gcp-serviceaccounts-private-key-create-output

A newly generated user-managed service-account private key is returned only by the create response.

gcpcritical service: gcp:serviceaccounts emits ExposesCredential

Where it sits

locationiam.projects.serviceAccounts.keys.create.privateKeyData
location kindoutput_value
data kindsprivate_key credential
emits edgeExposesCredential
serviceService Accounts (gcp:serviceaccounts)

Collection recipe

access modecreation_response_only
operationiam.projects.serviceAccounts.keys.create
response pathprivateKeyData
encodingbase64
params{"name": "\u003cresource-name\u003e"}

Required permissions

iam.serviceAccountKeys.create

References

move · open · esc close