aws-appmesh-route-header-match-values

Customer-authored HTTP header match values can accidentally contain bearer tokens, API keys, or confidential routing values.

awshigh service: aws:appmesh emits ContainsSecret

Where it sits

locationDescribeRoute.route.spec.httpRoute.match.headers[].match.{exact,prefix,regex,suffix}
location kindconfig_field
data kindscredential api_key bearer_token sensitive_data
emits edgeContainsSecret
serviceApp Mesh (aws:appmesh)

Collection recipe

access moderead_api
operationDescribeRoute
response pathroute.spec.httpRoute.match.headers[].match
encodingjson
params{"meshName": "\u003cmesh\u003e", "routeName": "\u003croute\u003e", "virtualRouterName": "\u003crouter\u003e"}

Required permissions

appmesh:DescribeRoute

References

move · open · esc close