last sync: 2024-Nov-25 18:54:42 UTC

Azure Red Hat OpenShift Azure Files Storage Operator Role

Azure BuiltIn RBAC Role definition

NameAzure Red Hat OpenShift Azure Files Storage Operator Role
Id0d7aedc0-15fd-4a67-a412-efad370c947e
DescriptionEnables permissions to set OpenShift cluster-wide storage defaults. It ensures a default storageclass exists for clusters. It also installs Container Storage Interface (CSI) drivers which enable your cluster to use Azure Files.
CreatedOn2024-01-30 16:11:37 UTC
UpdatedOn2024-07-30 16:22:46 UTC
History
Date/Time (UTC ymd) (i) Change Change detail
2024-04-15 17:47:24 change: Actions Actions: 'add Microsoft.Storage/storageAccounts/delete; add Microsoft.Storage/storageAccounts/fileServices/read; add Microsoft.Storage/storageAccounts/fileServices/shares/delete; add Microsoft.Storage/storageAccounts/fileServices/shares/read; add Microsoft.Storage/storageAccounts/fileServices/shares/write; add Microsoft.Storage/storageAccounts/listKeys/action; add Microsoft.Storage/storageAccounts/read; add Microsoft.Storage/storageAccounts/write; add Microsoft.Network/networkSecurityGroups/join/action; add Microsoft.Network/virtualNetworks/subnets/read; add Microsoft.Network/virtualNetworks/subnets/write'
2024-01-31 19:57:40 add: Role 0d7aedc0-15fd-4a67-a412-efad370c947e
Permissions summary Effective control plane and data plane operations: 11 (unique operations)
•action: 2
•delete: 2
•read: 4
•write: 3

Actions: 11
Resolved control plane operations from Actions: 11
Effective control plane operations: 11
•action: 2
•delete: 2
•read: 4
•write: 3

NotActions: 0
Resolved control plane operations from NotActions: 0
Effective denied control plane operations: 16161

DataActions: 0
Resolved data plane operations: 0
Effective data plane operations: 0

NotDataActions: 0
Resolved data plane operations from NotDataActions: 0
Effective denied data plane operations: 3303
Actions
Operation Description
Microsoft.Network/networkSecurityGroups/join/actionJoins a network security group. Not Alertable.
Microsoft.Network/virtualNetworks/subnets/readGets a virtual network subnet definition
Microsoft.Network/virtualNetworks/subnets/writeCreates a virtual network subnet or updates an existing virtual network subnet
Microsoft.Storage/storageAccounts/deleteDeletes an existing storage account.
Microsoft.Storage/storageAccounts/fileServices/readGet file service properties
Microsoft.Storage/storageAccounts/fileServices/shares/deleteDelete file share
Microsoft.Storage/storageAccounts/fileServices/shares/readList file shares
Microsoft.Storage/storageAccounts/fileServices/shares/writeCreate or update file share
Microsoft.Storage/storageAccounts/listKeys/actionReturns the access keys for the specified storage account.
Microsoft.Storage/storageAccounts/readReturns the list of storage accounts or gets the properties for the specified storage account.
Microsoft.Storage/storageAccounts/writeCreates a storage account with the specified parameters or update the properties or tags or adds custom domain for the specified storage account.
NotActions n/a
DataActions n/a
NotDataActions n/a
Used in
BuiltIn Policy
none
JSON
api-version=2023-07-01-preview
Condition none