azure-arm-deployments-deployment-script-secure-environment-input

Deployment Script secure environment values are plaintext request inputs omitted from GET responses.

azurecritical service: azure:arm-deployments emits ContainsSecret

Where it sits

locationMicrosoft.Resources/deploymentScripts.properties.environmentVariables[].secureValue
location kindsecret_value
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceARM/Bicep Deployments (azure:arm-deployments)

Collection recipe

access modewrite_only_input
operationDeployment Scripts - Create Or Update
response pathrequest.properties.environmentVariables[].secureValue
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Resources/deploymentScripts/write

References

move · open · esc close