Databricks personal access token lifetime is unspecified

Limit Databricks personal access tokens to the time needed for their purpose.

Description

When lifetime_seconds is omitted from databricks_token, the token uses the maximum lifetime allowed by the workspace or platform. That period may be longer than the task requires.

Potential impact

A leaked token can be used with the user’s permissions until it expires or is revoked.

Remediation

Specify the required duration with lifetime_seconds and replace the token in consuming systems before expiry. An expiry setting alone does not issue replacement tokens automatically.

Examples

The revised example uses 8,640,000 seconds, or 100 days. Choose the duration you need within workspace limits instead of adopting the example value unchanged. Provider configuration is omitted.

Before

hcl
resource "databricks_token" "example" {
  provider = databricks.created_workspace
  comment  = "Terraform Provisioning"
}

After

hcl
resource "databricks_token" "example" {
  provider         = databricks.created_workspace
  comment          = "Terraform Provisioning"
  lifetime_seconds = 8640000
}

References