gcp-wif-workforce-provider-oidc-secret-input
Workforce pool OIDC provider create and update requests can carry an input-only plaintext client secret.
Where it sits
| location | iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch.request.oidc.clientSecret.value.plainText |
|---|---|
| location kind | secret_value |
| data kinds | oauth_token secret_key credential |
| emits edge | ContainsCredential |
| service | Workload Identity Federation (gcp:wif) |
Collection recipe
| access mode | write_only_input |
|---|---|
| operation | iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch |
| response path | request.oidc.clientSecret.value.plainText |
| encoding | string |
| params | {"name": "\u003cresource-name\u003e"} |
Required permissions
iam.googleapis.com/workforcePoolProviders.create iam.googleapis.com/workforcePoolProviders.update