azure-aks-workload-env-command

Direct pod environment values and command arguments can contain plaintext credentials.

azurecritical service: azure:aks emits ContainsSecret

Where it sits

locationKubernetes PodSpec.containers[].{env,command,args}
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceAKS (azure:aks)

Collection recipe

access modedata_plane
operationKubernetes GET workload resources
response pathspec.template.spec.containers[].{env,command,args}
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.ContainerService/managedClusters/apps/deployments/read

References

move · open · esc close