aws-cloudformation-stack-event-status-reason

Provider errors and custom-resource responses can echo sensitive resource properties into stack event status reasons.

awshigh service: aws:cloudformation emits ContainsSecret

Where it sits

locationDescribeStackEvents.StackEvents[].ResourceStatusReason
location kindlog_field
data kindscredential password api_key sensitive_data
emits edgeContainsSecret
serviceCloudFormation (aws:cloudformation)

Collection recipe

access moderead_api
operationDescribeStackEvents
response pathStackEvents[].ResourceStatusReason
encodingstring
params{"StackName": "\u003cstack-name-or-id\u003e"}

Required permissions

cloudformation:DescribeStackEvents

References

move · open · esc close