Beta - Databricks OBO token has indefinite lifetime
This product is not supported for your selected
Datadog site. (
).
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Id: 23e1f5f0-12b7-4d7e-9087-f60f42ccd514
Cloud Provider: Databricks
Platform: Terraform
Severity: Medium
Category: Insecure Defaults
Learn More
Description
databricks_obo_token has an indefinite lifetime.
OBO tokens must include a lifetime_seconds attribute to enforce a finite validity period.
This rule flags any databricks_obo_token resource that does not set lifetime_seconds.
Compliant Code Examples
resource "databricks_obo_token" "negative" {
depends_on = [databricks_group_member.this]
application_id = databricks_service_principal.this.application_id
comment = "PAT on behalf of ${databricks_service_principal.this.display_name}"
lifetime_seconds = 3600
}
Non-Compliant Code Examples
resource "databricks_obo_token" "positive" {
depends_on = [databricks_group_member.this]
application_id = databricks_service_principal.this.application_id
comment = "PAT on behalf of ${databricks_service_principal.this.display_name}"
}