Skip to content

Commit a48ef2c

Browse files
Merge pull request #300442 from rolyon/rolyon-rbac-roles-container-apps-jobs-sessionpools
[Azure RBAC] Container Apps roles
2 parents 3175539 + e55f8bb commit a48ef2c

File tree

2 files changed

+630
-0
lines changed

2 files changed

+630
-0
lines changed

articles/role-based-access-control/built-in-roles.md

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -223,6 +223,17 @@ The following table provides a brief description of each built-in role. Click th
223223
> | <a name='azure-red-hat-openshift-network-operator'></a>[Azure Red Hat OpenShift Network Operator](./built-in-roles/containers.md#azure-red-hat-openshift-network-operator) | Install and upgrade the networking components on an OpenShift cluster. | be7a6435-15ae-4171-8f30-4a343eff9e8f |
224224
> | <a name='azure-red-hat-openshift-service-operator'></a>[Azure Red Hat OpenShift Service Operator](./built-in-roles/containers.md#azure-red-hat-openshift-service-operator) | Maintain machine health, network configuration, monitoring, and other features that are specific to an OpenShift cluster's continued functionality as a managed service. | 4436bae4-7702-4c84-919b-c4069ff25ee2 |
225225
> | <a name='connected-cluster-managed-identity-checkaccess-reader'></a>[Connected Cluster Managed Identity CheckAccess Reader](./built-in-roles/containers.md#connected-cluster-managed-identity-checkaccess-reader) | Built-in role that allows a Connected Cluster managed identity to call the checkAccess API | 65a14201-8f6c-4c28-bec4-12619c5a9aaa |
226+
> | <a name='container-apps-connectedenvironments-contributor'></a>[Container Apps ConnectedEnvironments Contributor](./built-in-roles/containers.md#container-apps-connectedenvironments-contributor) | Full management of Container Apps ConnectedEnvironments, including creation, deletion, and updates. | 6f4fe6fc-f04f-4d97-8528-8bc18c848dca |
227+
> | <a name='container-apps-connectedenvironments-reader'></a>[Container Apps ConnectedEnvironments Reader](./built-in-roles/containers.md#container-apps-connectedenvironments-reader) | Read access to Container Apps ConnectedEnvironments. | d5adeb5b-107f-4aca-99ea-4e3f4fc008d5 |
228+
> | <a name='container-apps-contributor'></a>[Container Apps Contributor](./built-in-roles/containers.md#container-apps-contributor) | Full management of Container Apps, including creation, deletion, and updates. | 358470bc-b998-42bd-ab17-a7e34c199c0f |
229+
> | <a name='container-apps-jobs-contributor'></a>[Container Apps Jobs Contributor](./built-in-roles/containers.md#container-apps-jobs-contributor) | Full management of Container Apps jobs, including creation, deletion, and updates. | 4e3d2b60-56ae-4dc6-a233-09c8e5a82e68 |
230+
> | <a name='container-apps-jobs-operator'></a>[Container Apps Jobs Operator](./built-in-roles/containers.md#container-apps-jobs-operator) | Read, start, and stop Container Apps jobs. | b9a307c4-5aa3-4b52-ba60-2b17c136cd7b |
231+
> | <a name='container-apps-jobs-reader'></a>[Container Apps Jobs Reader](./built-in-roles/containers.md#container-apps-jobs-reader) | Read access to ContainerApps jobs | edd66693-d32a-450b-997d-0158c03976b0 |
232+
> | <a name='container-apps-managedenvironments-contributor'></a>[Container Apps ManagedEnvironments Contributor](./built-in-roles/containers.md#container-apps-managedenvironments-contributor) | Full management of Container Apps ManagedEnvironments, including creation, deletion, and updates. | 57cc5028-e6a7-4284-868d-0611c5923f8d |
233+
> | <a name='container-apps-managedenvironments-reader'></a>[Container Apps ManagedEnvironments Reader](./built-in-roles/containers.md#container-apps-managedenvironments-reader) | Read access to ContainerApps managedenvironments. | 1b32c00b-7eff-4c22-93e6-93d11d72d2d8 |
234+
> | <a name='container-apps-operator'></a>[Container Apps Operator](./built-in-roles/containers.md#container-apps-operator) | Read, logstream and exec into Container Apps. | f3bd1b5c-91fa-40e7-afe7-0c11d331232c |
235+
> | <a name='container-apps-sessionpools-contributor'></a>[Container Apps SessionPools Contributor](./built-in-roles/containers.md#container-apps-sessionpools-contributor) | Full management of Container Apps SessionPools, including creation, deletion, and updates. | f7669afb-68b2-44b4-9c5f-6d2a47fddda0 |
236+
> | <a name='container-apps-sessionpools-reader'></a>[Container Apps SessionPools Reader](./built-in-roles/containers.md#container-apps-sessionpools-reader) | Read access to ContainerApps sessionpools. | af61e8fc-2633-4b95-bed3-421ad6826515 |
226237
> | <a name='container-registry-cache-rule-administrator'></a>[Container Registry Cache Rule Administrator](./built-in-roles/containers.md#container-registry-cache-rule-administrator) | Create, Read, Update, and Delete Cache Rules in Container Registry. This role doesn't grant permissions to manage Credential Sets. | df87f177-bb12-4db1-9793-a413691eff94 |
227238
> | <a name='container-registry-cache-rule-reader'></a>[Container Registry Cache Rule Reader](./built-in-roles/containers.md#container-registry-cache-rule-reader) | Read the configuration of Cache Rules in Container Registry. This permission doesn't grant permission to read Credential Sets. | c357b964-0002-4b64-a50d-7a28f02edc52 |
228239
> | <a name='container-registry-configuration-reader-and-data-access-configuration-reader'></a>[Container Registry Configuration Reader and Data Access Configuration Reader](./built-in-roles/containers.md#container-registry-configuration-reader-and-data-access-configuration-reader) | Provides permissions to list container registries and registry configuration properties. Provides permissions to list data access configuration such as admin user credentials, scope maps, and tokens, which can be used to read, write or delete repositories and images. Does not provide direct permissions to read, list, or write registry contents including repositories and images. Does not provide permissions to modify data plane content such as imports, Artifact Cache or Sync, and Transfer Pipelines. Does not provide permissions for managing Tasks. | 69b07be0-09bf-439a-b9a6-e73de851bd59 |

0 commit comments

Comments
 (0)