aws-emr-step-command-arguments

EMR step arguments and properties can contain plaintext credentials passed to Spark, Hadoop, or custom JARs.

awscritical service: aws:emr emits ContainsCredential

Where it sits

locationDescribeStep.Step.Config.Args / Properties
location kindcommand_argument
data kindscredential password api_key access_key secret_key connection_string
emits edgeContainsCredential
serviceEMR (aws:emr)

Collection recipe

access moderead_api
operationDescribeStep
response pathStep.Config.{Args,Properties}
encodingjson
params{"ClusterId": "\u003ccluster-id\u003e", "StepId": "\u003cstep-id\u003e"}

Required permissions

elasticmapreduce:DescribeStep

References

move · open · esc close