Control plane & compute plane
Databricks is split in two. The control plane runs in Databricks' own cloud account: the web UI, notebooks, the job scheduler, cluster management and Unity Catalog's metadata. The compute plane is where your data is actually processed, either on virtual machines in your cloud account (classic compute) or in a pool Databricks runs for you (serverless). Your data itself stays in your cloud storage. Knowing this boundary explains Databricks' security model, its networking, its bill and many of its error messages.
Air traffic control
The control tower (control plane) plans flights, tracks them and gives instructions, but it never carries passengers. The aircraft (compute plane) do the actual flying, and the passengers (your data) board at your own airport (your storage). The tower can tell a plane to take off, but it cannot open the luggage.
1. The picture
2. Accounts, workspaces and metastores
| Level | What it is | Typical count |
|---|---|---|
| Account | Your company's top-level Databricks tenant: users, groups, billing, metastores | 1 |
| Metastore (Unity Catalog) | The top of the data hierarchy, one per cloud region | 1 per region |
| Workspace | A deployment with its own URL, notebooks, jobs and compute (e.g. dev, prod) | several |
| Catalog → schema → table | The data hierarchy inside the metastore (lesson 06) | many |
Several workspaces can attach to the same metastore, so a table created in the dev workspace can be granted to users of the analytics workspace without copying anything. Identity (users, groups, service principals) lives at the account level and is synced from your identity provider (Microsoft Entra ID, Okta) via SCIM.
3. Why the split matters
Security
Data never has to pass through the control plane. Notebook results shown in the UI do, which is why admins can restrict downloading results and why secrets should never be printed.
Networking
Classic clusters in your VPC need to reach the control plane (outbound) and your storage. Private connectivity (PrivateLink / Private Link) keeps that traffic off the public internet.
Billing
Classic: two bills, cloud VMs plus Databricks DBUs. Serverless: one DBU-based bill that includes the machines (lesson 16).
Errors
"Cluster failed to start: cloud provider quota exceeded" is your cloud account's limit. "Permission denied on table" is Unity Catalog, in the control plane.
4. Where data lives
Tables are Delta files (Parquet data files plus a _delta_log folder) in cloud object storage.
With Unity Catalog, managed tables live in a storage location that Unity Catalog controls (you
never touch the paths), and external tables point at paths you manage. Access to storage is
granted through storage credentials and external locations defined in Unity Catalog, not
through keys pasted into notebooks. Lesson 06 covers this in detail.
DESCRIBE DETAIL main.default.orders; -- shows format = delta, location, numFiles, sizeInBytes DESCRIBE HISTORY main.default.orders; -- every write recorded in the transaction log
Recap
- Control plane (Databricks' account): UI, notebooks, scheduler, cluster manager, Unity Catalog metadata.
- Compute plane: classic VMs in your account, or serverless in Databricks' account.
- Data stays in cloud object storage as Delta tables; access is governed by Unity Catalog.
- Account → metastore (per region) → workspaces; many workspaces can share one metastore.