azure-aks-run-command-output

AKS run-command output may echo Kubernetes objects, command arguments, secrets, or customer data.

azurecritical service: azure:aks emits ContainsSecret

Where it sits

locationMicrosoft.ContainerService/managedClusters/runCommand response.{logs,exitCode}
location kindoutput_value
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeContainsSecret
serviceAKS (azure:aks)

Collection recipe

access moderead_api
operationManaged Clusters - Run Command
response path{logs,exitCode}
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.ContainerService/managedClusters/runCommand/action

References

move · open · esc close