> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Install Kyberis in Databricks

> Compatibility, Git folders, wheels for jobs, and deploying the Databricks App.

There are three ways to use Kyberis in Databricks. All of them need a Kyberis API
key ([Credential setup](/integrations/databricks/credentials)) and outbound HTTPS
to the Kyberis API ([Network requirements](/integrations/databricks/network)).

| Path | You get | Best for |
| - | - | - |
| [Databricks Marketplace](#1-databricks-marketplace) | The `kyberis_databricks` wheel in a shared Unity Catalog volume, plus the example notebooks attached to the listing | Jobs and clusters; no Git folder needed |
| [Git folder](#2-git-folder-and-notebooks) | The full source: helper package, example notebooks, and Databricks App | Getting started, and deploying the app |
| [Databricks App](#3-databricks-app) | An interactive Streamlit investigation app | Analysts who should not have to write code |

## Compatibility

| Component | Requirement |
| - | - |
| Notebooks and jobs | Databricks Runtime 13.3 LTS or newer (Python 3.10+). No cluster libraries required — the client is vendored and stdlib-only. |
| Databricks App | Databricks Apps enabled in the workspace, Python 3.11 runtime. The only external dependency is `streamlit`, installed from `requirements.txt` at deploy. |
| Unity Catalog | Required for the Marketplace path, since the share arrives as a Unity Catalog volume. Optional otherwise — the example notebooks write plain Delta tables, and Unity Catalog and `hive_metastore` both work. |
| Serverless compute | Supported, if serverless egress allows `api.kyberis.ai`. See [Network requirements](/integrations/databricks/network). |

## 1. Databricks Marketplace

Kyberis Threat Intelligence for Databricks is listed on
[Databricks Marketplace](https://marketplace.databricks.com/details/3205ecb2-64eb-4baf-8207-b97cd90a18d4/Kyberis_Kyberis-Threat-Intelligence-for-Databricks).

1. Open the listing and select **Get instance access**.
2. Name the catalog when Databricks prompts you. The default is
   `kyberis_kyberis_threat_intelligence_for_databricks`; the rest of these steps
   use `<catalog>` for whatever you chose.
3. The wheel arrives in a shared volume at
   `/Volumes/<catalog>/kyberis/releases/`.

Install it on the cluster or job that will run your enrichment:

```python theme={null}
%pip install /Volumes/<catalog>/kyberis/releases/kyberis_databricks-1.0.0-py3-none-any.whl
dbutils.library.restartPython()
```

The wheel is code only: the `kyberis_databricks` helper package and the vendored
`kyberis_core` client, both dependency-free, so there is nothing else to install.
The example notebooks are attached to the Marketplace listing itself, and the
Databricks App source comes from the Git folder below.

Then set up credentials per
[Credential setup](/integrations/databricks/credentials).

## 2. Git folder and notebooks

1. In your workspace, go to **Workspace → Create → Git folder** and use the URL
   `https://github.com/kyberis-ai/kyberis-databricks.git`.
2. Set up credentials per
   [Credential setup](/integrations/databricks/credentials).
3. Open `notebooks/01_ioc_batch_enrichment.py`, attach any DBR 13.3+ cluster,
   fill in the widgets, and run. The notebooks import `src/` and `vendor/` from
   the Git folder — nothing to install.

## 3. Databricks App

The repository root is the app source root, since `app.yaml` lives there.

```bash theme={null}
# one-time: create the app
databricks apps create kyberis-threat-intelligence

# deploy from a workspace copy of the repository
databricks sync . /Workspace/Users/<you>/kyberis-databricks
databricks apps deploy kyberis-threat-intelligence \
  --source-code-path /Workspace/Users/<you>/kyberis-databricks
```

Before the first deploy, add the two secret resources the app expects, under
**Compute → Apps → kyberis-threat-intelligence → Edit → Resources**:

| Resource key | Points at |
| - | - |
| `kyberis-api-key-id` | Secret scope `kyberis`, key `kyberis-api-key-id` |
| `kyberis-api-key-secret` | Secret scope `kyberis`, key `kyberis-api-key-secret` |

Grant analysts **Can use** on the app, from the **Permissions** tab. The app's
service principal needs **READ** on the secret scope; Databricks configures that
automatically when the secret resources are added. See
[Credential setup](/integrations/databricks/credentials) and
[Permissions](/integrations/databricks/permissions).

### Upgrading

Pull the Git folder, or re-run `databricks sync` followed by
`databricks apps deploy`. The version is tracked in `pyproject.toml` and
`kyberis_databricks.__version__`.

## Build the wheel from source

If you would rather not consume the Marketplace share — an air-gapped workspace,
or a build you want to audit first — build the same wheel from a clone of
[`kyberis-ai/kyberis-databricks`](https://github.com/kyberis-ai/kyberis-databricks):

```bash theme={null}
make wheel   # builds dist/kyberis_databricks-<version>-py3-none-any.whl
```

Upload it as a job or cluster library, or to a Unity Catalog volume of your own,
then `%pip install` it by path.

## Local development

```bash theme={null}
make test                      # hermetic pytest suite
uv run --group dev --with 'streamlit>=1.38,<2' \
  streamlit run app/app.py     # run the app locally
```

Export `KYBERIS_API_KEY_ID`, `KYBERIS_API_KEY_SECRET`, and optionally
`KYBERIS_API_BASE_URL` before running the app locally.
