
Unity Catalog Governance Pack: Encryption Guide for Unity Catalog
Encryption Guide for Unity Catalog Overview Encryption provides data protection at two levels: At rest : Data stored on disk is encrypted In transit : Data moving between services is encrypted 1. Encryption at Rest Default Encryption (Platform-Managed Keys) Databricks encrypts all data at rest by default using platform-managed keys: Delta tables on ADLS Gen2: AES-256 encryption Databricks DBFS: AES-256 encryption Notebook content: Encrypted in control plane Cluster EBS volumes: Encrypted Customer-Managed Keys (CMK) For regulatory requirements, you can bring your own encryption keys: Azure Key Vault Setup # Create Key Vault az keyvault create \ --name your-governance-kv \ --resource-group your-rg \ --location eastus \ --sku premium \ --enable-purge-protection \ --enable-soft-delete # Create encryption key az keyvault key create \ --vault-name your-governance-kv \ --name databricks-cmk \ --ktype RSA \ --size 2048 # Grant Databricks access to the key az keyvault set-policy \ --name your-g
Continue reading on Dev.to
Opens in a new tab




