Skip to content

Commit 41bf4b8

Browse files
authored
Merge pull request #300459 from rolyon/rolyon-rbac-roles-azure-arc-scvmm
[Azure RBAC] Azure Arc ScVmm roles and provider
2 parents 5bb6dbb + 526c17e commit 41bf4b8

File tree

4 files changed

+570
-1
lines changed

4 files changed

+570
-1
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -217,7 +217,7 @@ The following table provides a brief description of each built-in role. Click th
217217
> | <a name='azure-red-hat-openshift-federated-credential'></a>[Azure Red Hat OpenShift Federated Credential](./built-in-roles/containers.md#azure-red-hat-openshift-federated-credential) | Create, update and delete federated credentials on user assigned managed identities in order to build a trust relationship between the managed identity, OpenID Connect (OIDC), and the service account. | ef318e2a-8334-4a05-9e4a-295a196c6a6e |
218218
> | <a name='azure-red-hat-openshift-file-storage-operator'></a>[Azure Red Hat OpenShift File Storage Operator](./built-in-roles/containers.md#azure-red-hat-openshift-file-storage-operator) | Install Container Storage Interface (CSI) drivers that enable your cluster to use Azure Files. Set OpenShift cluster-wide storage defaults to ensure a default storageclass exists for clusters. | 0d7aedc0-15fd-4a67-a412-efad370c947e |
219219
> | <a name='azure-red-hat-openshift-image-registry-operator'></a>[Azure Red Hat OpenShift Image Registry Operator](./built-in-roles/containers.md#azure-red-hat-openshift-image-registry-operator) | Enables permissions for the operator to manage a singleton instance of the OpenShift image registry. It manages all configuration of the registry, including creating storage. | 8b32b316-c2f5-4ddf-b05b-83dacd2d08b5 |
220-
> | <a name='azure-red-hat-openshift-machine-api-operator'></a>[Azure Red Hat OpenShift Machine API Operator](./built-in-roles/containers.md#azure-red-hat-openshift-machine-api-operator) | Manage the lifecycle of specific-purpose custom resource definitions (CRD), controllers, and Azure RBAC objects that extend the Kubernetes API to declares the desired state of machines in a cluster. | 0358943c-7e01-48ba-8889-02cc51d78637 |
220+
> | <a name='azure-red-hat-openshift-machine-api-operator'></a>[Azure Red Hat OpenShift Machine API Operator](./built-in-roles/containers.md#azure-red-hat-openshift-machine-api-operator) | Manage the lifecycle of specific-purpose custom resource definitions (CRD), controllers, and Azure RBAC objects that extend the Kubernetes API to declare the desired state of machines in a cluster. | 0358943c-7e01-48ba-8889-02cc51d78637 |
221221
> | <a name='azure-red-hat-openshift-network-operator'></a>[Azure Red Hat OpenShift Network Operator](./built-in-roles/containers.md#azure-red-hat-openshift-network-operator) | Install and upgrade the networking components on an OpenShift cluster. | be7a6435-15ae-4171-8f30-4a343eff9e8f |
222222
> | <a name='azure-red-hat-openshift-service-operator'></a>[Azure Red Hat OpenShift Service Operator](./built-in-roles/containers.md#azure-red-hat-openshift-service-operator) | Maintain machine health, network configuration, monitoring, and other features that are specific to an OpenShift cluster's continued functionality as a managed service. | 4436bae4-7702-4c84-919b-c4069ff25ee2 |
223223
> | <a name='connected-cluster-managed-identity-checkaccess-reader'></a>[Connected Cluster Managed Identity CheckAccess Reader](./built-in-roles/containers.md#connected-cluster-managed-identity-checkaccess-reader) | Built-in role that allows a Connected Cluster managed identity to call the checkAccess API | 65a14201-8f6c-4c28-bec4-12619c5a9aaa |
@@ -558,6 +558,10 @@ The following table provides a brief description of each built-in role. Click th
558558
> [!div class="mx-tableFixed"]
559559
> | Built-in role | Description | ID |
560560
> | --- | --- | --- |
561+
> | <a name='azure-arc-scvmm-administrator-role'></a>[Azure Arc ScVmm Administrator role](./built-in-roles/hybrid-multicloud.md#azure-arc-scvmm-administrator-role) | Arc ScVmm VM Administrator has permissions to perform all ScVmm actions. | a92dfd61-77f9-4aec-a531-19858b406c87 |
562+
> | <a name='azure-arc-scvmm-private-cloud-user'></a>[Azure Arc ScVmm Private Cloud User](./built-in-roles/hybrid-multicloud.md#azure-arc-scvmm-private-cloud-user) | Azure Arc ScVmm Private Cloud User has permissions to use the ScVmm resources to deploy VMs. | c0781e91-8102-4553-8951-97c6d4243cda |
563+
> | <a name='azure-arc-scvmm-private-clouds-onboarding'></a>[Azure Arc ScVmm Private Clouds Onboarding](./built-in-roles/hybrid-multicloud.md#azure-arc-scvmm-private-clouds-onboarding) | Azure Arc ScVmm Private Clouds Onboarding role has permissions to provision all the required resources for onboard and deboard vmm server instances to Azure. | 6aac74c4-6311-40d2-bbdd-7d01e7c6e3a9 |
564+
> | <a name='azure-arc-scvmm-vm-contributor'></a>[Azure Arc ScVmm VM Contributor](./built-in-roles/hybrid-multicloud.md#azure-arc-scvmm-vm-contributor) | Arc ScVmm VM Contributor has permissions to perform all VM actions. | e582369a-e17b-42a5-b10c-874c387c530b |
561565
> | <a name='azure-resource-bridge-deployment-role'></a>[Azure Resource Bridge Deployment Role](./built-in-roles/hybrid-multicloud.md#azure-resource-bridge-deployment-role) | Azure Resource Bridge Deployment Role is used only for Azure Stack HCI. | 7b1f81f9-4196-4058-8aae-762e593270df |
562566
> | <a name='azure-stack-hci-administrator'></a>[Azure Stack HCI Administrator](./built-in-roles/hybrid-multicloud.md#azure-stack-hci-administrator) | Grants full access to the cluster and its resources, including the ability to register Azure Local and assign others as Azure Stack HCI VM Contributor and/or Azure Stack HCI VM Reader | bda0d508-adf1-4af0-9c28-88919fc3ae06 |
563567
> | <a name='azure-stack-hci-connected-infravms'></a>[Azure Stack HCI Connected InfraVMs](./built-in-roles/hybrid-multicloud.md#azure-stack-hci-connected-infravms) | Role of Arc Integration for Azure Stack HCI Infrastructure Virtual Machines. | c99c945f-8bd1-4fb1-a903-01460aae6068 |

0 commit comments

Comments
 (0)