azure-cosmosdb-non-sql-api-records

Cosmos DB non-SQL APIs store arbitrary records that can include credentials, PII, and customer data. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.

azurecritical service: azure:cosmosdb emits CanReadData

Where it sits

locationCosmos DB MongoDB documents, Cassandra rows, Gremlin vertices/edges, or Table entities
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceCosmos DB (azure:cosmosdb)

Collection recipe

access modedata_plane
operationMongoDB/CQL/Gremlin/Table data-plane read
response pathresult records
encodingprotocol_native
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close