Outbound Private Connect for Databricks

This topic covers setup information specific to the data provider. General information on setting up a private connection is in Outbound Private Connect, and information on setting up the Tableau Cloud endpoint is in Outbound Private Connection Set Up: Tableau Cloud.

Prerequisites

Note: Tableau Cloud connections to Databricks over Private Connect support the following authentication methods: Service Principal (OAuth M2M) and Personal Access Token (PAT). Other authentication methods (for example, OAuth through an external identity provider) aren't supported

Tableau Cloud Information for the Data Provider

Databricks front-end PrivateLink doesn't require endpoint service configuration on the Databricks side to allow a connection from Tableau Cloud. This means that you don't need to get the Identity and Access Management (IAM) Amazon Resource Name (ARN) from Tableau Cloud and add it to the endpoint service.

Data Provider Information for Tableau Cloud

From the Databricks Account Console, get:

  • Endpoint service name: The regional front-end VPC Endpoint Service Name for your Tableau Cloud site's AWS region (for example, com.amazonaws.vpce.us-east-1.vpce-svc-1234567890abcdef1). This is published by Databricks per region. See the Databricks topic Configure Inbound PrivateLink(Link opens in a new window) for the service name for your region.

    Note: If your Databricks workspace and your Tableau Cloud site are in different AWS regions, use the endpoint service name for your Tableau Cloud site's region, not your workspace's region.

  • Workspace URL: The default workspace URL for the workspace you want Tableau Cloud to connect to (for example, dbc-12345678-abcd.cloud.databricks.com).

After you have the values, enter them in the Tableau Cloud Create Private Connection dialog:

  • Enter the endpoint service name in the Endpoint Service Name field.
  • Enter the workspace URL in the Custom Address field.

For instructions on the Create Private Connection dialog, see the Databricks topic Configure Inbound PrivateLink(Link opens in a new window).

Register the VPC Endpoint in Databricks

After you create the private connection in TCM, Tableau provisions a VPC Endpoint and assigns it a VPC Endpoint ID. Register this VPC Endpoint ID with your Databricks account to complete the private connection setup.

  1. In TCM, find the private connection and record the VPC Endpoint ID (for example, vpce-1234567890abcdef1).
  2. In the Databricks Account Console, go to Cloud resources > VPC endpoints, and select Add VPC endpoint.
  3. Name the endpoint, then enter the VPC Endpoint ID from TCM that you recorded in step 1. Select the AWS region that matches your Tableau Cloud site's region.
  4. Attach the registered VPC endpoint to your workspace's Private Access Settings (front-end VPC endpoints list).

For full instructions, see Configure AWS PrivateLink for front-end connections.

After Databricks accepts the connection, return to Tableau Cloud Manager. In the private connection's Actions menu (...), select Sync and watch for the status to become Ready.

Note: If you need both public and private access to the same Databricks workspace (for example, private access from Tableau Cloud and public access from user browsers), you must configure a custom workspace URL(Link opens in a new window) in Databricks before setting up Private Connect. After the custom URL is configured, use the default workspace URL in the Custom Address field in Tableau Cloud Manager, and make sure that public access is enabled on the workspace's Private Access Settings in the Databricks Account Console.

Thanks for your feedback!Your feedback has been successfully submitted. Thank you!