gcp-appengine-authorized-certificate-private-key-input

An App Engine authorized-certificate request can carry an unencrypted PEM private key that is input-only after creation.

gcpcritical service: gcp:appengine emits ContainsCredential

Where it sits

locationappengine.apps.authorizedCertificates.create/appengine.apps.authorizedCertificates.patch.request.certificateRawData.privateKey
location kindsecret_value
data kindsprivate_key credential
emits edgeContainsCredential
serviceApp Engine (gcp:appengine)

Collection recipe

access modewrite_only_input
operationappengine.apps.authorizedCertificates.create/appengine.apps.authorizedCertificates.patch
response pathrequest.certificateRawData.privateKey
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

appengine.applications.update

References

move · open · esc close