CanDeploy
Source can deploy new workloads to a platform (then attach identity).
Identity
── CanDeploy ──▸
Compute, ContainerService, KubernetesCluster, ApplicationPlatform
Source types
IdentityTarget types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Rules that emit CanDeploy 7
StartDeployment redeploys latest source/image (realizes poisoned code / auto-deploy).
awsderived
CreateService deploys a new App Runner workload (attacker code/image).
awsderived
awsderived
Principal with codepipeline:CreatePipeline can deploy new pipelines to the CodePipeline platform.
awsderived
azurederived
The Cloud Deploy execution SA's GKE deployment permissions (container.developer) give it CanDeploy to a GKE cluster.
gcpderived
The Cloud Deploy execution SA's Cloud Run deployment permissions (run.developer) give it CanDeploy to a Cloud Run service.
gcpderived