gcp-datastream-connection-profile-username-endpoint

Readable connection profiles expose database usernames, hosts, and database identifiers while passwords are redacted.

gcphigh service: gcp:datastream emits ContainsCredential

Where it sits

locationdatastream.projects.locations.connectionProfiles.get.{mysqlProfile,postgresqlProfile,oracleProfile,sqlServerProfile,mongodbProfile}.{hostname,username,database}
location kindconnection_string
data kindsdatabase_credential pii sensitive_data
emits edgeContainsCredential
serviceDatastream / Data Fusion (gcp:datastream)

Collection recipe

access moderead_api
operationdatastream.projects.locations.connectionProfiles.get
response path{mysqlProfile,postgresqlProfile,oracleProfile,sqlServerProfile,mongodbProfile}.{hostname,username,database}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

datastream.connectionProfiles.get

References

move · open · esc close