Skip to content

Azure Installation Permissions

The following permissions are required to run the Deployer on Azure:

json
[
    {
        "actions": [
            "Microsoft.Resources/subscriptions/resourcegroups/read",
            "Microsoft.Network/virtualNetworks/read",
            "Microsoft.Network/virtualNetworks/write",
            "Microsoft.Network/virtualNetworks/delete",
            "Microsoft.Network/virtualNetworks/subnets/read",
            "Microsoft.Network/virtualNetworks/subnets/join/action",
            "Microsoft.ContainerRegistry/registries/read",
            "Microsoft.ContainerRegistry/registries/write",
            "Microsoft.ContainerRegistry/registries/delete",
            "Microsoft.ContainerRegistry/registries/generateCredentials/action",
            "Microsoft.ContainerRegistry/registries/pull/read",
            "Microsoft.ContainerRegistry/registries/push/write",
            "Microsoft.ManagedIdentity/userAssignedIdentities/write",
            "Microsoft.ManagedIdentity/userAssignedIdentities/read",
            "Microsoft.ManagedIdentity/userAssignedIdentities/delete",
            "Microsoft.ContainerService/managedClusters/read",
            "Microsoft.ContainerService/managedClusters/write",
            "Microsoft.ContainerService/managedClusters/delete",
            "Microsoft.ContainerService/managedClusters/listClusterAdminCredential/action",
            "Microsoft.Authorization/roleAssignments/read",
            "Microsoft.Authorization/roleAssignments/write",
            "Microsoft.Authorization/roleAssignments/delete",
            "Microsoft.Authorization/roleDefinitions/read",
            "Microsoft.Authorization/roleDefinitions/write",
            "Microsoft.Authorization/roleDefinitions/delete",
            "Microsoft.ManagedIdentity/userAssignedIdentities/federatedIdentityCredentials/read",
            "Microsoft.ManagedIdentity/userAssignedIdentities/federatedIdentityCredentials/write",
            "Microsoft.ManagedIdentity/userAssignedIdentities/federatedIdentityCredentials/delete",
            "Microsoft.Storage/storageAccounts/read",
            "Microsoft.Storage/storageAccounts/write",
            "Microsoft.Storage/storageAccounts/delete",
            "Microsoft.Storage/storageAccounts/blobServices/containers/read",
            "Microsoft.Storage/storageAccounts/blobServices/containers/write"
        ],
        "notActions": [],
        "dataActions": [],
        "notDataActions": []
    }
]