azure-aks-pod-logs
Pod logs can reveal authorization headers, environment values, request bodies, and customer data.
Where it sits
| location | Kubernetes Pod log stream |
| location kind | log_field |
| data kinds | credential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data |
| emits edge | ContainsSecret |
| service | AKS (azure:aks) |
Collection recipe
| access mode | data_plane |
| operation | Kubernetes GET pod/log |
| response path | $value |
| encoding | string |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
Required permissions
Microsoft.ContainerService/managedClusters/pods/log/read
References