last sync: 2024-Mar-18 18:48:33 UTC

Azure Arc Kubernetes Viewer

Azure BuiltIn RBAC Role definition

NameAzure Arc Kubernetes Viewer
Id63f0a09d-1495-4db4-a681-037d84835eb4
DescriptionLets you view all resources in cluster/namespace, except secrets.
CreatedOn2020-06-12 20:51:12 UTC
UpdatedOn2021-11-11 20:14:33 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-11-03 14:38:31 change: DataActions, NotDataActions DataActions: 'remove Microsoft.Kubernetes/connectedClusters/*/read; add Microsoft.Kubernetes/connectedClusters/apps/controllerrevisions/read; add Microsoft.Kubernetes/connectedClusters/apps/daemonsets/read; add Microsoft.Kubernetes/connectedClusters/apps/deployments/read; add Microsoft.Kubernetes/connectedClusters/apps/replicasets/read; add Microsoft.Kubernetes/connectedClusters/apps/statefulsets/read; add Microsoft.Kubernetes/connectedClusters/autoscaling/horizontalpodautoscalers/read; add Microsoft.Kubernetes/connectedClusters/batch/cronjobs/read; add Microsoft.Kubernetes/connectedClusters/batch/jobs/read; add Microsoft.Kubernetes/connectedClusters/configmaps/read; add Microsoft.Kubernetes/connectedClusters/endpoints/read; add Microsoft.Kubernetes/connectedClusters/events.k8s.io/events/read; add Microsoft.Kubernetes/connectedClusters/events/read; add Microsoft.Kubernetes/connectedClusters/extensions/daemonsets/read; add Microsoft.Kubernetes/connectedClusters/extensions/deployments/read; add Microsoft.Kubernetes/connectedClusters/extensions/ingresses/read; add Microsoft.Kubernetes/connectedClusters/extensions/networkpolicies/read; add Microsoft.Kubernetes/connectedClusters/extensions/replicasets/read; add Microsoft.Kubernetes/connectedClusters/limitranges/read; add Microsoft.Kubernetes/connectedClusters/namespaces/read; add Microsoft.Kubernetes/connectedClusters/networking.k8s.io/ingresses/read; add Microsoft.Kubernetes/connectedClusters/networking.k8s.io/networkpolicies/read; add Microsoft.Kubernetes/connectedClusters/persistentvolumeclaims/read; add Microsoft.Kubernetes/connectedClusters/pods/read; add Microsoft.Kubernetes/connectedClusters/policy/poddisruptionbudgets/read; add Microsoft.Kubernetes/connectedClusters/replicationcontrollers/read; add Microsoft.Kubernetes/connectedClusters/replicationcontrollers/read; add Microsoft.Kubernetes/connectedClusters/resourcequotas/read; add Microsoft.Kubernetes/connectedClusters/serviceaccounts/read; add Microsoft.Kubernetes/connectedClusters/services/read',
NotDataActions: 'remove Microsoft.Kubernetes/connectedClusters/secrets/read; remove Microsoft.Kubernetes/connectedClusters/clusterconfig.azure.com/azureclusteridentityrequests/read'
2020-06-15 15:35:59 add: Role 63f0a09d-1495-4db4-a681-037d84835eb4
Permissions summary Effective control plane and data plane operations: 78 (unique operations)
•Action: 8
•Delete: 1
•read: 66
•Write: 3

Actions: 7
Resolved control plane operations from Actions: 50
Effective control plane operations: 50
•Action: 8
•Delete: 1
•read: 38
•Write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 15079

DataActions: 29
Resolved data plane operations: 28
Effective data plane operations: 28
•read: 28

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3067
Actions
Operation Description
Microsoft.Authorization/*/readwildcarded / no description
Microsoft.Insights/alertRules/*wildcarded / no description
Microsoft.Resources/deployments/writeCreates or updates an deployment.
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results.
Microsoft.Resources/subscriptions/readGets the list of subscriptions.
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups.
Microsoft.Support/*wildcarded / no description
NotActions n/a
DataActions
Operation Description
Microsoft.Kubernetes/connectedClusters/apps/controllerrevisions/readReads controllerrevisions
Microsoft.Kubernetes/connectedClusters/apps/daemonsets/readReads daemonsets
Microsoft.Kubernetes/connectedClusters/apps/deployments/readReads deployments
Microsoft.Kubernetes/connectedClusters/apps/replicasets/readReads replicasets
Microsoft.Kubernetes/connectedClusters/apps/statefulsets/readReads statefulsets
Microsoft.Kubernetes/connectedClusters/autoscaling/horizontalpodautoscalers/readReads horizontalpodautoscalers
Microsoft.Kubernetes/connectedClusters/batch/cronjobs/readReads cronjobs
Microsoft.Kubernetes/connectedClusters/batch/jobs/readReads jobs
Microsoft.Kubernetes/connectedClusters/configmaps/readReads configmaps
Microsoft.Kubernetes/connectedClusters/endpoints/readReads endpoints
Microsoft.Kubernetes/connectedClusters/events.k8s.io/events/readReads events
Microsoft.Kubernetes/connectedClusters/events/readReads events
Microsoft.Kubernetes/connectedClusters/extensions/daemonsets/readReads daemonsets
Microsoft.Kubernetes/connectedClusters/extensions/deployments/readReads deployments
Microsoft.Kubernetes/connectedClusters/extensions/ingresses/readReads ingresses
Microsoft.Kubernetes/connectedClusters/extensions/networkpolicies/readReads networkpolicies
Microsoft.Kubernetes/connectedClusters/extensions/replicasets/readReads replicasets
Microsoft.Kubernetes/connectedClusters/limitranges/readReads limitranges
Microsoft.Kubernetes/connectedClusters/namespaces/readReads namespaces
Microsoft.Kubernetes/connectedClusters/networking.k8s.io/ingresses/readReads ingresses
Microsoft.Kubernetes/connectedClusters/networking.k8s.io/networkpolicies/readReads networkpolicies
Microsoft.Kubernetes/connectedClusters/persistentvolumeclaims/readReads persistentvolumeclaims
Microsoft.Kubernetes/connectedClusters/pods/readReads pods
Microsoft.Kubernetes/connectedClusters/policy/poddisruptionbudgets/readReads poddisruptionbudgets
Microsoft.Kubernetes/connectedClusters/replicationcontrollers/readReads replicationcontrollers
Microsoft.Kubernetes/connectedClusters/replicationcontrollers/readReads replicationcontrollers
Microsoft.Kubernetes/connectedClusters/resourcequotas/readReads resourcequotas
Microsoft.Kubernetes/connectedClusters/serviceaccounts/readReads serviceaccounts
Microsoft.Kubernetes/connectedClusters/services/readReads services
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2022-05-01-preview
Condition none