last sync: 2020-Oct-28 15:04:35 UTC

Azure Role

Azure Kubernetes Service RBAC Reader

NameAzure Kubernetes Service RBAC Reader
Id7f6c6a51-bcf8-42ba-9220-52d62157d7db
DescriptionAllows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.
CreatedOn2020-07-02 17:53:05 UTC
UpdatedOn2020-10-22 16:08:11 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2020-10-23 13:31:33 change: Description, Actions, DataActions, NotDataActions New Description: 'Allows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.'
Old Description: 'Lets you view all resources in cluster/namespace, except secrets.',
Actions: 'remove Microsoft.ContainerService/managedClusters/listClusterUserCredential/action',
DataActions: 'remove Microsoft.ContainerService/managedClusters/*/read; add Microsoft.ContainerService/managedClusters/apps/controllerrevisions/read; add Microsoft.ContainerService/managedClusters/apps/daemonsets/read; add Microsoft.ContainerService/managedClusters/apps/deployments/read; add Microsoft.ContainerService/managedClusters/apps/replicasets/read; add Microsoft.ContainerService/managedClusters/apps/statefulsets/read; add Microsoft.ContainerService/managedClusters/autoscaling/horizontalpodautoscalers/read; add Microsoft.ContainerService/managedClusters/batch/cronjobs/read; add Microsoft.ContainerService/managedClusters/batch/jobs/read; add Microsoft.ContainerService/managedClusters/configmaps/read; add Microsoft.ContainerService/managedClusters/endpoints/read; add Microsoft.ContainerService/managedClusters/events.k8s.io/events/read; add Microsoft.ContainerService/managedClusters/events/read; add Microsoft.ContainerService/managedClusters/extensions/daemonsets/read; add Microsoft.ContainerService/managedClusters/extensions/deployments/read; add Microsoft.ContainerService/managedClusters/extensions/ingresses/read; add Microsoft.ContainerService/managedClusters/extensions/networkpolicies/read; add Microsoft.ContainerService/managedClusters/extensions/replicasets/read; add Microsoft.ContainerService/managedClusters/limitranges/read; add Microsoft.ContainerService/managedClusters/namespaces/read; add Microsoft.ContainerService/managedClusters/networking.k8s.io/ingresses/read; add Microsoft.ContainerService/managedClusters/networking.k8s.io/networkpolicies/read; add Microsoft.ContainerService/managedClusters/persistentvolumeclaims/read; add Microsoft.ContainerService/managedClusters/pods/read; add Microsoft.ContainerService/managedClusters/policy/poddisruptionbudgets/read; add Microsoft.ContainerService/managedClusters/replicationcontrollers/read; add Microsoft.ContainerService/managedClusters/replicationcontrollers/read; add Microsoft.ContainerService/managedClusters/resourcequotas/read; add Microsoft.ContainerService/managedClusters/serviceaccounts/read; add Microsoft.ContainerService/managedClusters/services/read',
NotDataActions: 'remove Microsoft.ContainerService/managedClusters/rbac.authorization.k8s.io/*/read; remove Microsoft.ContainerService/managedClusters/rbac.authorization.k8s.io/*/write; remove Microsoft.ContainerService/managedClusters/secrets/*'
2020-07-03 14:58:03 add: Role 6a51-bcf8-42ba-9220-52d62157d7db
Actions
Operation Description Used in other Roles
Microsoft.Authorization/*/readno description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, Backup Reader, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Marketplace Admin, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Insights/alertRules/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, BizTalk Contributor, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Collaborative Data Contributor, Cosmos DB Operator, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Log Analytics Contributor, Logic App Contributor, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Resources/deployments/writeCreates or updates an deployment. Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin , Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Kubernetes Cluster - Azure Arc Onboarding
Microsoft.Resources/subscriptions/operationresults/readGet the subscription operation results. Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin , Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Cognitive Services Contributor, Cognitive Services User, Kubernetes Cluster - Azure Arc Onboarding, Logic App Contributor, Logic App Operator
Microsoft.Resources/subscriptions/readGets the list of subscriptions. Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin , Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Cognitive Services Contributor, Cognitive Services User, Cost Management Contributor, Cost Management Reader, Kubernetes Cluster - Azure Arc Onboarding, Reservation Purchaser
Microsoft.Resources/subscriptions/resourceGroups/readGets or lists resource groups. API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Avere Operator, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DevTest Labs User, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, EventGrid EventSubscription Reader, Experimentation Administrator, Experimentation Contributor, HDInsight Cluster Operator, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Metrics Publisher, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Reservation Purchaser, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), Security Reader, Services Hub Operator, SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
Microsoft.Support/*no description given API Management Service Contributor, API Management Service Operator Role, API Management Service Reader Role , Application Insights Component Contributor, Application Insights Snapshot Debugger, Automation Job Operator, Automation Operator, Automation Runbook Operator, Avere Contributor, Azure Arc Enabled Kubernetes Cluster User Role, Azure Arc Kubernetes Admin, Azure Arc Kubernetes Cluster Admin, Azure Arc Kubernetes Viewer, Azure Arc Kubernetes Writer, Azure Kubernetes Service RBAC Admin, Azure Kubernetes Service RBAC Cluster Admin, Azure Kubernetes Service RBAC Writer, Azure Sentinel Contributor, Azure Sentinel Reader, Azure Sentinel Responder, Backup Contributor, Backup Operator, Billing Reader, BizTalk Contributor, Blueprint Contributor, Blueprint Operator, CDN Endpoint Contributor, CDN Endpoint Reader, CDN Profile Contributor, CDN Profile Reader, Classic Network Contributor, Classic Storage Account Contributor, Classic Virtual Machine Contributor, ClearDB MySQL DB Contributor, Cognitive Services Contributor, Cognitive Services User, Collaborative Data Contributor, Cosmos DB Account Reader Role, Cosmos DB Operator, Cost Management Contributor, Cost Management Reader, Data Box Contributor, Data Box Reader, Data Factory Contributor, Data Lake Analytics Developer, Device Update Administrator, Device Update Content Administrator, Device Update Content Reader, Device Update Deployments Administrator, Device Update Deployments Reader, Device Update Reader, DNS Zone Contributor, DocumentDB Account Contributor, EventGrid EventSubscription Contributor, HDInsight Cluster Operator, Integration Service Environment Contributor, Integration Service Environment Developer, Intelligent Systems Account Contributor, Key Vault Administrator (preview), Key Vault Certificates Officer (preview), Key Vault Contributor, Key Vault Crypto Officer (preview), Key Vault Reader (preview), Key Vault Secrets Officer (preview), Kubernetes Cluster - Azure Arc Onboarding, Lab Creator, Log Analytics Contributor, Log Analytics Reader, Logic App Contributor, Logic App Operator, Managed Identity Contributor, Managed Identity Operator, Monitoring Contributor, Monitoring Metrics Publisher, Monitoring Reader, Network Contributor, New Relic APM Account Contributor, Private DNS Zone Contributor, Redis Cache Contributor, Resource Policy Contributor, Scheduler Job Collections Contributor, Search Service Contributor, Security Admin, Security Manager (Legacy), SignalR AccessKey Reader, SignalR Contributor, Site Recovery Contributor, Site Recovery Operator, Site Recovery Reader, SQL DB Contributor, SQL Managed Instance Contributor, SQL Security Manager, SQL Server Contributor, Storage Account Contributor, Support Request Contributor, Tag Contributor, Traffic Manager Contributor, User Access Administrator, Virtual Machine Contributor, Web Plan Contributor, Website Contributor
NotActions n/a
DataActions
Operation Description Used in other Roles
Microsoft.ContainerService/managedClusters/apps/controllerrevisions/readReads controllerrevisions Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/apps/daemonsets/readReads daemonsets none
Microsoft.ContainerService/managedClusters/apps/deployments/readReads deployments none
Microsoft.ContainerService/managedClusters/apps/replicasets/readReads replicasets none
Microsoft.ContainerService/managedClusters/apps/statefulsets/readReads statefulsets none
Microsoft.ContainerService/managedClusters/autoscaling/horizontalpodautoscalers/readReads horizontalpodautoscalers none
Microsoft.ContainerService/managedClusters/batch/cronjobs/readReads cronjobs none
Microsoft.ContainerService/managedClusters/batch/jobs/readReads jobs none
Microsoft.ContainerService/managedClusters/configmaps/readReads configmaps none
Microsoft.ContainerService/managedClusters/endpoints/readReads endpoints none
Microsoft.ContainerService/managedClusters/events.k8s.io/events/readReads events Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/events/readReads events Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/extensions/daemonsets/readReads daemonsets none
Microsoft.ContainerService/managedClusters/extensions/deployments/readReads deployments none
Microsoft.ContainerService/managedClusters/extensions/ingresses/readReads ingresses none
Microsoft.ContainerService/managedClusters/extensions/networkpolicies/readReads networkpolicies none
Microsoft.ContainerService/managedClusters/extensions/replicasets/readReads replicasets none
Microsoft.ContainerService/managedClusters/limitranges/readReads limitranges Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/namespaces/readReads namespaces Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/networking.k8s.io/ingresses/readReads ingresses none
Microsoft.ContainerService/managedClusters/networking.k8s.io/networkpolicies/readReads networkpolicies none
Microsoft.ContainerService/managedClusters/persistentvolumeclaims/readReads persistentvolumeclaims none
Microsoft.ContainerService/managedClusters/pods/readReads pods none
Microsoft.ContainerService/managedClusters/policy/poddisruptionbudgets/readReads poddisruptionbudgets none
Microsoft.ContainerService/managedClusters/replicationcontrollers/readReads replicationcontrollers none
Microsoft.ContainerService/managedClusters/replicationcontrollers/readReads replicationcontrollers none
Microsoft.ContainerService/managedClusters/resourcequotas/readReads resourcequotas Azure Kubernetes Service RBAC Writer
Microsoft.ContainerService/managedClusters/serviceaccounts/readReads serviceaccounts none
Microsoft.ContainerService/managedClusters/services/readReads services none
NotDataActions n/a
Used in Policy none
Json
{
  "Name": "Azure Kubernetes Service RBAC Reader",
  "Id": "7f6c6a51-bcf8-42ba-9220-52d62157d7db",
  "IsCustom": false,
  "Description": "Allows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.",
  "Actions": [
    "Microsoft.Authorization/*/read",
    "Microsoft.Insights/alertRules/*",
    "Microsoft.Resources/deployments/write",
    "Microsoft.Resources/subscriptions/operationresults/read",
    "Microsoft.Resources/subscriptions/read",
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Support/*"
  ],
  "NotActions": [
    
  ],
  "DataActions": [
    "Microsoft.ContainerService/managedClusters/apps/controllerrevisions/read",
    "Microsoft.ContainerService/managedClusters/apps/daemonsets/read",
    "Microsoft.ContainerService/managedClusters/apps/deployments/read",
    "Microsoft.ContainerService/managedClusters/apps/replicasets/read",
    "Microsoft.ContainerService/managedClusters/apps/statefulsets/read",
    "Microsoft.ContainerService/managedClusters/autoscaling/horizontalpodautoscalers/read",
    "Microsoft.ContainerService/managedClusters/batch/cronjobs/read",
    "Microsoft.ContainerService/managedClusters/batch/jobs/read",
    "Microsoft.ContainerService/managedClusters/configmaps/read",
    "Microsoft.ContainerService/managedClusters/endpoints/read",
    "Microsoft.ContainerService/managedClusters/events.k8s.io/events/read",
    "Microsoft.ContainerService/managedClusters/events/read",
    "Microsoft.ContainerService/managedClusters/extensions/daemonsets/read",
    "Microsoft.ContainerService/managedClusters/extensions/deployments/read",
    "Microsoft.ContainerService/managedClusters/extensions/ingresses/read",
    "Microsoft.ContainerService/managedClusters/extensions/networkpolicies/read",
    "Microsoft.ContainerService/managedClusters/extensions/replicasets/read",
    "Microsoft.ContainerService/managedClusters/limitranges/read",
    "Microsoft.ContainerService/managedClusters/namespaces/read",
    "Microsoft.ContainerService/managedClusters/networking.k8s.io/ingresses/read",
    "Microsoft.ContainerService/managedClusters/networking.k8s.io/networkpolicies/read",
    "Microsoft.ContainerService/managedClusters/persistentvolumeclaims/read",
    "Microsoft.ContainerService/managedClusters/pods/read",
    "Microsoft.ContainerService/managedClusters/policy/poddisruptionbudgets/read",
    "Microsoft.ContainerService/managedClusters/replicationcontrollers/read",
    "Microsoft.ContainerService/managedClusters/replicationcontrollers/read",
    "Microsoft.ContainerService/managedClusters/resourcequotas/read",
    "Microsoft.ContainerService/managedClusters/serviceaccounts/read",
    "Microsoft.ContainerService/managedClusters/services/read"
  ],
  "NotDataActions": [
    
  ],
  "AssignableScopes": [
    "/"
  ]
}