azure-appservice-deployment-source-artifacts

Deployed application files and configuration may contain hard-coded secrets. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:appservice emits ContainsSecret

Where it sits

locationSCM/Kudu /api/vfs and deployment repository file content
location kindcode_artifact
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceApp Service / Web Apps (azure:appservice)

Collection recipe

access modedata_plane
operationKudu VFS API GET
response path$value
encodingbinary
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close