last sync: 2025-Oct-30 18:22:48 UTC

Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters

Azure BuiltIn RBAC Role definition

NameAzure Kubernetes Fleet Manager RBAC Writer for Member Clusters
Id50346970-0998-40f2-b47d-f3b8809840f8
DescriptionAllows read/write access to most objects in a namespace. This role does not allow viewing or modifying roles or role bindings. However, this role allows accessing Secrets and running Pods as any ServiceAccount in the namespace, so it can be used to gain the API access levels of any ServiceAccount in the namespace. Applying this role at cluster scope will give access across all namespaces.
CategoryNone
CreatedOn2025-10-22 18:33:37 UTC
UpdatedOn2025-10-22 18:33:37 UTC
Permissions summary Effective control plane and data plane operations: 119 (unique operations)
•action: 2
•delete: 25
•read: 67
•write: 25

Actions: 4
Resolved control plane operations from Actions: 34
Effective control plane operations: 34
•read: 34

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 17431

DataActions: 35
Resolved data plane operations: 85
Effective data plane operations: 85
•action: 2
•delete: 25
•read: 33
•write: 25

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3996
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
NotActions n/a
DataActions
Operation Description
Microsoft.ContainerService/fleets/members/apps/controllerrevisions/readReads controllerrevisions
Microsoft.ContainerService/fleets/members/apps/daemonsets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/apps/deployments/*wildcarded / no description
Microsoft.ContainerService/fleets/members/apps/replicasets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/apps/statefulsets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/autoscaling/horizontalpodautoscalers/*wildcarded / no description
Microsoft.ContainerService/fleets/members/batch/cronjobs/*wildcarded / no description
Microsoft.ContainerService/fleets/members/batch/jobs/*wildcarded / no description
Microsoft.ContainerService/fleets/members/configmaps/*wildcarded / no description
Microsoft.ContainerService/fleets/members/coordination.k8s.io/leases/deleteDeletes leases
Microsoft.ContainerService/fleets/members/coordination.k8s.io/leases/readReads leases
Microsoft.ContainerService/fleets/members/coordination.k8s.io/leases/writeWrites leases
Microsoft.ContainerService/fleets/members/discovery.k8s.io/endpointslices/readReads endpointslices
Microsoft.ContainerService/fleets/members/endpoints/*wildcarded / no description
Microsoft.ContainerService/fleets/members/events.k8s.io/events/readReads events
Microsoft.ContainerService/fleets/members/events/*wildcarded / no description
Microsoft.ContainerService/fleets/members/extensions/daemonsets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/extensions/deployments/*wildcarded / no description
Microsoft.ContainerService/fleets/members/extensions/ingresses/*wildcarded / no description
Microsoft.ContainerService/fleets/members/extensions/networkpolicies/*wildcarded / no description
Microsoft.ContainerService/fleets/members/extensions/replicasets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/limitranges/readReads limitranges
Microsoft.ContainerService/fleets/members/metrics.k8s.io/nodes/readReads nodes
Microsoft.ContainerService/fleets/members/metrics.k8s.io/pods/readReads pods
Microsoft.ContainerService/fleets/members/namespaces/readReads namespaces
Microsoft.ContainerService/fleets/members/networking.k8s.io/ingresses/*wildcarded / no description
Microsoft.ContainerService/fleets/members/networking.k8s.io/networkpolicies/*wildcarded / no description
Microsoft.ContainerService/fleets/members/persistentvolumeclaims/*wildcarded / no description
Microsoft.ContainerService/fleets/members/pods/*wildcarded / no description
Microsoft.ContainerService/fleets/members/policy/poddisruptionbudgets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/replicationcontrollers/*wildcarded / no description
Microsoft.ContainerService/fleets/members/resourcequotas/readReads resourcequotas
Microsoft.ContainerService/fleets/members/secrets/*wildcarded / no description
Microsoft.ContainerService/fleets/members/serviceaccounts/*wildcarded / no description
Microsoft.ContainerService/fleets/members/services/*wildcarded / no description
NotDataActions n/a
Used in
BuiltIn Policy
none
History
Date/Time (UTC ymd) (i) Change Change detail
2025-10-23 17:22:49 add: Role 50346970-0998-40f2-b47d-f3b8809840f8
JSON
api-version=2023-07-01-preview
Condition none