gcp-vertexai-custom-job-environment

Vertex AI custom-job container environment values can persist literal credentials.

gcpcritical service: gcp:vertexai emits ContainsCredential

Where it sits

locationaiplatform.projects.locations.customJobs.get.jobSpec.workerPoolSpecs[].containerSpec.env[].value
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsCredential
serviceVertex AI / Workbench (gcp:vertexai)

Collection recipe

access moderead_api
operationaiplatform.projects.locations.customJobs.get
response pathjobSpec.workerPoolSpecs[].containerSpec.env[].value
encodinglist
params{"name": "\u003cresource-name\u003e"}

Required permissions

aiplatform.customJobs.get

References

move · open · esc close