azure-aks-kubernetes-labels-annotations

Kubernetes labels and especially annotations are plaintext maps that can contain tokens, identities, or sensitive operator data.

azurehigh service: azure:aks emits ContainsSecret

Where it sits

locationKubernetes ObjectMeta.{labels,annotations}
location kindmetadata
data kindscredential api_key sensitive_data pii
emits edgeContainsSecret
serviceAKS (azure:aks)

Collection recipe

access modedata_plane
operationKubernetes GET object
response pathmetadata.{labels,annotations}
encodingmap
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.ContainerService/managedClusters/apps/deployments/read

References

move · open · esc close