gcp-cloudarmor-rule-expression

Cloud Armor CEL expressions can include sensitive hostnames, paths, identifiers, or literal values.

gcphigh service: gcp:cloudarmor emits ContainsSecret

Where it sits

locationcompute.securityPolicies.get.rules[].match.expr.expression
location kindpolicy_document
data kindscredential api_key sensitive_data pii
emits edgeContainsSecret
serviceCloud Armor (gcp:cloudarmor)

Collection recipe

access moderead_api
operationcompute.securityPolicies.get
response pathrules[].match.expr.expression
encodingstring
params{"project": "\u003cproject\u003e", "securityPolicy": "\u003cpolicy\u003e"}

Required permissions

compute.securityPolicies.get

References

move · open · esc close