gcp-wif-workforce-extra-attributes-secret-input
Workforce extra-attribute retrieval configuration can carry an input-only OAuth client secret.
Where it sits
| location | iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch.request.{extendedAttributesOauth2Client,extraAttributesOauth2Client}.clientSecret.value.plainText |
|---|---|
| location kind | secret_value |
| data kinds | oauth_token secret_key credential |
| emits edge | ContainsCredential |
| service | Workload Identity Federation (gcp:wif) |
Collection recipe
| access mode | write_only_input |
|---|---|
| operation | iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch |
| response path | request.{extendedAttributesOauth2Client,extraAttributesOauth2Client}.clientSecret.value.plainText |
| encoding | json |
| params | {"name": "\u003cresource-name\u003e"} |
Required permissions
iam.googleapis.com/workforcePoolProviders.create iam.googleapis.com/workforcePoolProviders.update