gcp-composer-environment-bucket-content

The Composer bucket holds executable DAGs, plugins, data, and logs that may contain credentials.

gcpcritical service: gcp:composer emits CanReadData

Where it sits

locationcomposer.projects.locations.environments.get.config.dagGcsPrefix/storageConfig.bucket -> DAG, plugin, data, and log object bytes
location kindcode_artifact
data kindssource_code_secret credential password api_key private_key customer_data
emits edgeCanReadData
serviceCloud Composer (Airflow) (gcp:composer)

Collection recipe

access modeindirect_destination
operationcomposer.projects.locations.environments.get
response pathconfig.dagGcsPrefix/storageConfig.bucket -> DAG, plugin, data, and log object bytes
encodingbinary
params{"name": "\u003cresource-name\u003e"}

Required permissions

composer.environments.get
storage.objects.get

References

move · open · esc close