Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters

Azure RBAC · Containers · Data Plane

Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters

Data PlaneIAM ScopeContainers·39 na definição · ≥ 32 efetivas

Dado verificado em · Fonte

Entradas na definição

39

Actions

0

NotActions

0

DataActions

0

Alcance efetivo

piso, não total

Control plane

32

Data plane

Sem denominador

Na definição (nativo)

39

Piso, não total: expandido contra 17.591 ações de 151 providers colhidas da documentação da Microsoft. A Azure Management API expõe mais — o número real é maior, nunca menor.

O universo de ações mistura control plane e data plane sem marcar qual é qual, então não há denominador contra o qual expandir um wildcard de DataActions. Preferimos deixar em branco a publicar um número inventado.

Role ID
50346970-0998-40f2-b47d-f3b8809840f8
Categoria
Containers
Risk Tier
Data Plane (DP)
Risk Tier: Data Plane

Grants access to data stored within services (blobs, queues, secrets, keys) without management plane control.

Descrição

Microsoft

Allows read/write access to most objects in a namespace. This role does not allow viewing or modifying roles or role bindings. However, this role allows accessing Secrets and running Pods as any ServiceAccount in the namespace, so it can be used to gain the API access levels of any ServiceAccount in the namespace.  Applying this role at cluster scope will give access across all namespaces.

Permissões

MicrosoftCarregando...Azure built-in roles

Role Definition (JSON)

{
"Name": "Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters",
"Id": "50346970-0998-40f2-b47d-f3b8809840f8",
"IsCustom": false,
"Description": "Allows read/write access to most objects in a namespace. This role does not allow viewing or modifying roles or role bindings. However, this role allows accessing Secrets and running Pods as any ServiceAccount in the namespace, so it can be used to gain the API access levels of any ServiceAccount in the namespace.  Applying this role at cluster scope will give access across all namespaces.",
"Actions": [],
"NotActions": [],
"DataActions": [],
"NotDataActions": [],
"AssignableScopes": [
"/"
]

Assignable Scopes

/

PowerShell

Get-AzRoleDefinition -Name "Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters"

Azure CLI

az role definition list --name "Azure Kubernetes Fleet Manager RBAC Writer for Member Clusters"
Ver a documentação oficial na Microsoft Learn