azure-aks-pod-logs

Pod logs can reveal authorization headers, environment values, request bodies, and customer data.

azurehigh service: azure:aks emits ContainsSecret

Where it sits

locationKubernetes Pod log stream
location kindlog_field
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceAKS (azure:aks)

Collection recipe

access modedata_plane
operationKubernetes GET pod/log
response path$value
encodingstring
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.ContainerService/managedClusters/pods/log/read

References

move · open · esc close