azure-postgres-mysql-database-query-results
Database rows can contain arbitrary credentials, personal information, and customer data. No single Azure RBAC action authorizes this service-native path; its own authentication and authorization apply.
azurecritical
service: azure:postgres-mysql
emits CanReadData
Where it sits
| location | PostgreSQL/MySQL protocol query result rows |
| location kind | data_record |
| data kinds | database_credential sensitive_data pii customer_data credential password api_key access_key secret_key oauth_token connection_string |
| emits edge | CanReadData |
| service | DB for PostgreSQL/MySQL (azure:postgres-mysql) |
Collection recipe
| access mode | data_plane |
| operation | SQL SELECT over PostgreSQL or MySQL protocol |
| response path | result rows |
| encoding | protocol_native |
| params | {"resource_id": "\u003cazure-resource-id\u003e"} |
References