services / Google Cloud / Cloud Run Services

A Cloud Run service continuously runs code that responds to web requests or events. It will automatically scale the number of instances to match incoming requests.

Cloud Run services may be used to run core organizational infrastructure, such as web applications or REST APIs.


run.​services.​createTagBinding

A common use case of tag bindings is for use in IAM policy conditions. The risks apply if the tag is used in any policies.

Risks

Scope: HIGH

This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.

Links

  • https:​/​/​cloud.​google.​com/​run/​docs/​resource-​model
  • https:​/​/​cloud.​google.​com/​run/​docs/​deploying
  • https:​/​/​cloud.​google.​com/​run/​docs/​managing/​services
  • https:​/​/​cloud.​google.​com/​run/​docs/​reference/​rest/​v1/​namespaces.​services
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog