gcp-gke-workload-command-arguments

Container command and argument arrays may contain inline secrets.

gcphigh service: gcp:gke emits ContainsCredential

Where it sits

locationKubernetes workload GET/LIST.PodSpec.containers[].{command[],args[]}
location kindcommand_argument
data kindscredential password api_key access_key secret_key oauth_token sensitive_data
emits edgeContainsCredential
serviceGKE (gcp:gke)

Collection recipe

access modedata_plane
operationKubernetes workload GET/LIST
response pathPodSpec.containers[].{command[],args[]}
encodingjson
params{"name": "\u003cresource-name\u003e"}

Required permissions

container.clusters.get

References

move · open · esc close