicy_AccountDatabricksOneDestination ¶
type IngressNetworkPolicy_AccountDatabricksOneDestination struct {
// Must be set to true.
AllDestinations *bool
}
type IngressNetworkPolicy_AccountUiDestination ¶
type IngressNetworkPolicy_AccountUiDestination struct {
// Must be set to true.
AllDestinations *bool
}
The account console UI destination..
type IngressNetworkPolicy_ApiScopeQualifier ¶
type IngressNetworkPolicy_ApiScopeQualifier string
Qualifies the breadth of API access permitted by an ingress network policy rule. API_SCOPE_QUALIFIER_READ narrows matching to read-only variants of the listed scopes; API_SCOPE_QUALIFIER_ALL matches any scope. When unset, scopes match exactly as listed.
const ( IngressNetworkPolicy_ApiScopeQualifier_Unspecified IngressNetworkPolicy_ApiScopeQualifier = "" // Narrows matching to read-only variants of the listed scopes (e.g. GET/HEAD // requests). IngressNetworkPolicy_ApiScopeQualifier_ApiScopeQualifierRead IngressNetworkPolicy_ApiScopeQualifier = "API_SCOPE_QUALIFIER_READ" // Matches any scope regardless of access level. IngressNetworkPolicy_ApiScopeQualifier_ApiScopeQualifierAll IngressNetworkPolicy_ApiScopeQualifier = "API_SCOPE_QUALIFIER_ALL" )
type IngressNetworkPolicy_AppsRuntimeDestination ¶
type IngressNetworkPolicy_AppsRuntimeDestination struct {
// Must be set to true.
AllDestinations *bool
}
type IngressNetworkPolicy_Authentication ¶
type IngressNetworkPolicy_Authentication struct {
IdentityType IngressNetworkPolicy_Authentication_IdentityType
// Valid only when IdentityType is IDENTITY_TYPE_SELECTED_IDENTITIES.
Identities []IngressNetworkPolicy_AuthenticationIdentity
}
type IngressNetworkPolicy_AuthenticationIdentity ¶
type IngressNetworkPolicy_AuthenticationIdentity struct {
PrincipalType IngressNetworkPolicy_AuthenticationIdentity_PrincipalType
PrincipalId *int64
}
type IngressNetworkPolicy_AuthenticationIdentity_PrincipalType ¶
type IngressNetworkPolicy_AuthenticationIdentity_PrincipalType string
const ( IngressNetworkPolicy_AuthenticationIdentity_PrincipalType_Unspecified IngressNetworkPolicy_AuthenticationIdentity_PrincipalType = "" IngressNetworkPolicy_AuthenticationIdentity_PrincipalType_PrincipalTypeUser IngressNetworkPolicy_AuthenticationIdentity_PrincipalType = "PRINCIPAL_TYPE_USER" IngressNetworkPolicy_AuthenticationIdentity_PrincipalType_PrincipalTypeServicePrincipal IngressNetworkPolicy_AuthenticationIdentity_PrincipalType = "PRINCIPAL_TYPE_SERVICE_PRINCIPAL" )
type IngressNetworkPolicy_Authentication_IdentityType ¶
type IngressNetworkPolicy_Authentication_IdentityType string
const ( IngressNetworkPolicy_Authentication_IdentityType_Unspecified IngressNetworkPolicy_Authentication_IdentityType = "" IngressNetworkPolicy_Authentication_IdentityType_IdentityTypeAllUsers IngressNetworkPolicy_Authentication_IdentityType = "IDENTITY_TYPE_ALL_USERS" IngressNetworkPolicy_Authentication_IdentityType_IdentityTypeAllServicePrincipals IngressNetworkPolicy_Authentication_IdentityType = "IDENTITY_TYPE_ALL_SERVICE_PRINCIPALS" IngressNetworkPolicy_Authentication_IdentityType_IdentityTypeSelectedIdentities IngressNetworkPolicy_Authentication_IdentityType = "IDENTITY_TYPE_SELECTED_IDENTITIES" )
type IngressNetworkPolicy_CrossWorkspaceAccess ¶
type IngressNetworkPolicy_CrossWorkspaceAccess struct {
// The restriction mode for cross-workspace access.
RestrictionMode IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode
// Deny rules are evaluated first. A request matching any deny rule is denied,
// regardless of allow rules. Only applies when restriction_mode is
// RESTRICTED_ACCESS.
DenyRules []IngressNetworkPolicy_CrossWorkspaceIngressRule
// Allow rules are evaluated after deny rules. A request matching any allow rule
// is allowed; a request matching no rule is denied by default. Only applies
// when restriction_mode is RESTRICTED_ACCESS.
AllowRules []IngressNetworkPolicy_CrossWorkspaceIngressRule
}
type IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode ¶
type IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode string
The restriction mode for cross-workspace access. In FULL_ACCESS mode, requests from any source workspace (in any account) are allowed, and deny rules and allow rules cannot be set. In RESTRICTED_ACCESS mode, access is restricted based on deny rules and allow rules; requests that do not match any allow rule are denied. In LEGACY_MODE, cross-workspace ingress is not governed by this policy.
const ( IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode_Unspecified IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode = "" // Allows requests from any source workspace, regardless of account. Deny rules // and allow rules cannot be set in this mode. IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode_FullAccess IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode = "FULL_ACCESS" // Restricts access based on deny rules and allow rules. Requests that do not // match any allow rule are denied. IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode_RestrictedAccess IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode = "RESTRICTED_ACCESS" // Cross-workspace ingress is not governed by this policy. Traffic from other // workspaces is subject only to the workspace's pre-existing network controls, // not to the allow and deny rules configured here. IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode_LegacyMode IngressNetworkPolicy_CrossWorkspaceAccess_RestrictionMode = "LEGACY_MODE" )
type IngressNetworkPolicy_CrossWorkspaceIngressRule ¶
type IngressNetworkPolicy_CrossWorkspaceIngressRule struct {
// The origin the request must match — the source workspace the request comes
// from, either specific source workspaces or any source workspace in any
// account. See CrossWorkspaceRequestOrigin.
Origin *IngressNetworkPolicy_CrossWorkspaceRequestOrigin
// The destination the request must match — the resource being accessed, for
// example the workspace UI or workspace APIs. See RequestDestination.
Destination *IngressNetworkPolicy_RequestDestination
// The authenticated identity the request must match. When unset, the rule
// matches all users and service principals.
Authentication *IngressNetworkPolicy_Authentication
// The label for this ingress rule.
Label *string
}
An ingress rule is enforced when a request satisfies all specified attributes — including request origin, destination, and authentication..
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin ¶
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin struct {
Source isIngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source
}
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_AllSourceWorkspaces ¶
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_AllSourceWorkspaces struct {
AllSourceWorkspaces bool
}
IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_AllSourceWorkspaces selects AllSourceWorkspaces for IngressNetworkPolicy_CrossWorkspaceRequestOrigin.Source. Matches all source workspaces.
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_SelectedWorkspaces ¶
type IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_SelectedWorkspaces struct {
SelectedWorkspaces IngressNetworkPolicy_WorkspaceIdList
}
IngressNetworkPolicy_CrossWorkspaceRequestOrigin_Source_SelectedWorkspaces selects SelectedWorkspaces for IngressNetworkPolicy_CrossWorkspaceRequestOrigin.Source. Specific source workspace IDs to match.
type IngressNetworkPolicy_Endpoints ¶
type IngressNetworkPolicy_Endpoints struct {
// The IDs of the registered endpoints. Must contain at least one endpoint ID.
EndpointIds []string
}
A set of registered endpoints, identified by their endpoint IDs..
type IngressNetworkPolicy_IpRanges ¶
type IngressNetworkPolicy_IpRanges struct {
// We only support IPv4 and IPv4 CIDR notation for now.
IpRanges []string
}
type IngressNetworkPolicy_LakebaseRuntimeDestination ¶
type IngressNetworkPolicy_LakebaseRuntimeDestination struct {
// Must be set to true.
AllDestinations *bool
}
type IngressNetworkPolicy_PrivateAccess ¶
type IngressNetworkPolicy_PrivateAccess struct {
// The restriction mode for private access.
RestrictionMode IngressNetworkPolicy_PrivateAccess_RestrictionMode
// Deny rules are evaluated first. A request matching any deny rule is denied,
// regardless of allow rules. Only applies when restriction_mode is
// RESTRICTED_ACCESS.
DenyRules []IngressNetworkPolicy_PrivateIngressRule
// Allow rules are evaluated after deny rules. A request matching any allow rule
// is allowed; a request matching no rule is denied by default. Only applies
// when restriction_mode is RESTRICTED_ACCESS.
AllowRules []IngressNetworkPolicy_PrivateIngressRule
}
Configures how requests arriving over private connectivity, such as registered endpoints, are allowed or denied access..
type IngressNetworkPolicy_PrivateAccess_RestrictionMode ¶
type IngressNetworkPolicy_PrivateAccess_RestrictionMode string
The restriction mode for private access. In ALLOW_ALL_REGISTERED_ENDPOINTS mode, requests arriving through any endpoint registered to the account are allowed, and deny rules and allow rules cannot be set. In RESTRICTED_ACCESS mode, access is restricted based on deny rules and allow rules; requests that do not match any allow rule are denied.
const ( IngressNetworkPolicy_PrivateAccess_RestrictionMode_Unspecified IngressNetworkPolicy_PrivateAccess_RestrictionMode = "" // Allows requests arriving through any endpoint registered to the account. Deny // rules and allow rules cannot be set in this mode. IngressNetworkPolicy_PrivateAccess_RestrictionMode_AllowAllRegisteredEndpoints IngressNetworkPolicy_PrivateAccess_RestrictionMode = "ALLOW_ALL_REGISTERED_ENDPOINTS" // Restricts access based on deny rules and allow rules. Requests that do not // match any allow rule are denied. IngressNetworkPolicy_PrivateAccess_RestrictionMode_RestrictedAccess IngressNetworkPolicy_PrivateAccess_RestrictionMode = "RESTRICTED_ACCESS" )
type IngressNetworkPolicy_PrivateIngressRule ¶
type IngressNetworkPolicy_PrivateIngressRule struct {
// The origin the request must match — the private connectivity the request
// arrives through, for example a specific set of registered endpoints or any
// endpoint registered to the account. See PrivateRequestOrigin.
Origin *IngressNetworkPolicy_PrivateRequestOrigin
// The destination the request must match — the resource being accessed, for
// example the workspace UI, workspace APIs, or account-level APIs. See
// RequestDestination.
Destination *IngressNetworkPolicy_RequestDestination
// The authenticated identity the request must match. When unset, the rule
// matches all users and service principals. On the account-level network
// policy, scoping to specific identities is not currently supported, so this
// field must be unset (the rule matches all users and service principals).
Authentication *IngressNetworkPolicy_Authentication
// The label for this ingress rule.
Label *string
}
An ingress rule is enforced when a request satisfies all specified attributes — including request origin, destination, and authentication..
type IngressNetworkPolicy_PrivateRequestOrigin ¶
type IngressNetworkPolicy_PrivateRequestOrigin struct {
Source isIngressNetworkPolicy_PrivateRequestOrigin_Source
}
The origin of a private access request, identified by the endpoint through which the request arrives..
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllPrivateAccess ¶
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllPrivateAccess struct {
AllPrivateAccess bool
}
IngressNetworkPolicy_PrivateRequestOrigin_Source_AllPrivateAccess selects AllPrivateAccess for IngressNetworkPolicy_PrivateRequestOrigin.Source. Matches requests arriving over any private connectivity, including registered endpoints and the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllRegisteredEndpoints ¶
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AllRegisteredEndpoints struct {
AllRegisteredEndpoints bool
}
IngressNetworkPolicy_PrivateRequestOrigin_Source_AllRegisteredEndpoints selects AllRegisteredEndpoints for IngressNetworkPolicy_PrivateRequestOrigin.Source. Matches requests arriving through any endpoint registered to the account. Must be set to true when specified.
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AzureWorkspacePrivateLink ¶
type IngressNetworkPolicy_PrivateRequestOrigin_Source_AzureWorkspacePrivateLink struct {
AzureWorkspacePrivateLink bool
}
IngressNetworkPolicy_PrivateRequestOrigin_Source_AzureWorkspacePrivateLink selects AzureWorkspacePrivateLink for IngressNetworkPolicy_PrivateRequestOrigin.Source. Matches requests arriving through the workspace's Azure Private Link (ui-api) endpoints. Can only be used in deny rules of workspace-level network policies. Must be set to true when specified.
type IngressNetworkPolicy_PrivateRequestOrigin_Source_Endpoints ¶
type IngressNetworkPolicy_PrivateRequestOrigin_Source_Endpoints struct {
Endpoints IngressNetworkPolicy_Endpoints
}
IngressNetworkPolicy_PrivateRequestOrigin_Source_Endpoints selects Endpoints for IngressNetworkPolicy_PrivateRequestOrigin.Source. Matches requests arriving through any of the specified registered endpoints.
type IngressNetworkPolicy_PublicAccess ¶
type IngressNetworkPolicy_PublicAccess struct {
RestrictionMode IngressNetworkPolicy_PublicAccess_RestrictionMode
DenyRules []IngressNetworkPolicy_PublicIngressRule
AllowRules []IngressNetworkPolicy_PublicIngressRule
}
type IngressNetworkPolicy_PublicAccess_RestrictionMode ¶
type IngressNetworkPolicy_PublicAccess_RestrictionMode string
const ( IngressNetworkPolicy_PublicAccess_RestrictionMode_Unspecified IngressNetworkPolicy_PublicAccess_RestrictionMode = "" IngressNetworkPolicy_PublicAccess_RestrictionMode_FullAccess IngressNetworkPolicy_PublicAccess_RestrictionMode = "FULL_ACCESS" IngressNetworkPolicy_PublicAccess_RestrictionMode_RestrictedAccess IngressNetworkPolicy_PublicAccess_RestrictionMode = "RESTRICTED_ACCESS" )
type IngressNetworkPolicy_PublicIngressRule ¶
type IngressNetworkPolicy_PublicIngressRule struct {
Origin *IngressNetworkPolicy_PublicRequestOrigin
Destination *IngressNetworkPolicy_RequestDestination
Authentication *IngressNetworkPolicy_Authentication
// The label for this ingress rule.
Label *string
}
An ingress rule is enforced when a request satisfies all specified attributes — including request origin, destination, and authentication..
type IngressNetworkPolicy_PublicRequestOrigin ¶
type IngressNetworkPolicy_PublicRequestOrigin struct {
Source isIngressNetworkPolicy_PublicRequestOrigin_Source
}
type IngressNetworkPolicy_PublicRequestOrigin_Source_AllIpRanges ¶
type IngressNetworkPolicy_PublicRequestOrigin_Source_AllIpRanges struct {
AllIpRanges bool
}
IngressNetworkPolicy_PublicRequestOrigin_Source_AllIpRanges selects AllIpRanges for IngressNetworkPolicy_PublicRequestOrigin.Source. Matches all IPv4 and IPv6 ranges (both public and private).
type IngressNetworkPolicy_PublicRequestOrigin_Source_ExcludedIpRanges ¶
type IngressNetworkPolicy_PublicRequestOrigin_Source_ExcludedIpRanges struct {
ExcludedIpRanges IngressNetworkPolicy_IpRanges
}
IngressNetworkPolicy_PublicRequestOrigin_Source_ExcludedIpRanges selects ExcludedIpRanges for IngressNetworkPolicy_PublicRequestOrigin.Source. Excluded means: all public IP ranges except this one.
type IngressNetworkPolicy_PublicRequestOrigin_Source_IncludedIpRanges ¶
type IngressNetworkPolicy_PublicRequestOrigin_Source_IncludedIpRanges struct {
IncludedIpRanges IngressNetworkPolicy_IpRanges
}
IngressNetworkPolicy_PublicRequestOrigin_Source_IncludedIpRanges selects IncludedIpRanges for IngressNetworkPolicy_PublicRequestOrigin.Source. Will not allow IP ranges with private IPs.
type IngressNetworkPolicy_RequestDestination ¶
type IngressNetworkPolicy_RequestDestination struct {
// When true, match all destinations, no other destination fields can be set.
// When not set or false, at least one specific destination must be provided.
AllDestinations *bool
WorkspaceUi *IngressNetworkPolicy_WorkspaceUiDestination
WorkspaceApi *IngressNetworkPolicy_WorkspaceApiDestination
AppsRuntime *IngressNetworkPolicy_AppsRuntimeDestination
LakebaseRuntime *IngressNetworkPolicy_LakebaseRuntimeDestination
// Matches requests to the account console UI. Can only be used in the
// account-level network policy.
AccountUi *IngressNetworkPolicy_AccountUiDestination
// Matches requests to account-level APIs. Can only be used in the account-level
// network policy.
AccountApi *IngressNetworkPolicy_AccountApiDestination
// Account DatabricksOne destination is not supported.
AccountDatabricksOne *IngressNetworkPolicy_AccountDatabricksOneDestination
}
type IngressNetworkPolicy_WorkspaceApiDestination ¶
type IngressNetworkPolicy_WorkspaceApiDestination struct {
Scopes []string
// Qualifies the breadth of API access for the listed scopes. See
// ApiScopeQualifier.
ScopeQualifier IngressNetworkPolicy_ApiScopeQualifier
}
Matches workspace-level Databricks API endpoints for an ingress network policy rule..
type IngressNetworkPolicy_WorkspaceIdList ¶
type IngressNetworkPolicy_WorkspaceIdList struct {
WorkspaceIds []int64
}
type IngressNetworkPolicy_WorkspaceUiDestination ¶
type IngressNetworkPolicy_WorkspaceUiDestination struct {
// Must be set to true.
AllDestinations *bool
}
type IpAccessList ¶
type IpAccessList struct {
// Universally unique identifier (UUID) of the IP access list.
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
IpAddresses []string
// Total number of IP or CIDR values.
AddressCount *int
ListType IpAccessListType
// Creation timestamp in milliseconds.
CreatedAt *int64
// User ID of the user who created this list.
CreatedBy *int64
// Update timestamp in milliseconds.
UpdatedAt *int64
// User ID of the user who updated this list.
UpdatedBy *int64
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Definition of an IP Access list.
type IpAccessListType ¶
type IpAccessListType string
Type of IP access list. Valid values are as follows and are case-sensitive:
* `ALLOW`: An allow list. Include this IP or range. * `BLOCK`: A block list. Exclude this IP or range. IP addresses in the block list are excluded even if they are included in an allow list.
const ( IpAccessListType_Unspecified IpAccessListType = "" IpAccessListType_Allow IpAccessListType = "ALLOW" // Blocks the associated CIDRs. IpAccessListType_Block IpAccessListType = "BLOCK" )
type ListAccountIpAccessListsRequest ¶
type ListAccountIpAccessListsRequest struct {
AccountId *string
}
type ListAccountIpAccessListsResponse ¶
type ListAccountIpAccessListsResponse struct {
IpAccessLists []AccountIpAccessList
}
IP access lists were successfully returned..
type ListEndpointsRequest ¶
type ListEndpointsResponse ¶
type ListIpAccessLists ¶
type ListIpAccessLists struct {
}
type ListIpAccessListsResponse ¶
type ListIpAccessListsResponse struct {
IpAccessLists []IpAccessList
}
IP access lists were successfully returned..
type ListNccPrivateEndpointRulesRequest ¶
type ListNccPrivateEndpointRulesRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Your Network Connectvity Configuration ID.
NetworkConnectivityConfigId *string
// Pagination token to go to next page based on previous query.
PageToken *string
}
Gets an array of private endpoint rules..
type ListNccPrivateEndpointRulesResponse ¶
type ListNccPrivateEndpointRulesResponse struct {
Items []NccPrivateEndpointRule
// A token that can be used to get the next page of results. If null, there are
// no more results to show.
NextPageToken *string
}
The private endpoint rule list was successfully retrieved..
type ListNetworkConnectivityConfigsResponse ¶
type ListNetworkConnectivityConfigsResponse struct {
Items []NetworkConnectivityConfig
// A token that can be used to get the next page of results. If null, there are
// no more results to show.
NextPageToken *string
}
The network connectivity configuration list was successfully retrieved..
type ListNetworkPoliciesResponse ¶
type ListNetworkPoliciesResponse struct {
// List of network policies.
Items []AccountNetworkPolicy
// A token that can be used to get the next page of results. If null, there are
// no more results to show.
NextPageToken *string
}
type ListNetworkRequest ¶
type ListNetworkRequest struct {
AccountId *string
}
type ListNetworkResponse ¶
type ListNetworkResponse struct {
Networks []Network
}
type ListPrivateAccessSettingsRequest ¶
type ListPrivateAccessSettingsRequest struct {
AccountId *string
}
type ListPrivateAccessSettingsResponse ¶
type ListPrivateAccessSettingsResponse struct {
PrivateAccessSettings []PrivateAccessSettings
}
type ListVpcEndpointRequest ¶
type ListVpcEndpointRequest struct {
AccountId *string
}
type ListVpcEndpointResponse ¶
type ListVpcEndpointResponse struct {
VpcEndpoints []VpcEndpoint
}
type NccPrivateEndpointRule ¶
type NccPrivateEndpointRule struct {
// The ID of a private endpoint rule.
RuleId *string
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string
// The current status of this private endpoint. The private endpoint rules are
// effective only if the connection state is ESTABLISHED. Remember that you must
// approve new endpoints on your resources in the Cloud console before they take
// effect. The possible values are: - PENDING: The endpoint has been created and
// pending approval. - ESTABLISHED: The endpoint has been approved and is ready
// to use in your serverless compute resources. - REJECTED: Connection was
// rejected by the private link resource owner. - DISCONNECTED: Connection was
// removed by the private link resource owner, the private endpoint becomes
// informative and should be deleted for clean-up. - EXPIRED: If the endpoint
// was created but not approved in 14 days, it will be EXPIRED. - CREATING: The
// endpoint creation is in progress. Once successfully created, the state will
// transition to PENDING. - CREATE_FAILED: The endpoint creation failed. You can
// check the error_message field for more details.
ConnectionState NccPrivateEndpointRule_PrivateLinkConnectionState
// Only used by private endpoints to customer-managed private endpoint services.
//
// Domain names of target private link service. When updating this field, the
// full list of target domain_names must be specified.
DomainNames []string
// Time in epoch milliseconds when this object was created.
CreationTime *int64
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Whether this private endpoint is deactivated.
Deactivated *bool
// Time in epoch milliseconds when this object was deactivated.
DeactivatedAt *int64
ErrorMessage *string
// The Azure resource ID of the target resource.
ResourceId *string
// Not used by customer-managed private endpoint services.
//
// The sub-resource type (group ID) of the target resource. Note that to connect
// to workspace root storage (root DBFS), you need two endpoints, one for blob
// and one for dfs.
GroupId *string
// The name of the Azure private endpoint resource.
EndpointName *string
// <Databricks> account ID. You can find your account ID from the Accounts
// Console.
AccountId *string
// The full target AWS endpoint service name that connects to the destination
// resources of the private endpoint.
EndpointService *string
// Only used by private endpoints towards AWS S3 service.
//
// The globally unique S3 bucket names that will be accessed via the VPC
// endpoint. The bucket names must be in the same region as the NCC/endpoint
// service. When updating this field, we perform full update on this field.
// Please ensure a full list of desired resource_names is provided.
ResourceNames []string
// The AWS VPC endpoint ID. You can use this ID to identify the VPC endpoint
// created by <Databricks>.
VpcEndpointId *string
// Update this field to activate/deactivate this private endpoint to allow
// egress access from serverless compute resources. Only honored for first-party
// services on each cloud (e.g. AWS S3).
Enabled *bool
Endpoint isNccPrivateEndpointRule_Endpoint
}
Properties of the new private endpoint rule. Note that you must approve the endpoint in Azure portal after initialization..
type NccPrivateEndpointRule_Endpoint_GcpEndpoint ¶
type NccPrivateEndpointRule_Endpoint_GcpEndpoint struct {
GcpEndpoint GcpEndpoint
}
NccPrivateEndpointRule_Endpoint_GcpEndpoint selects GcpEndpoint for NccPrivateEndpointRule.Endpoint.
type NccPrivateEndpointRule_PrivateLinkConnectionState ¶
type NccPrivateEndpointRule_PrivateLinkConnectionState string
const ( NccPrivateEndpointRule_PrivateLinkConnectionState_Unspecified NccPrivateEndpointRule_PrivateLinkConnectionState = "" // The endpoint has been approved and is ready to use in your serverless compute // resources. NccPrivateEndpointRule_PrivateLinkConnectionState_Established NccPrivateEndpointRule_PrivateLinkConnectionState = "ESTABLISHED" // Connection was rejected by the private link resource owner. NccPrivateEndpointRule_PrivateLinkConnectionState_Rejected NccPrivateEndpointRule_PrivateLinkConnectionState = "REJECTED" // Connection was removed by the private link resource owner, the private // endpoint becomes informative and should be deleted for clean-up. NccPrivateEndpointRule_PrivateLinkConnectionState_Disconnected NccPrivateEndpointRule_PrivateLinkConnectionState = "DISCONNECTED" // If the endpoint was created but not approved in 14 days, it will be EXPIRED. NccPrivateEndpointRule_PrivateLinkConnectionState_Expired NccPrivateEndpointRule_PrivateLinkConnectionState = "EXPIRED" // The endpoint has been created and pending approval. NccPrivateEndpointRule_PrivateLinkConnectionState_Pending NccPrivateEndpointRule_PrivateLinkConnectionState = "PENDING" // The endpoint creation is in progress. NccPrivateEndpointRule_PrivateLinkConnectionState_Creating NccPrivateEndpointRule_PrivateLinkConnectionState = "CREATING" // The endpoint creation failed. NccPrivateEndpointRule_PrivateLinkConnectionState_CreateFailed NccPrivateEndpointRule_PrivateLinkConnectionState = "CREATE_FAILED" )
type Network ¶
type Network struct {
// The <Databricks> network configuration ID.
NetworkId *string
// The <Databricks> account ID associated with this network configuration.
AccountId *string
// Workspace ID associated with this network configuration.
WorkspaceId *int64
// The ID of the VPC associated with this network configuration. VPC IDs can be
// used in multiple networks.
VpcId *string
// IDs of at least two subnets associated with this network. Subnet IDs
// **cannot** be used in multiple network configurations.
SubnetIds []string
// IDs of one to five security groups associated with this network. Security
// group IDs **cannot** be used in multiple network configurations.
SecurityGroupIds []string
VpcStatus VpcStatus
// Array of error messages about the network configuration.
ErrorMessages []NetworkHealth
// The human-readable name of the network configuration.
NetworkName *string
// Time in epoch milliseconds when the network was created.
CreationTime *int64
// Array of warning messages about the network configuration.
WarningMessages []NetworkWarning
VpcEndpoints *NetworkVpcEndpoints
NetworkInfo isNetwork_NetworkInfo
}
type NetworkConnectivityConfig ¶
type NetworkConnectivityConfig struct {
// <Databricks> network connectivity configuration ID.
NetworkConnectivityConfigId *string
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// The name of the network connectivity configuration. The name can contain
// alphanumeric characters, hyphens, and underscores. The length must be between
// 3 and 30 characters. The name must match the regular expression
// ^[0-9a-zA-Z-_]{3,30}$
Name *string
// The region for the network connectivity configuration. Only workspaces in the
// same region can be attached to the network connectivity configuration.
Region *string
// The network connectivity rules that apply to network traffic from your
// serverless compute resources.
EgressConfig *CustomerFacingNetworkConnectivityConfigEgressConfig
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Time in epoch milliseconds when this object was created.
CreationTime *int64
}
Properties of the new network connectivity configuration..
type NetworkConnectivityConfigAwsPrivateEndpointRule ¶
type NetworkConnectivityConfigAwsPrivateEndpointRule struct {
// The ID of a private endpoint rule.
RuleId *string
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string
// <Databricks> account ID. You can find your account ID from the Accounts
// Console.
AccountId *string
// The full target AWS endpoint service name that connects to the destination
// resources of the private endpoint.
EndpointService *string
// Only used by private endpoints towards a VPC endpoint service for
// customer-managed VPC endpoint service.
//
// The target AWS resource FQDNs accessible via the VPC endpoint service. When
// updating this field, we perform full update on this field. Please ensure a
// full list of desired domain_names is provided.
DomainNames []string
// Only used by private endpoints towards AWS S3 service.
//
// The globally unique S3 bucket names that will be accessed via the VPC
// endpoint. The bucket names must be in the same region as the NCC/endpoint
// service. When updating this field, we perform full update on this field.
// Please ensure a full list of desired resource_names is provided.
ResourceNames []string
// The AWS VPC endpoint ID. You can use this ID to identify VPC endpoint created
// by <Databricks>.
VpcEndpointId *string
// The current status of this private endpoint. The private endpoint rules are
// effective only if the connection state is ESTABLISHED. Remember that you must
// approve new endpoints on your resources in the AWS console before they take
// effect. The possible values are: - PENDING: The endpoint has been created and
// pending approval. - ESTABLISHED: The endpoint has been approved and is ready
// to use in your serverless compute resources. - REJECTED: Connection was
// rejected by the private link resource owner. - DISCONNECTED: Connection was
// removed by the private link resource owner, the private endpoint becomes
// informative and should be deleted for clean-up. - EXPIRED: If the endpoint is
// created but not approved in 14 days, it is EXPIRED.
ConnectionState NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState
// Time in epoch milliseconds when this object was created.
CreationTime *int64
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Whether this private endpoint is deactivated.
Deactivated *bool
// Time in epoch milliseconds when this object was deactivated.
DeactivatedAt *int64
// Only used by private endpoints towards an AWS S3 service.
//
// Update this field to activate/deactivate this private endpoint to allow
// egress access from serverless compute resources.
Enabled *bool
ErrorMessage *string
}
Properties of the new private endpoint rule. Note that for private endpoints towards a VPC endpoint service behind a customer-managed NLB, you must approve the endpoint in AWS console after initialization..
type NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState ¶
type NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState string
const ( NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Unspecified NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "" // The endpoint has been approved and is ready to use in your serverless compute // resources. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Established NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "ESTABLISHED" // Connection was rejected by the private link resource owner. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Rejected NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "REJECTED" // Connection was removed by the private link resource owner, the private // endpoint becomes informative and should be deleted for clean-up. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Disconnected NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "DISCONNECTED" // If the endpoint is created but not approved in 14 days, it is EXPIRED. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Expired NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "EXPIRED" // The endpoint has been created and pending approval. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Pending NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "PENDING" // The endpoint creation is in progress. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_Creating NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "CREATING" // The endpoint creation failed. NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState_CreateFailed NetworkConnectivityConfigAwsPrivateEndpointRule_PrivateLinkConnectionState = "CREATE_FAILED" )
type NetworkConnectivityConfigAzurePrivateEndpointRule ¶
type NetworkConnectivityConfigAzurePrivateEndpointRule struct {
// The ID of a private endpoint rule.
RuleId *string
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string
// The Azure resource ID of the target resource.
ResourceId *string
// Only used by private endpoints to Azure first-party services.
//
// The sub-resource type (group ID) of the target resource. Note that to connect
// to workspace root storage (root DBFS), you need two endpoints, one for blob
// and one for dfs.
GroupId *string
// The name of the Azure private endpoint resource.
EndpointName *string
// The current status of this private endpoint. The private endpoint rules are
// effective only if the connection state is ESTABLISHED. Remember that you must
// approve new endpoints on your resources in the Azure portal before they take
// effect. The possible values are: - INIT: (deprecated) The endpoint has been
// created and pending approval. - PENDING: The endpoint has been created and
// pending approval. - ESTABLISHED: The endpoint has been approved and is ready
// to use in your serverless compute resources. - REJECTED: Connection was
// rejected by the private link resource owner. - DISCONNECTED: Connection was
// removed by the private link resource owner, the private endpoint becomes
// informative and should be deleted for clean-up. - EXPIRED: If the endpoint
// was created but not approved in 14 days, it will be EXPIRED.
ConnectionState NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState
// Time in epoch milliseconds when this object was created.
CreationTime *int64
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64
// Whether this private endpoint is deactivated.
Deactivated *bool
// Time in epoch milliseconds when this object was deactivated.
DeactivatedAt *int64
// Not used by customer-managed private endpoint services.
//
// Domain names of target private link service. When updating this field, the
// full list of target domain_names must be specified.
DomainNames []string
ErrorMessage *string
}
Properties of the new private endpoint rule. Note that you must approve the endpoint in Azure portal after initialization..
type NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState ¶
type NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState string
const ( NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Unspecified NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "" // The endpoint has been created and pending approval. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Init NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "INIT" // The endpoint has been approved and is ready to use in your serverless compute // resources. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Established NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "ESTABLISHED" // Connection was rejected by the private link resource owner. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Rejected NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "REJECTED" // Connection was removed by the private link resource owner, the private // endpoint becomes informative and should be deleted for clean-up. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Disconnected NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "DISCONNECTED" // If the endpoint was created but not approved in 14 days, it will be EXPIRED. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Expired NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "EXPIRED" // The endpoint has been created and pending approval. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Pending NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "PENDING" // The endpoint creation is in progress. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_Creating NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "CREATING" // The endpoint creation failed. NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState_CreateFailed NetworkConnectivityConfigAzurePrivateEndpointRule_PrivateLinkConnectionState = "CREATE_FAILED" )
type NetworkConnectivityConfigEgressConfig ¶
type NetworkConnectivityConfigEgressConfig struct {
}
Egress network configurations. Provides network configurations for Databricks -> Customer traffic..
type NetworkConnectivityConfigEgressConfig_DefaultRule ¶
type NetworkConnectivityConfigEgressConfig_DefaultRule struct {
AzureServiceEndpointRule *NetworkConnectivityConfigEgressConfig_DefaultRule_AzureServiceEndpointRule
AwsStableIpRule *NetworkConnectivityConfigEgressConfig_DefaultRule_AwsStableIpRule
}
Default rules don't have specific targets..
type NetworkConnectivityConfigEgressConfig_DefaultRule_AwsStableIpRule ¶
type NetworkConnectivityConfigEgressConfig_DefaultRule_AwsStableIpRule struct {
// The list of stable IP CIDR blocks from which <Databricks> network traffic
// originates when accessing your resources.
CidrBlocks []string
}
The stable AWS IP CIDR blocks. You can use these to configure the firewall of your resources to allow traffic from your <Databricks> workspace..
type NetworkConnectivityConfigEgressConfig_DefaultRule_AzureServiceEndpointRule ¶
type NetworkConnectivityConfigEgressConfig_DefaultRule_AzureServiceEndpointRule struct {
// The Azure region in which this service endpoint rule applies..
TargetRegion *string
// The Azure services to which this service endpoint rule applies to.
TargetServices []EgressResourceType
// The list of subnets from which <Databricks> network traffic originates when
// accessing your Azure resources.
Subnets []string
}
The stable Azure service endpoints. You can configure the firewall of your Azure resources to allow traffic from your <Databricks> serverless compute resources..
type NetworkHealth ¶
type NetworkVpcEndpoints ¶
type NetworkWarning ¶
type Network_NetworkInfo_GcpNetworkInfo ¶
type Network_NetworkInfo_GcpNetworkInfo struct {
GcpNetworkInfo GcpNetworkInfo
}
Network_NetworkInfo_GcpNetworkInfo selects GcpNetworkInfo for Network.NetworkInfo.
type PrivateAccessLevel ¶
type PrivateAccessLevel string
const ( PrivateAccessLevel_Unspecified PrivateAccessLevel = "" // Only specifically listed endpoints can access my workspace PrivateAccessLevel_Endpoint PrivateAccessLevel = "ENDPOINT" // Only endpoints in the same account can access my workspace PrivateAccessLevel_Account PrivateAccessLevel = "ACCOUNT" )
type PrivateAccessSettings ¶
type PrivateAccessSettings struct {
// <Databricks> private access settings ID.
PrivateAccessSettingsId *string
// The <Databricks> account ID that hosts the private access settings.
AccountId *string
// The human-readable name of the private access settings object.
PrivateAccessSettingsName *string
// The AWS region for workspaces attached to this private access settings
// object.
Region *string
// Determines if the workspace can be accessed over public internet. For fully
// private workspaces, you can optionally specify false, but only if you
// implement both the front-end and the back-end PrivateLink connections.
// Otherwise, specify true, which means that public access is enabled.
PublicAccessEnabled *bool
// The private access level controls which VPC endpoints can connect to the UI
// or API of any workspace that attaches this private access settings object.
// `ACCOUNT` level access (the default) allows only VPC endpoints that are
// registered in your <Databricks> account connect to your workspace. `ENDPOINT`
// level access allows only specified VPC endpoints connect to your workspace.
// For details, see allowed_vpc_endpoint_ids.
PrivateAccessLevel PrivateAccessLevel
// An array of Databricks VPC endpoint IDs. This is the <Databricks> ID that is
// returned when registering the VPC endpoint configuration in your <Databricks>
// account. This is not the ID of the VPC endpoint in AWS. Only used when
// private_access_level is set to ENDPOINT. This is an allow list of VPC
// endpoints that in your account that can connect to your workspace over AWS
// PrivateLink. If hybrid access to your workspace is enabled by setting
// public_access_enabled to true, this control only works for PrivateLink
// connections. To control how your workspace is accessed via public internet,
// see IP access lists.
AllowedVpcEndpointIds []string
}
*.
type ReplaceAccountIpAccessListRequest ¶
type ReplaceAccountIpAccessListRequest struct {
AccountId *string
// The ID for the corresponding IP access list
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
ListType AccountIpAccessListType_IpAccessListType
IpAddresses []string
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Details required to replace an IP access list..
type ReplaceAccountIpAccessListResponse ¶
type ReplaceAccountIpAccessListResponse struct {
IpAccessList *AccountIpAccessList
}
The IP access list was successfully replaced..
type ReplaceIpAccessListRequest ¶
type ReplaceIpAccessListRequest struct {
// The ID for the corresponding IP access list
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
ListType IpAccessListType
IpAddresses []string
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Details required to replace an IP access list..
type ReplaceIpAccessListResponse ¶
type ReplaceIpAccessListResponse struct {
IpAccessList *IpAccessList
}
The IP access list was successfully replaced..
type UpdateAccountIpAccessListRequest ¶
type UpdateAccountIpAccessListRequest struct {
AccountId *string
// The ID for the corresponding IP access list
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
ListType AccountIpAccessListType_IpAccessListType
IpAddresses []string
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Details required to update an IP access list..
type UpdateAccountIpAccessListResponse ¶
type UpdateAccountIpAccessListResponse struct {
IpAccessList *AccountIpAccessList
}
The IP access list was successfully updated..
type UpdateIpAccessListRequest ¶
type UpdateIpAccessListRequest struct {
// The ID for the corresponding IP access list
ListId *string
// Label for the IP access list. This **cannot** be empty.
Label *string
ListType IpAccessListType
IpAddresses []string
// Specifies whether this IP access list is enabled.
Enabled *bool
}
Details required to update an IP access list..
type UpdateIpAccessListResponse ¶
type UpdateIpAccessListResponse struct {
IpAccessList *IpAccessList
}
The IP access list was successfully updated..
type UpdateNccPrivateEndpointRuleRequest ¶
type UpdateNccPrivateEndpointRuleRequest struct {
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Your private endpoint rule ID.
PrivateEndpointRuleId *string
PrivateEndpointRule *UpdatePrivateEndpointRule
UpdateMask *types.FieldMask[UpdatePrivateEndpointRule]
}
Your Network Connectivity Configuration ID..
type UpdateNetworkPolicyRequest ¶
type UpdateNetworkPolicyRequest struct {
// The unique identifier for the network policy.
NetworkPolicyId *string
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// Updated network policy configuration details.
NetworkPolicy *AccountNetworkPolicy
}
type UpdatePrivateAccessSettingsRequest ¶
type UpdatePrivateAccessSettingsRequest struct {
// Properties of the new private access settings object.
CustomerFacingPrivateAccessSettings *PrivateAccessSettings
}
type UpdatePrivateEndpointRule ¶
type UpdatePrivateEndpointRule struct {
// The ID of a private endpoint rule.
RuleId *string `fieldmask:"rule_id"`
// The ID of a network connectivity configuration, which is the parent resource
// of this private endpoint rule object.
NetworkConnectivityConfigId *string `fieldmask:"network_connectivity_config_id"`
// The current status of this private endpoint. The private endpoint rules are
// effective only if the connection state is ESTABLISHED. Remember that you must
// approve new endpoints on your resources in the Cloud console before they take
// effect. The possible values are: - PENDING: The endpoint has been created and
// pending approval. - ESTABLISHED: The endpoint has been approved and is ready
// to use in your serverless compute resources. - REJECTED: Connection was
// rejected by the private link resource owner. - DISCONNECTED: Connection was
// removed by the private link resource owner, the private endpoint becomes
// informative and should be deleted for clean-up. - EXPIRED: If the endpoint
// was created but not approved in 14 days, it will be EXPIRED. - CREATING: The
// endpoint creation is in progress. Once successfully created, the state will
// transition to PENDING. - CREATE_FAILED: The endpoint creation failed. You can
// check the error_message field for more details.
ConnectionState NccPrivateEndpointRule_PrivateLinkConnectionState `fieldmask:"connection_state"`
// Only used by private endpoints to customer-managed private endpoint services.
//
// Domain names of target private link service. When updating this field, the
// full list of target domain_names must be specified.
DomainNames []string `fieldmask:"domain_names"`
// Time in epoch milliseconds when this object was created.
CreationTime *int64 `fieldmask:"creation_time"`
// Time in epoch milliseconds when this object was updated.
UpdatedTime *int64 `fieldmask:"updated_time"`
// Whether this private endpoint is deactivated.
Deactivated *bool `fieldmask:"deactivated"`
// Time in epoch milliseconds when this object was deactivated.
DeactivatedAt *int64 `fieldmask:"deactivated_at"`
ErrorMessage *string `fieldmask:"error_message"`
// The Azure resource ID of the target resource.
ResourceId *string `fieldmask:"resource_id"`
// Not used by customer-managed private endpoint services.
//
// The sub-resource type (group ID) of the target resource. Note that to connect
// to workspace root storage (root DBFS), you need two endpoints, one for blob
// and one for dfs.
GroupId *string `fieldmask:"group_id"`
// The name of the Azure private endpoint resource.
EndpointName *string `fieldmask:"endpoint_name"`
// <Databricks> account ID. You can find your account ID from the Accounts
// Console.
AccountId *string `fieldmask:"account_id"`
// The full target AWS endpoint service name that connects to the destination
// resources of the private endpoint.
EndpointService *string `fieldmask:"endpoint_service"`
// Only used by private endpoints towards AWS S3 service.
//
// The globally unique S3 bucket names that will be accessed via the VPC
// endpoint. The bucket names must be in the same region as the NCC/endpoint
// service. When updating this field, we perform full update on this field.
// Please ensure a full list of desired resource_names is provided.
ResourceNames []string `fieldmask:"resource_names"`
// The AWS VPC endpoint ID. You can use this ID to identify the VPC endpoint
// created by <Databricks>.
VpcEndpointId *string `fieldmask:"vpc_endpoint_id"`
// Update this field to activate/deactivate this private endpoint to allow
// egress access from serverless compute resources. Only honored for first-party
// services on each cloud (e.g. AWS S3).
Enabled *bool `fieldmask:"enabled"`
Endpoint isUpdatePrivateEndpointRule_Endpoint
// contains filtered or unexported fields
}
Properties of the new private endpoint rule. Note that you must approve the endpoint in Azure portal after initialization..
type UpdatePrivateEndpointRule_Endpoint_GcpEndpoint ¶
type UpdatePrivateEndpointRule_Endpoint_GcpEndpoint struct {
GcpEndpoint GcpEndpoint `fieldmask:"gcp_endpoint"`
}
UpdatePrivateEndpointRule_Endpoint_GcpEndpoint selects GcpEndpoint for UpdatePrivateEndpointRule.Endpoint.
type UpdateWorkspaceNetworkOptionRequest ¶
type UpdateWorkspaceNetworkOptionRequest struct {
// Your <Databricks> account ID. You can find your account ID in your
// <Databricks> accounts console.
AccountId *string
// The workspace ID.
WorkspaceId *int64
// The network option details for the workspace.
WorkspaceNetworkOption *WorkspaceNetworkOption
}
type VpcEndpoint ¶
type VpcEndpoint struct {
// Databricks VPC endpoint ID. This is the <Databricks>-specific name of the VPC
// endpoint. Do not confuse this with the `aws_vpc_endpoint_id`, which is the ID
// within AWS of the VPC endpoint.
VpcEndpointId *string
// The <Databricks> account ID that hosts the VPC endpoint configuration.
AccountId *string
// The human-readable name of the storage configuration.
VpcEndpointName *string
// The ID of the VPC endpoint object in AWS.
AwsVpcEndpointId *string
// The ID of the <Databricks> [endpoint service] that this VPC endpoint is
// connected to. For a list of endpoint service IDs for each supported AWS
// region, see the [Databricks PrivateLink documentation].
//
// [Databricks PrivateLink documentation]: https://docs.databricks.com/administration-guide/cloud-configurations/aws/privatelink.html
// [endpoint service]: https://docs.aws.amazon.com/vpc/latest/privatelink/endpoint-service.html
AwsEndpointServiceId *string
// This enumeration represents the type of Databricks VPC endpoint service that
// was used when creating this VPC endpoint. If the VPC endpoint connects to the
// <Databricks> control plane for either the front-end connection or the
// back-end REST API connection, the value is GENERAL_ACCESS. If the VPC
// endpoint connects to the <Databricks> workspace for the back-end secure
// cluster connectivity relay, the value is DATAPLANE_RELAY_ACCESS.
UseCase VpcEndpointUseCase
// The AWS region in which this VPC endpoint object exists.
Region *string
// The AWS Account in which the VPC endpoint object exists.
AwsAccountId *string
// The current state (such as `available` or `rejected`) of the VPC endpoint.
// Derived from AWS. For the full set of values, see [AWS DescribeVpcEndpoint
// documentation].
//
// [AWS DescribeVpcEndpoint documentation]: https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-vpc-endpoints.html
State *string
VpcEndpointInfo isVpcEndpoint_VpcEndpointInfo
}
*.
type VpcEndpointUseCase ¶
type VpcEndpointUseCase string
const ( VpcEndpointUseCase_Unspecified VpcEndpointUseCase = "" VpcEndpointUseCase_WorkspaceAccess VpcEndpointUseCase = "WORKSPACE_ACCESS" VpcEndpointUseCase_DataplaneRelayAccess VpcEndpointUseCase = "DATAPLANE_RELAY_ACCESS" // General access, replaces WORKSPACE_ACCESS in customer-facing API. VpcEndpointUseCase_GeneralAccess VpcEndpointUseCase = "GENERAL_ACCESS" )
type VpcEndpoint_VpcEndpointInfo_GcpVpcEndpointInfo ¶
type VpcEndpoint_VpcEndpointInfo_GcpVpcEndpointInfo struct {
GcpVpcEndpointInfo GcpVpcEndpointInfo
}
VpcEndpoint_VpcEndpointInfo_GcpVpcEndpointInfo selects GcpVpcEndpointInfo for VpcEndpoint.VpcEndpointInfo. The cloud info of this vpc endpoint. Info for a GCP vpc endpoint.
type WorkspaceNetworkOption ¶
type WorkspaceNetworkOption struct {
// The network policy ID to apply to the workspace. This controls the network
// access rules for all serverless compute resources in the workspace. Each
// workspace can only be linked to one policy at a time. If no policy is
// explicitly assigned, the workspace will use 'default-policy'.
NetworkPolicyId *string
// The workspace ID.
WorkspaceId *int64
}