azure-batch-pool-start-task

Pool start-task commands, environment settings, and resource URLs can expose credentials on every node.

azurecritical service: azure:batch emits ContainsSecret

Where it sits

locationBatch Pool.startTask.{commandLine,environmentSettings,resourceFiles}
location kindbootstrap_script
data kindscredential password api_key access_key secret_key oauth_token connection_string source_code_secret
emits edgeContainsSecret
serviceAzure Batch (azure:batch)

Collection recipe

access modedata_plane
operationPool - Get
response pathstartTask
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Batch/batchAccounts/pools/read

References

move · open · esc close