gcp-gcs-bucket-iam-members-condition

Bucket IAM policies expose principal identifiers and conditional expressions.

gcpmedium service: gcp:gcs emits ContainsSecret

Where it sits

locationstorage.buckets.getIamPolicy.bindings[].{members[],condition}
location kindpolicy_document
data kindspii sensitive_data
emits edgeContainsSecret
serviceCloud Storage (gcp:gcs)

Collection recipe

access moderead_api
operationstorage.buckets.getIamPolicy
response pathbindings[].{members[],condition}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

storage.buckets.getIamPolicy

References

move · open · esc close