aws-imagebuilder-workflow-document-data

Image Builder workflow YAML can include command parameters and literals containing secrets.

awscritical service: aws:imagebuilder emits ContainsCredential

Where it sits

locationGetWorkflow.workflow.data
location kindtemplate_document
data kindscredential password api_key source_code_secret
emits edgeContainsCredential
serviceEC2 Image Builder (aws:imagebuilder)

Collection recipe

access moderead_api
operationGetWorkflow
response pathworkflow.data
encodingyaml
params{"workflowBuildVersionArn": "\u003cworkflow-version-arn\u003e"}

Required permissions

imagebuilder:GetWorkflow

References

move · open · esc close