last sync: 2025-Oct-30 18:22:48 UTC

Azure Kubernetes Fleet Manager RBAC Reader for Member Clusters

Azure BuiltIn RBAC Role definition

NameAzure Kubernetes Fleet Manager RBAC Reader for Member Clusters
Id463ad26c-fcce-4469-9c7f-5653d8acbab5
DescriptionAllows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.
CategoryNone
CreatedOn2025-10-22 18:33:37 UTC
UpdatedOn2025-10-22 18:33:37 UTC
Permissions summary Effective control plane and data plane operations: 65 (unique operations)
•read: 65

Actions: 4
Resolved control plane operations from Actions: 34
Effective control plane operations: 34
•read: 34

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 17431

DataActions: 31
Resolved data plane operations: 31
Effective data plane operations: 31
•read: 31

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 4050
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
NotActions n/a
DataActions
Operation Description
Microsoft.ContainerService/fleets/members/apps/controllerrevisions/readReads controllerrevisions
Microsoft.ContainerService/fleets/members/apps/daemonsets/readReads daemonsets
Microsoft.ContainerService/fleets/members/apps/deployments/readReads deployments
Microsoft.ContainerService/fleets/members/apps/replicasets/readReads replicasets
Microsoft.ContainerService/fleets/members/apps/statefulsets/readReads statefulsets
Microsoft.ContainerService/fleets/members/autoscaling/horizontalpodautoscalers/readReads horizontalpodautoscalers
Microsoft.ContainerService/fleets/members/batch/cronjobs/readReads cronjobs
Microsoft.ContainerService/fleets/members/batch/jobs/readReads jobs
Microsoft.ContainerService/fleets/members/configmaps/readReads configmaps
Microsoft.ContainerService/fleets/members/discovery.k8s.io/endpointslices/readReads endpointslices
Microsoft.ContainerService/fleets/members/endpoints/readReads endpoints
Microsoft.ContainerService/fleets/members/events.k8s.io/events/readReads events
Microsoft.ContainerService/fleets/members/events/readReads events
Microsoft.ContainerService/fleets/members/extensions/daemonsets/readReads daemonsets
Microsoft.ContainerService/fleets/members/extensions/deployments/readReads deployments
Microsoft.ContainerService/fleets/members/extensions/ingresses/readReads ingresses
Microsoft.ContainerService/fleets/members/extensions/networkpolicies/readReads networkpolicies
Microsoft.ContainerService/fleets/members/extensions/replicasets/readReads replicasets
Microsoft.ContainerService/fleets/members/limitranges/readReads limitranges
Microsoft.ContainerService/fleets/members/metrics.k8s.io/nodes/readReads nodes
Microsoft.ContainerService/fleets/members/metrics.k8s.io/pods/readReads pods
Microsoft.ContainerService/fleets/members/namespaces/readReads namespaces
Microsoft.ContainerService/fleets/members/networking.k8s.io/ingresses/readReads ingresses
Microsoft.ContainerService/fleets/members/networking.k8s.io/networkpolicies/readReads networkpolicies
Microsoft.ContainerService/fleets/members/persistentvolumeclaims/readReads persistentvolumeclaims
Microsoft.ContainerService/fleets/members/pods/readReads pods
Microsoft.ContainerService/fleets/members/policy/poddisruptionbudgets/readReads poddisruptionbudgets
Microsoft.ContainerService/fleets/members/replicationcontrollers/readReads replicationcontrollers
Microsoft.ContainerService/fleets/members/resourcequotas/readReads resourcequotas
Microsoft.ContainerService/fleets/members/serviceaccounts/readReads serviceaccounts
Microsoft.ContainerService/fleets/members/services/readReads services
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-10-23 17:22:49 add: Role 463ad26c-fcce-4469-9c7f-5653d8acbab5
JSON
api-version=2023-07-01-preview
Condition none