Databricks OBO token lifetime is unspecified

Limit the lifetime of Databricks tokens issued on behalf of service principals.

Description

databricks_obo_token creates a personal access token on behalf of a service principal. Without lifetime_seconds, the intended lifetime is unspecified and the token may remain valid for a long period, subject to applicable service policies.

Potential impact

A leaked token can be used with the service principal’s permissions until it expires or is revoked.

Remediation

Set lifetime_seconds to fit the required task duration and workspace policy. Arrange replacement and delivery to consuming systems before expiry. Setting a lifetime alone does not rotate tokens across those systems.

Examples

The revised example sets a lifetime of 3,600 seconds (one hour). Service principal and group configuration are omitted.

Before

hcl
resource "databricks_obo_token" "example" {
  depends_on     = [databricks_group_member.this]
  application_id = databricks_service_principal.this.application_id
  comment        = "PAT on behalf of ${databricks_service_principal.this.display_name}"
}

After

hcl
resource "databricks_obo_token" "example" {
  depends_on       = [databricks_group_member.this]
  application_id   = databricks_service_principal.this.application_id
  comment          = "PAT on behalf of ${databricks_service_principal.this.display_name}"
  lifetime_seconds = 3600
}

References