CanDeploy

Source can deploy new workloads to a platform (then attach identity).

execution EXECUTION nature: explicit walkable weight 1
Identity  ── CanDeploy ──▸  Compute, ContainerService, KubernetesCluster, ApplicationPlatform

Source types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit CanDeploy 7

StartDeployment redeploys latest source/image (realizes poisoned code / auto-deploy).
awsderived
CreateService deploys a new App Runner workload (attacker code/image).
awsderived
Principal with codepipeline:CreatePipeline can deploy new pipelines to the CodePipeline platform.
awsderived
azurederived
The Cloud Deploy execution SA's GKE deployment permissions (container.developer) give it CanDeploy to a GKE cluster.
gcpderived
The Cloud Deploy execution SA's Cloud Run deployment permissions (run.developer) give it CanDeploy to a Cloud Run service.
gcpderived
move · open · esc close