gcp-gcf-runtime-environment-variables

Cloud Functions configuration returns this customer-controlled plaintext field to authorized readers.

gcpcritical service: gcp:gcf emits ContainsCredential

Where it sits

locationcloudfunctions.projects.locations.functions.get.serviceConfig.environmentVariables.<value>
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsCredential
serviceCloud Functions (gcp:gcf)

Collection recipe

access moderead_api
operationcloudfunctions.projects.locations.functions.get
response pathserviceConfig.environmentVariables.<value>
encodingmap
params{"name": "\u003cresource-name\u003e"}

Required permissions

cloudfunctions.functions.get

References

move · open · esc close