azure-databricks-global-init-script-content

Global init scripts run on every cluster and may hard-code credentials or download URLs with tokens. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:databricks emits ContainsSecret

Where it sits

locationDatabricks global init script response.script
location kindbootstrap_script
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceAzure Databricks (azure:databricks)

Collection recipe

access modedata_plane
operationGET /api/2.0/global-init-scripts/{script_id}
response pathscript
encodingbase64
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close