gcp-vertexai-custom-job-python-package-environment

Vertex AI Python-package custom jobs can persist literal credentials in their environment values.

gcpcritical service: gcp:vertexai emits ContainsCredential

Where it sits

locationaiplatform.projects.locations.customJobs.get.jobSpec.workerPoolSpecs[].pythonPackageSpec.env[].value
location kindenvironment_variable
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsCredential
serviceVertex AI / Workbench (gcp:vertexai)

Collection recipe

access moderead_api
operationaiplatform.projects.locations.customJobs.get
response pathjobSpec.workerPoolSpecs[].pythonPackageSpec.env[].value
encodinglist
params{"name": "\u003cresource-name\u003e"}

Required permissions

aiplatform.customJobs.get

References

move · open · esc close