gcp-cloudrun-worker-pool-literal-environment-values

Cloud Run worker-pool environment variables can contain literal credentials instead of secret references.

gcpcritical service: gcp:cloudrun emits ContainsCredential

Where it sits

locationrun.projects.locations.workerPools.get.template.containers[].env[].value
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsCredential
serviceCloud Run (gcp:cloudrun)

Collection recipe

access moderead_api
operationrun.projects.locations.workerPools.get
response pathtemplate.containers[].env[].value
encodinglist
params{"name": "\u003cresource-name\u003e"}

Required permissions

run.workerpools.get

References

move · open · esc close