Description
databricks_obo_token creates a personal access token on behalf of a service principal. Without lifetime_seconds, the intended lifetime is unspecified and the token may remain valid for a long period, subject to applicable service policies.
Potential impact
A leaked token can be used with the service principal’s permissions until it expires or is revoked.
Remediation
Set lifetime_seconds to fit the required task duration and workspace policy. Arrange replacement and delivery to consuming systems before expiry. Setting a lifetime alone does not rotate tokens across those systems.
Examples
The revised example sets a lifetime of 3,600 seconds (one hour). Service principal and group configuration are omitted.
Before
resource "databricks_obo_token" "example" {
depends_on = [databricks_group_member.this]
application_id = databricks_service_principal.this.application_id
comment = "PAT on behalf of ${databricks_service_principal.this.display_name}"
}
After
resource "databricks_obo_token" "example" {
depends_on = [databricks_group_member.this]
application_id = databricks_service_principal.this.application_id
comment = "PAT on behalf of ${databricks_service_principal.this.display_name}"
lifetime_seconds = 3600
}