aws-controltower-landing-zone-manifest-config
The landing-zone manifest is customer-controlled JSON and can carry account emails, identifiers, or accidental secrets.
Where it sits
| location | GetLandingZone.landingZone.manifest |
|---|---|
| location kind | config_field |
| data kinds | sensitive_data pii credential |
| emits edge | ContainsSecret |
| service | Control Tower (aws:controltower) |
Collection recipe
| access mode | read_api |
|---|---|
| operation | GetLandingZone |
| response path | landingZone.manifest |
| encoding | json |
| params | {"landingZoneIdentifier": "\u003clanding-zone-id\u003e"} |
Required permissions
controltower:GetLandingZone