gcp-datastream-connection-profile-password-input

Datastream connection-profile create and update requests carry source database passwords that are not returned on read.

gcpcritical service: gcp:datastream emits ContainsCredential

Where it sits

locationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch.request.{mysqlProfile.password,postgresqlProfile.password,oracleProfile.password,oracleProfile.oracleAsmConfig.password,sqlServerProfile.password,mongodbProfile.password}
location kindsecret_value
data kindspassword database_credential credential
emits edgeContainsCredential
serviceDatastream / Data Fusion (gcp:datastream)

Collection recipe

access modewrite_only_input
operationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch
response pathrequest.{mysqlProfile.password,postgresqlProfile.password,oracleProfile.password,oracleProfile.oracleAsmConfig.password,sqlServerProfile.password,mongodbProfile.password}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

datastream.connectionProfiles.create
datastream.connectionProfiles.update

References

move · open · esc close