aws-documentdb-master-password-write-input

DocumentDB master passwords are write-only plaintext API inputs.

awscritical service: aws:documentdb emits ContainsCredential

Where it sits

locationCreateDBCluster.MasterUserPassword / ModifyDBCluster.MasterUserPassword
location kindsecret_value
data kindspassword database_credential credential
emits edgeContainsCredential
serviceDocumentDB (aws:documentdb)

Collection recipe

access modewrite_only_input
operationCreateDBCluster/ModifyDBCluster
response pathrequest.MasterUserPassword
encodingstring
params{"DBClusterIdentifier": "\u003ccluster-id\u003e"}

Required permissions

rds:CreateDBCluster
rds:ModifyDBCluster

References

move · open · esc close