Jobs & Pipeline Governance

Jobs & Pipelines.
Checked Continuously.

Kostavo scans both Databricks Jobs and Declarative Pipelines for runaway resources, silent failures, cluster misconfigurations, and security risks, without manual reviews.

What Goes Wrong Without Policies

Runaway Resources

Continuous-mode pipelines and jobs run 24/7 without review. Pipelines left in development mode burn compute indefinitely.

Silent Failures

Repeatedly failing jobs and pipelines stuck in FAILED state notify no one. Teams discover data issues long after the fact.

Cluster Misconfigurations

Jobs running on all-purpose clusters, secrets hardcoded in env vars, SSH keys left active, missing cost tags: all invisible without systematic policies.

What Kostavo Scans

Continuous & Runaway Detection

Flags continuous-mode pipelines and continuously-running jobs. Also detects long-running stuck job runs. Can stop them automatically.

  • Continuous pipeline mode
  • Continuous job detection
  • Long-running run detection

Failure & Reliability Policies

Detects repeatedly failing jobs, pipelines stuck in FAILED state, and resources with no failure notifications or retry policies configured.

  • Repeatedly failing jobs
  • Failed pipeline state
  • Missing notifications & retry

Cluster & Security Policies

Scans job clusters for all-purpose cluster use, SSH access, plaintext secrets in env vars, missing cost tags, and overly permissive job permissions.

  • All-purpose cluster usage
  • Env var secret detection
  • Open permissions & SSH

Job and pipeline findings: failing runs, missing timeouts, retry policy, and continuous mode.

Coverage

Declarative Pipelines

Continuous mode, failed state, development mode, edition, preview channel, target schema, notifications, asset bundle

Jobs & Workflows

Failing runs, long-running runs, continuous jobs, concurrency, cluster configs, permissions, notifications, retry policies, asset bundle

Getting Started in Minutes

1

Connect Your Workspace

Add your Databricks workspace to Kostavo. Kostavo becomes a workspace admin and uses a minimal service principal (Azure or AWS), read-only for most policies.

2

Configure Policy Profiles

Choose which policies to enable and set action modes: Notify to alert resource owners and workspace admins, or Fix/Remove to stop runaway resources automatically.

3

Policies Run Continuously

Kostavo scans your workspace on a schedule. Findings appear in the dashboard and trigger notifications to the resource owner and workspace admins.

Catch What Your Teams Miss

See which jobs and pipelines are failing, retrying, or running without limits.

Start Free Trial