aws-ecs-task-definition-docker-label-value

Docker label maps are customer-controlled plaintext and may contain build metadata, endpoints, or misplaced credentials.

awshigh service: aws:ecs emits ContainsCredential

Where it sits

locationDescribeTaskDefinition.taskDefinition.containerDefinitions[].dockerLabels.<value>
location kindmetadata
data kindscredential password api_key connection_string sensitive_data
emits edgeContainsCredential
serviceECS/Fargate (aws:ecs)

Collection recipe

access moderead_api
operationDescribeTaskDefinition
response pathtaskDefinition.containerDefinitions[].dockerLabels.<value>
encodingmap
params{"taskDefinition": "\u003cfamily:revision-or-arn\u003e"}

Required permissions

ecs:DescribeTaskDefinition

References

move · open · esc close