Azure Containers built-in role

Azure Kubernetes Fleet Manager Contributor Role

Creates and manages Fleet Manager Azure resources and subresources, including fleets, members, update strategies, update runs, and related orchestration. It is Azure control-plane authority and does not itself grant Kubernetes API DataActions on the hub or member clusters.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 63bb64ad-9799-4770-b5c3-24ed299a07bf

Control-plane actions (3)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

Assign on the Fleet Manager resource or its dedicated resource group. A broader parent assignment is inherited by all fleet resources below it and permits fleet orchestration across them.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Assign directly on the Fleet Manager resource to the fleet platform team. Assign hub or member Kubernetes RBAC roles separately on the Fleet or Managed Fleet Namespace ARM scope as documented.

Related roles (2)

Common questions

When should I assign the Azure Kubernetes Fleet Manager Contributor Role Azure role?

Assign Azure Kubernetes Fleet Manager Contributor Role when you need to: Let a fleet platform administrator register members, define update strategies, and operate fleet update runs without granting Kubernetes workload access.. Practical scope: Assign on the Fleet Manager resource or its dedicated resource group. A broader parent assignment is inherited by all fleet resources below it and permits fleet orchestration across them.

What permissions does the Azure Kubernetes Fleet Manager Contributor Role Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.ContainerService/fleets/*; Microsoft.Resources/deployments/*; and Microsoft.ContainerService/fleetMemberships/*. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Kubernetes Fleet Manager Contributor Role Azure role?

Key considerations when assigning Azure Kubernetes Fleet Manager Contributor Role: Membership and update orchestration can affect availability and software versions across multiple clusters.; and The role is broad fleet management, not a workload authorization role and not a least-privilege default for application teams.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (6)

Official Microsoft Learn documentation →