MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.21k stars 21.36k forks source link

Metastore, artifact Blob storage, log Blob storage, DBFS root Blob storage, and Event Hub endpoint IPs can change over time. #57831

Closed pnarsi closed 1 year ago

pnarsi commented 4 years ago

The warning box on this page warns that the IP addresses of five of the services that we need to add to the Routing Table with a next hop of "Internet" can change over time.

How frequently will these IP addresses change? In theory can they change several times within the same day or are we talking about infrequent changes to the IP Addresses potentially once every few months?

Furthermore the Databricks team through a blog article talk about an alternative solution where we use an Azure Firewall on a peered VNET with service endpoints to whitelist the specific FQDN of these five service dependencies. The advantage of this is that we don't need to worry about changing IP addresses (at the cost of spinning up an Azure Firewall). Is this alternative setup suggested by Databricks something that Microsoft officially endorses?

Databricks blog entry on this topic: https://databricks.com/blog/2020/03/27/data-exfiltration-protection-with-azure-databricks.html


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

shashishailaj commented 4 years ago

@pnarsi Thank you for your feedback . We will investigate this and update the thread.

MartinJaffer-MSFT commented 4 years ago

While it is possible for the IPs to change 'several times within the same day', the changes on average are closer to the 'every few months' timescale than the 'several times within the same day' timescale. @pnarsi I will ask author whether the approach is officially endorsed.

MartinJaffer-MSFT commented 4 years ago

@mamccrea can you please help me determine whether the solution hosted on Databricks website is officially endorsed by Microsoft?

mikelor commented 4 years ago

Just wanted to add, that we're experiencing a similar issue. It also looks like the doc was updated recently to add more artifact storage hostnames for the WestUS2 region.

I see two options

  1. Implement the alternative solution as described on the databricks blog (adds cost & complexity)
  2. Add UDR routes for all storage ranges in regions used based on the Azure IP Range document. https://www.microsoft.com/en-us/download/details.aspx?id=56519 (which also changes over time).

Of course my preferred option, would be for MS to implement something that makes it all transparent to me.

mamccrea commented 4 years ago

reassign:mssaperla

kateglee-db commented 1 year ago

Thanks for your dedication to our documentation. Unfortunately, we have been unable to address your issue and apologize for the delayed response. We are closing this issue, but if you feel that it's still a concern, please let us know directly at doc-feedback@databricks.com.

please-close

prmerger-automator[bot] commented 1 year ago

Invalid command: '#please-close'. Only Microsoft employees can use this command.

JasonWHowell commented 1 year ago

please-close