CredentialsFor
This secret/credential authenticates as the target. Zero-cost link completing credential chains.
Secret, Credential, AccessKey, Token, Certificate
── CredentialsFor ──▸
Identity, Data, ServiceIdentity
Source types
Target types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Rules that emit CredentialsFor 16
An exported ACM private key authenticates as the certificate's DNS/TLS server identity.
awsderived
A CA-issued certificate authenticates as the downstream identity a trust consumer maps it to.
awsderived
An AppFlow connector profile's stored credential (OAuth token / API key) authenticates to the external SaaS system - reading the Secrets Manager secret yields a usable credential for that SaaS identity.
awsderived
A Lightsail bucket access key authenticates to the bucket's data plane.
awsderived
A SecureString parameter's value authenticates as the target identity/service.
awsderived
An IMDS bearer token minted from a host+MI pair is valid authentication as that MI.
azurederived
A cert signed by the CA authenticates as the subject/SAN it names to a consuming trust.
gcpderived
A CMEK-encrypted Secret Manager payload authenticates as another identity, completing CanExecuteAs -> CanReadSecret -> CredentialsFor.
gcpderived
The secret's payload authenticates as another identity / service account / data store.
gcpderived
awsexplicit
awsexplicit
awsexplicit
awsexplicit
azureexplicit
azureexplicit
gcpexplicit