aws-controltower-landing-zone-manifest-config

The landing-zone manifest is customer-controlled JSON and can carry account emails, identifiers, or accidental secrets.

awshigh service: aws:controltower emits ContainsSecret

Where it sits

locationGetLandingZone.landingZone.manifest
location kindconfig_field
data kindssensitive_data pii credential
emits edgeContainsSecret
serviceControl Tower (aws:controltower)

Collection recipe

access moderead_api
operationGetLandingZone
response pathlandingZone.manifest
encodingjson
params{"landingZoneIdentifier": "\u003clanding-zone-id\u003e"}

Required permissions

controltower:GetLandingZone

References

move · open · esc close