gcp-datastream-connection-profile-tls-client-key-input

Database TLS configuration can carry PEM client private keys in connection-profile create and update requests.

gcpcritical service: gcp:datastream emits ContainsCredential

Where it sits

locationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch.request.{mysqlProfile.sslConfig.clientKey,postgresqlProfile.sslConfig.serverAndClientVerification.clientKey,mongodbProfile.sslConfig.clientKey}
location kindsecret_value
data kindsprivate_key database_credential credential
emits edgeContainsCredential
serviceDatastream / Data Fusion (gcp:datastream)

Collection recipe

access modewrite_only_input
operationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch
response pathrequest.{mysqlProfile.sslConfig.clientKey,postgresqlProfile.sslConfig.serverAndClientVerification.clientKey,mongodbProfile.sslConfig.clientKey}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

datastream.connectionProfiles.create
datastream.connectionProfiles.update

References

move · open · esc close