An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
Traffic between Databricks and Private Endpoints in Hub and Spoke Architecture
I am working on deploying some of my workloads in hub and spoke in Azure where I have deployed Azure firewall and Private Endpoints for storage accounts in hub vnet and in the Spoke Vnets, I have my databricks workspace. I have setup peering between hub and spoke Vnets. I was able to access storage accounts using databricks but I wanted to provide selective access to few storage accounts from databricks and during the research for a solution for it I discovered that traffic between databricks and storage account PE was not travelling via firewall and this is the default behaviour with PEs and to overide this we need to enable network policies for private endpoint subnet and we need to create a route to force the traffic via firewall and create a allow network rule in the firewall policy to allow selected private endpoint ip addresses and deny other databricks traffic but after implementing this I am not able to reach those storage accounts at all from databricks whose ips are allowed in azure firewall network policy so I need some guidance how can this issue be resolved?