azure-devops-secret-variable-job-materialization

Secret variables are unavailable to inventory reads but are materialized as plaintext for authorized pipeline tasks. No single Azure RBAC action authorizes the downstream destination; its own access control applies.

azurecritical service: azure:devops emits ContainsSecret

Where it sits

locationAzure Pipelines job environment/task input generated from variable marked isSecret=true
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceAzure DevOps (azure:devops)

Collection recipe

access modeindirect_destination
operationAzure Pipelines agent secret-variable materialization
response pathjob environment or task input
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

References

move · open · esc close