gcp-secretmanager-managed-rotation-cloudsql-password-input

The managed-rotation request can carry a Cloud SQL user's plaintext password; the official method currently documents OAuth scopes but no IAM permission action.

gcpcritical service: gcp:secretmanager emits ContainsCredential

Where it sits

locationsecretmanager.projects.secrets.enableManagedRotation/secretmanager.projects.locations.secrets.enableManagedRotation.request.cloudSqlSingleUserCredentials.password
location kindsecret_value
data kindspassword database_credential credential
emits edgeContainsCredential
serviceSecret Manager (gcp:secretmanager)

Collection recipe

access modewrite_only_input
operationsecretmanager.projects.secrets.enableManagedRotation/secretmanager.projects.locations.secrets.enableManagedRotation
response pathrequest.cloudSqlSingleUserCredentials.password
encodingstring
params{"name": "\u003cresource-name\u003e"}

References

move · open · esc close