Description
When lifetime_seconds is omitted from databricks_token, the token uses the maximum lifetime allowed by the workspace or platform. That period may be longer than the task requires.
Potential impact
A leaked token can be used with the user’s permissions until it expires or is revoked.
Remediation
Specify the required duration with lifetime_seconds and replace the token in consuming systems before expiry. An expiry setting alone does not issue replacement tokens automatically.
Examples
The revised example uses 8,640,000 seconds, or 100 days. Choose the duration you need within workspace limits instead of adopting the example value unchanged. Provider configuration is omitted.
Before
hcl
resource "databricks_token" "example" {
provider = databricks.created_workspace
comment = "Terraform Provisioning"
}
After
hcl
resource "databricks_token" "example" {
provider = databricks.created_workspace
comment = "Terraform Provisioning"
lifetime_seconds = 8640000
}