Azure Storage built-in role

Avere Operator

Is the service role used by Avere vFXT cluster node identities to manage node networking, join the cluster subnet and network security group, manage blob containers, and read, write, or delete blob data used by the cluster. It is not an end-user file-access role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: c025889f-8102-4ebf-b32c-fc0c6f0c6bd9

Control-plane actions (11)

Data-plane actions (3)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The role is assignable throughout the Azure hierarchy, but the archived Avere guidance assigns it to cluster nodes inside the isolated cluster deployment. Its limited control-plane actions still include network-interface writes and container management, while its DataActions grant blob read, write, and delete at the assigned scope.

Common use cases (2)

Prerequisites (3)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign Avere Operator only to each Avere vFXT cluster node identity, at the smallest scope containing the cluster network resources and intended Blob Storage core filer. Keep controller duties on Avere Contributor and remove node assignments as the cluster is decommissioned.

Related roles (1)

Editorial sources (5)

Official Microsoft Learn documentation →