aws-opsworks-deployment-command-args

Deployment command argument maps can contain plaintext credentials delivered to recipes.

awscritical service: aws:opsworks emits ContainsCredential

Where it sits

locationDescribeDeployments.Deployments[].Command.Args.<value>
location kindcommand_argument
data kindscredential password api_key connection_string
emits edgeContainsCredential
serviceOpsWorks (aws:opsworks)

Collection recipe

access moderead_api
operationDescribeDeployments
response pathDeployments[].Command.Args.<value>
encodingmap
params{"DeploymentIds": ["\u003cdeployment-id\u003e"]}

Required permissions

opsworks:DescribeDeployments

References

move · open · esc close