@@ -972,7 +972,7 @@ module storageRoleUser 'core/security/role.bicep' = {
972972 name : 'storage-role-user'
973973 params : {
974974 principalId : principalId
975- roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1'
975+ roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1' // Storage Blob Data Reader
976976 principalType : principalType
977977 }
978978}
@@ -982,7 +982,7 @@ module storageContribRoleUser 'core/security/role.bicep' = {
982982 name : 'storage-contrib-role-user'
983983 params : {
984984 principalId : principalId
985- roleDefinitionId : 'ba92f5b4-2d11-453d-a403-e96b0029c9fe'
985+ roleDefinitionId : 'ba92f5b4-2d11-453d-a403-e96b0029c9fe' // Storage Blob Data Contributor
986986 principalType : principalType
987987 }
988988}
@@ -992,7 +992,7 @@ module storageOwnerRoleUser 'core/security/role.bicep' = if (useUserUpload) {
992992 name : 'storage-owner-role-user'
993993 params : {
994994 principalId : principalId
995- roleDefinitionId : 'b7e6dc6d-f1e8-4753-8033-0f276bb0955b'
995+ roleDefinitionId : 'b7e6dc6d-f1e8-4753-8033-0f276bb0955b' // Storage Blob Data Owner
996996 principalType : principalType
997997 }
998998}
@@ -1092,7 +1092,7 @@ module storageRoleBackend 'core/security/role.bicep' = {
10921092 principalId : (deploymentTarget == 'appservice' )
10931093 ? backend .outputs .identityPrincipalId
10941094 : acaBackend .outputs .identityPrincipalId
1095- roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1'
1095+ roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1' // Storage Blob Data Reader
10961096 principalType : 'ServicePrincipal'
10971097 }
10981098}
@@ -1104,7 +1104,7 @@ module storageOwnerRoleBackend 'core/security/role.bicep' = if (useUserUpload) {
11041104 principalId : (deploymentTarget == 'appservice' )
11051105 ? backend .outputs .identityPrincipalId
11061106 : acaBackend .outputs .identityPrincipalId
1107- roleDefinitionId : 'b7e6dc6d-f1e8-4753-8033-0f276bb0955b'
1107+ roleDefinitionId : 'b7e6dc6d-f1e8-4753-8033-0f276bb0955b' // Storage Blob Data Owner
11081108 principalType : 'ServicePrincipal'
11091109 }
11101110}
@@ -1114,7 +1114,7 @@ module storageRoleSearchService 'core/security/role.bicep' = if (useIntegratedVe
11141114 name : 'storage-role-searchservice'
11151115 params : {
11161116 principalId : searchService .outputs .principalId
1117- roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1'
1117+ roleDefinitionId : '2a2b9908-6ea1-4ae2-8e65-a410df84e7d1' // Storage Blob Data Reader
11181118 principalType : 'ServicePrincipal'
11191119 }
11201120}
0 commit comments