Azure Kubernetes Service RBAC Reader

Azure RBAC · Containers · Data Plane

Azure Kubernetes Service RBAC Reader

Data PlaneIAM ScopeContainers·35 na definição · ≥ 32 efetivas

Dado verificado em · Fonte

Entradas na definição

35

Actions

0

NotActions

0

DataActions

0

Alcance efetivo

piso, não total

Control plane

32

Data plane

31

Na definição (nativo)

35

Piso, não total: expandido contra 17.591 ações de 151 providers colhidas da documentação da Microsoft. A Azure Management API expõe mais — o número real é maior, nunca menor.

Role ID
7f6c6a51-bcf8-42ba-9220-52d62157d7db
Categoria
Containers
Risk Tier
Data Plane (DP)
Risk Tier: Data Plane

Grants access to data stored within services (blobs, queues, secrets, keys) without management plane control.

Descrição

Microsoft

Allows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.

Permissões

MicrosoftCarregando...Azure built-in roles

Role Definition (JSON)

{
"Name": "Azure Kubernetes Service RBAC Reader",
"Id": "7f6c6a51-bcf8-42ba-9220-52d62157d7db",
"IsCustom": false,
"Description": "Allows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces.",
"Actions": [],
"NotActions": [],
"DataActions": [],
"NotDataActions": [],
"AssignableScopes": [
"/"
]

Assignable Scopes

/

PowerShell

Get-AzRoleDefinition -Name "Azure Kubernetes Service RBAC Reader"

Azure CLI

az role definition list --name "Azure Kubernetes Service RBAC Reader"
Ver a documentação oficial na Microsoft Learn