Azure Storage built-in role

Avere Contributor

Creates and manages the compute, network, deployment, storage, monitoring, and support resources used by an Avere vFXT cluster. The role also has direct read, write, and delete access to blob data for the cluster workflow; the Avere documentation is archived, but the built-in role remains in the canonical Azure role inventory.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4f8fab4f-1852-4a58-a46a-8eaf358af14a

Control-plane actions (20)

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but the Avere deployment guidance places the cluster controller, nodes, network, and storage in a deliberately isolated subscription or resource group. Its Actions are broad across those cluster resources and its DataActions reach blob contents, so the assignment scope controls both management-plane and data-plane exposure.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

For a maintained Avere vFXT environment, assign Avere Contributor to the documented cluster controller identity at the isolated deployment scope. Keep Avere Operator on cluster node identities, verify the controller and nodes do not share a scope with unrelated workloads, and remove assignments when the retired deployment is dismantled.

Related roles (1)

Editorial sources (6)

Official Microsoft Learn documentation →