gcp-batch-private-registry-password

A private-registry password supplied as plaintext is retained in the Batch job and exposed to users who can view the job or its logs.

gcpcritical service: gcp:batch emits CanReadCredential

Where it sits

locationbatch.projects.locations.jobs.get.taskGroups[].taskSpec.runnables[].container.password
location kindsecret_value
data kindspassword credential
emits edgeCanReadCredential
serviceBatch (gcp:batch)

Collection recipe

access moderead_api
operationbatch.projects.locations.jobs.get
response pathtaskGroups[].taskSpec.runnables[].container.password
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

batch.jobs.get

References

move · open · esc close