Lakebase Governance

Lakebase Costs Under
Control

Endpoints left running, branches accumulating storage, autoscaling over-provisioned. Kostavo detects it all and alerts your team before costs spiral.

Where Lakebase Costs Leak

Endpoints Never Suspend

A Lakebase endpoint with auto-suspend disabled keeps burning compute 24/7, even when no one is querying. Databricks doesn't enforce this for you.

Branches Without Expiry

Dev and feature branches pile up without expiry dates. Each one consumes storage silently, and no one remembers to clean them up.

Over-Provisioned Autoscaling

Minimum CU set too high means you pay for capacity you never use. Maximum CU set too high means a single query can trigger runaway costs.

What Kostavo Scans

Endpoint Cost Controls

Flags endpoints with auto-suspend disabled or suspend timeouts set above your threshold. Detects excessive HA configurations burning double compute.

  • Auto-suspend detection
  • Suspend timeout alerting
  • HA policy checks

Branch Lifecycle

Detects branches without expiry dates, excessive branch counts per project, and unprotected default branches at risk of accidental deletion.

  • Missing expiry detection
  • Branch count alerting
  • Unprotected branch detection

Autoscaling Guardrails

Flags minimum and maximum CU that exceed your configured thresholds. Surfaces over-provisioned baselines and uncapped scaling before they turn into waste.

  • Min CU baseline checks
  • Max CU ceiling checks
  • Configurable thresholds

Lakebase findings: endpoints without suspension, stale branches, and Postgres role hygiene.

Security & Compliance

  • Detect roles with DATABRICKS_SUPERUSER membership granting excessive privileges
  • Flag roles using Postgres password auth instead of OAuth
  • Detect roles with BYPASSRLS, CREATEDB, or CREATEROLE attributes
  • Flag projects with native password login enabled instead of OAuth
  • Detect projects running Postgres below your required minimum version
  • Flag projects without tags for cost tracking and audit
  • Ensure point-in-time recovery meets your backup requirements

Connect in 5 Minutes

1

Connect Your Workspace

Add your Databricks workspace to Kostavo.

2

Assign Lakebase Policies

Pick from 15 built-in Lakebase policies.

3

Start Governing

Kostavo scans continuously and alerts your team when something drifts from policy.

Secure by Design

  • No data access: Kostavo monitors Lakebase resources, never touches your databases
  • Configurable thresholds: adapt CU limits, branch counts, and timeouts to your team's standards
  • Continuous scanning: checks run on schedule so drift is caught early, not at month-end

Stop Paying for Idle Lakebase Compute

See which Lakebase branches, endpoints, and roles need attention on your first scan.

Start Free Trial