Allowing Atlan IPs in Databricks
Add Atlan's addresses to your Databricks workspace IP access list (or a corporate firewall in the path) so crawlers and miners can connect.
Add Atlan's addresses to your Databricks workspace IP access list (or a corporate firewall in the path) so crawlers and miners can connect.
Enable a public IP on your AlloyDB for PostgreSQL instance and admit only Atlan's tenant-specific egress IPs through authorized networks.
Everything IP- and firewall-related for dbt - dbt Cloud's IP restrictions feature, and storage-side firewalls for dbt Core buckets.
The three gatekeepers that can sit between Atlan and Tableau - Tableau Cloud's IP allowlist, your firewall, and WAF content rules - and how to open each.
What identity Atlan presents to your AWS account for AWS Glue, which values are tenant-specific, and exactly what to request from support in a single ticket.
The Atlan-side values an Amazon S3 role setup needs, what each is for, and how to get them in a single support ticket.
Learn about the network identities Atlan presents to your data sources—public egress IPs, private CIDR ranges, and endpoint identities for AWS, Azure, and GCP tenants.
Compare the three ways Atlan can reach your AlloyDB for PostgreSQL instance - the self-deployed runtime, Private Service Connect, and public IP with authorized networks.
Pick the right AWS identity type and network path for Atlan to connect to Amazon Athena - IAM access keys, IAM role delegation, or either with AWS PrivateLink.
Compare the three ways Atlan can reach your Amazon Redshift cluster or Serverless workgroup - public IP allowlisting, the AWS private network link, and the self-deployed agent.
Pick the identity Atlan uses to read your Amazon S3 metadata - a cross-account IAM role it borrows, or an IAM user whose keys you hand over.
Pick how Atlan proves its identity to AWS Glue - IAM access keys, a cross-account IAM role, or the self-deployed agent.
Compare the three ways Atlan can reach your Cloud SQL for PostgreSQL instance - public IP with authorized networks, the self-deployed runtime, and Private Service Connect.
Compare the two ways Atlan can read your dbt metadata - the dbt Cloud API with a token, or dbt output files in a cloud storage bucket for dbt Core.
Pick the network path and authentication method Atlan uses to reach Google BigQuery - public API endpoint or Private Service Connect, service account key or Workload Identity Federation.
Compare the three ways Atlan can reach your PostgreSQL database - internet with IP allowlisting, private connectivity, or a self-deployed agent - and pick the right one before touching any firewall.
Compare the three ways Atlan can reach your Snowflake account—public IP allowlisting, Private Link, and the self-deployed agent—and pick the right one before you touch any cloud configuration.
Compare the three ways Atlan can reach your Microsoft SQL Server - direct with IP allowlisting, a private network link, or the self-deployed runtime - and pick the right one before you touch any firewall.
Compare the four ways Atlan can reach your Tableau environment - direct, direct with IP allowlisting, AWS PrivateLink, and the self-deployed agent.
Keep your Cloud SQL for PostgreSQL instance private - run a small Atlan-provided agent inside your network that reads metadata locally and sends it to Atlan over outbound HTTPS only.
Connect Atlan to a SQL Server that is reachable from the internet - including Azure SQL Database with "Selected networks" enabled. Four phases, each labeled with who performs it.
Connect Atlan to Cloud SQL for PostgreSQL over the instance's public IP, with Cloud SQL's authorized-networks list and SSL keeping everyone else out.
The fastest path to connect Atlan to PostgreSQL - Atlan connects to your database's public endpoint over TLS, and you allowlist Atlan's fixed egress IPs. Five phases, each labeled with who performs it.
Connect Atlan to a private AlloyDB for PostgreSQL instance with the self-deployed runtime - a small service in your network that reads AlloyDB locally and sends metadata out over outbound-only HTTPS.
Learn how Atlan supports private network connectivity to data sources in different AWS regions and across cloud providers.
Troubleshoot Databricks connectivity, covering network and private-link issues, authentication, permissions, extraction, and metadata questions.
Allow Atlan's fixed source IPs through your security group so crawlers and miners can connect to publicly accessible Amazon Redshift clusters and workgroups.
SQL Server traffic from Atlan usually crosses several firewalls, owned by different teams. Every layer, which Atlan value belongs in each, and the mistakes that generate the most support tickets.
The reference for gates 1 and 2 - what to allowlist where, how pg_hba.conf decides, and how to keep the SSL settings on both ends consistent. Applies to every connectivity method.
Learn why AlloyDB for PostgreSQL is hard to reach from outside, and what each of the three connection paths - self-deployed runtime, Private Service Connect, and public IP - actually does.
Understand the three connectivity paths between Atlan and Databricks—public, Private Link, and site-to-site VPN—and what determines which one applies to your workspace.
Learn the two Tableau APIs Atlan uses, how sign-in works with PATs and Connected Apps, and where Tableau connections typically get blocked.
Learn how Atlan reaches Google BigQuery, why there are no IP addresses to allowlist on the main path, and the four traffic hops that matter.
Learn the three traffic paths between Atlan and your Cloud SQL for PostgreSQL instance, who owns each piece, and why connectivity is not authentication.
Learn how Atlan reads your AWS Glue Data Catalog - the traffic path, the two ways of proving identity, and the two-key door that makes role-based access safe.
Learn how Atlan reads Amazon S3 - IAM roles, trust policies, External IDs, and the four AWS doors every crawl must pass through.
A plain-language explanation of the journey a connection makes from Atlan to your PostgreSQL database - the three gates it must pass, the three paths it can take, and SSL in one minute.
Learn the three traffic paths between your dbt setup and Atlan - the dbt Cloud API pull, the storage-bucket read, and your own upload pipeline.
Learn how Atlan borrows an identity in your AWS account for Amazon Athena, why there are two halves to set up, and the four traffic paths a healthy connection uses.
A plain-language explanation of what a private link to Databricks is, who builds which half, and the three traffic paths between Atlan and Databricks.
Learn what a private link is, who is responsible for each part of the setup, and the three traffic paths between Atlan and Snowflake.
Learn how Redshift-managed VPC endpoints work, who builds which half, and the three traffic paths between Atlan and Amazon Redshift.
A plain-language explanation of where Atlan's crawler actually runs, the three traffic paths to your SQL Server, and how authentication rides on top of the network path.
Definitions of the connectivity and identity terms used across Atlan's connector setup guides—endpoints, endpoint services, CIDR ranges, service principals, tenant settings, and more.
Connect Atlan to Google Cloud data sources using Private Service Connect: Google APIs PSC for BigQuery and GCS, or published-service PSC for VPC databases.
Classic AWS PrivateLink for Atlan: publish a VPC endpoint service backed by an NLB; covers AWS databases, on-premises sources, and multi-account hubs.
Share individual AWS databases with Atlan over PrivateLink using VPC resource gateways—no NLB, endpoint service, or target-group maintenance.
At-scale AWS private connectivity: one VPC Lattice service-network share reaches many databases across VPCs and accounts, with real hostnames for RDS IAM auth.
Azure Private Link for Atlan: direct private endpoints into PaaS services, or IaaS sources behind a Standard SKU ILB and Private Link Service.
A decision guide for connecting Atlan to your data sources privately, without crossing the public internet—which pattern fits your cloud and source.
Connect Atlan to a SQL Server that has no public access, over AWS PrivateLink or Azure Private Link - one common five-phase pattern covering EC2, RDS, Azure VM, and Azure SQL Database / Managed Instance.
Keep traffic between your GCP-hosted Atlan tenant and your Cloud SQL for PostgreSQL instance entirely on Google's internal network with Private Service Connect.
Understand how AWS PrivateLink ensures all metadata traffic between Atlan and AWS SageMaker Unified Studio stays within the AWS private network.
For all details, see [Databricks documentation](https://docs.databricks.com/administration-guide/cloud-configurations/aws/privatelink.html).
Connect Atlan to a private Amazon Redshift cluster over a Redshift-managed VPC endpoint, so traffic never crosses the public internet.
Connect Atlan to an AWS-hosted Databricks workspace over AWS PrivateLink, so traffic never crosses the public internet.
Set up AWS PrivateLink between your Snowflake account and your Atlan tenant, including cross-region configurations.
Private connectivity from Atlan to Azure Database for PostgreSQL is a support-assisted VNet peering setup - what to ask for, what you configure yourself, and the caveats to insist on before signing off.
Connect Atlan to an Azure Databricks workspace over Azure Private Link, including the endpoint approval handshake and the NSG rule.
Private connectivity to PostgreSQL on Google Cloud depends on what the database is - Cloud SQL and AlloyDB have Private Service Connect paths under their own connectors; self-managed Postgres uses the self-deployed agent.
Keep Atlan's BigQuery API traffic off the public internet with Google Private Service Connect - Atlan builds the private endpoint; you paste one DNS name.
Let Atlan's SaaS reach your AlloyDB for PostgreSQL privately over Google's internal network - no public IP, nothing deployed on your side beyond a service attachment.
Tableau special cases - AWS PrivateLink, fully on-premises servers, Server-to-Cloud migrations, multiple sites, and org changes that quietly break connections.
Google BigQuery special cases - multiple projects, Delta external tables, Data Quality with WIF, per-user SSO, credential rotation, and the Lakehouse integration.
AlloyDB for PostgreSQL special cases - fleets of instances, very large databases, cross-cloud tenants, and connection paths that rewrite the port.
Amazon Athena special cases - PrivateLink, cross-account Glue catalogs, cross-region sources, very large catalogs, and multiple Atlan tenants.
Cloud SQL for PostgreSQL special cases - IAM authentication done right, cross-cloud tenants, multiple instances and read replicas, and private IPs that quietly change.
On-premises SQL Server via the self-deployed runtime, Windows/NTLM and Entra ID authentication quirks, Azure SQL Managed Instance failover listeners, and estates with many environments and ports.
On-premises PostgreSQL, many databases behind one PrivateLink, Aurora failovers and moving IPs, Azure and GCP hosting, cross-region IAM authentication, and VPC Lattice.
Multiple workspaces, extra hostnames and custom ports, cross-cloud and cross-region setups, site-to-site VPNs, and the reversed traffic of lakehouse and MCP integrations.
Amazon Redshift Serverless, DC2 clusters, multiple clusters, cross-region and cross-cloud tenants, external (Glue/Spectrum) schemas, and sources reachable only from inside your network.
Symptom-first troubleshooting for AlloyDB for PostgreSQL connectivity - private IP errors, PSC handshake failures, IAM authentication issues, grants, large crawls, and sudden breakage.
Symptom-first troubleshooting for Amazon Redshift connectivity - timeouts, IAM policy scope, role trust, DNS, password failures, Serverless quirks, and sudden breakage.
Symptom-first troubleshooting for Amazon Athena connectivity - role authentication failures, JDBC timeouts, permission gaps, platform-side signatures, and sudden breakage.
Symptom-first troubleshooting for Cloud SQL for PostgreSQL connectivity - private IP errors, timeouts dressed as auth failures, SSL mismatches, IAM login, agent hangs, and PSC pending states.
Symptom-first troubleshooting for Google BigQuery connectivity - VPC-SC denials, generic connection errors, WIF failures, key rotation, and cross-project permission issues.
Symptom-first troubleshooting for Tableau connectivity - PAT failures, SSL certificate errors, host and site issues, Metadata API limits, mid-run 401s, and WAF blocks.
The Google services and VPC Service Controls ingress rules your security team must allow for Atlan to reach Google BigQuery.