Using AWS PrivateLink, you can securely connect your AWS-deployed services to Hightouch.
Network traffic between Hightouch and your services connected by AWS PrivateLink stays on the AWS backbone network and doesn't travel over the public internet. That means that you can restrict public access to your services, and your data is never exposed to the public internet.
Hightouch can use AWS PrivateLink to connect to your Databricks workspace control plane. This allows Hightouch to securely interact with your Databricks workspace without exposing your data to the public internet.
Hightouch uses Databricks "Front-end PrivateLink", which is distinct from Databricks "Back-end PrivateLink", which is used to connect the Databricks control plane to a compute plane running in your AWS VPCs.
Hightouch supports AWS PrivateLink on Business tier accounts.
Your Hightouch workspace must be located in the AWS us-east-1, eu-west-1, or ap-south-1 region.
Your Databricks workspace must be located in one of the following AWS regions: us-east-1, us-west-2, eu-west-1, ap-south-1, or ap-southeast-2
Your Databricks workspace must have been created with a "Private Access Settings" object. Databricks does not support setting a Private Access Settings object on existing workspaces. If you need to use PrivateLink with an existing workspace, you will need to create a new workspace with the appropriate settings.
Hightouch can connect to any source or destination exposed via a VPC Endpoint Service. This allows you to expose any service running in your VPC to Hightouch without exposing it to the public internet.
Hightouch supports AWS PrivateLink on Business tier accounts.
Your integration (source / destination) must be exposed via a VPC Endpoint Service. This generally requires a Network Load Balancer to sit in front of your service.
Your VPC Endpoint Service must be located in one of the following AWS regions: us-east-1, us-west-2, eu-west-1, ap-south-1, or ap-southeast-2
Your Hightouch workspace must be located in the AWS us-east-1, eu-west-1, or ap-south-1 region.