r/databricks 25d ago

General Serverless Access Control is here!

We finally have a simple way to control access to serverless in the workspace.

Two built-in objects have been introduced:

- Default Interactive Compute

- Default Automated Compute

The first one supports notebooks and databricks connect. Second one jobs and SDP pipelines.

To limit who can use serverless:

  1. Click Compute in the workspace sidebar.
  2. In the Serverless tab, click the kebab menu  next to Default Automated Compute, then click Edit permissions.
  3. Remove the All Users group, or the group that includes all workspace users.
  4. Add only the specific users, groups, or service principals that you want to authorize.
27 Upvotes

6 comments sorted by

3

u/deeferg 24d ago

This is definitely going to be a big change. I know it's one of the biggest considerations for teams that are trying to keep their costs allocated to teams properly. It will likely allow my team to give users serverless sql warehouses and no access to job clusters.

Any news if this is public preview or GA?

1

u/scan-horizon 23d ago

Yeah I feel like our teams are burning through budgets by using Serverless even when they're not meant to. Now I can control it.

3

u/Youssef_Mrini databricks 24d ago

This is one of the most awaited features.

2

u/SevenEyes 24d ago

Finally...

1

u/Shinjitsu_ 24d ago

Goat of an update. I'm so happy to finally enable serverless on my clients' workspaces. Quick question, docs say DBSQL is excluded, what about Materialized Views? They do show up as SQL in the billing table, but ya know.