Azure Containers built-in role
Azure Red Hat OpenShift Image Registry Operator
Azure Red Hat OpenShift Image Registry Operator is a service-agent role for the user-assigned managed identity associated with the Image Registry operator. It allows that operator to configure the singleton OpenShift image registry and create or manage its Azure Storage and private-network resources. Azure Red Hat OpenShift creates a separate assignment of this role on the ARO managed resource group for the service-managed resources. The role combines Azure control-plane Actions with Azure Blob DataActions for the registry content; it is not a human OpenShift administration role.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 8b32b316-c2f5-4ddf-b05b-83dacd2d08b5
Control-plane actions (25)
Microsoft.Storage/storageAccounts/blobServices/readMicrosoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/blobServices/containers/writeMicrosoft.Storage/storageAccounts/blobServices/containers/deleteMicrosoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/actionMicrosoft.Storage/storageAccounts/readMicrosoft.Storage/storageAccounts/writeMicrosoft.Storage/storageAccounts/deleteMicrosoft.Storage/storageAccounts/listKeys/actionMicrosoft.Storage/storageAccounts/PrivateEndpointConnectionsApproval/actionMicrosoft.Resources/tags/writeMicrosoft.Network/privateEndpoints/writeMicrosoft.Network/privateEndpoints/readMicrosoft.Network/privateEndpoints/privateDnsZoneGroups/writeMicrosoft.Network/privateEndpoints/privateDnsZoneGroups/readMicrosoft.Network/privateDnsZones/readMicrosoft.Network/privateDnsZones/writeMicrosoft.Network/privateDnsZones/join/actionMicrosoft.Network/privateDnsZones/A/writeMicrosoft.Network/privateDnsZones/virtualNetworkLinks/writeMicrosoft.Network/privateDnsZones/virtualNetworkLinks/readMicrosoft.Network/networkInterfaces/readMicrosoft.Network/virtualNetworks/subnets/readMicrosoft.Network/virtualNetworks/subnets/join/actionMicrosoft.Network/virtualNetworks/join/action
Data-plane actions (5)
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/deleteMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/writeMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/readMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/add/actionMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/move/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The ARO service creates the assignment on the managed resource group. For customer-owned resources outside that group, Microsoft documents customer-created assignments to the corresponding Image Registry operator identity only at the ARO virtual network. Do not infer additional external assignment scopes from the role's Actions.
Common use cases (1)
- Allow the ARO Image Registry operator identity to operate service-managed resources in the managed resource group and only the documented customer-owned resources required by the cluster architecture.
Prerequisites (2)
- Deploy an Azure Red Hat OpenShift cluster with managed identities and create the dedicated user-assigned identity for this operator.
- Prepare only the external network or storage resources named for this operator in the current ARO identity architecture and create the documented customer-owned role assignments before cluster creation.
Best practices (2)
- Use the service-created managed-resource-group assignment and reproduce the published external identity-to-role and scope table exactly when using existing identities and role assignments.
- Keep one managed identity per ARO core operator, create customer-owned assignments at the most limited documented external resource scope, and do not reuse these roles for people or application workloads.
Security considerations (2)
- The operator can list storage account keys, which provide full storage-account data access, and request a blob user-delegation key that can sign SAS tokens for limited blob access. It can also change or delete storage accounts and containers and read, write, move, or delete registry blobs, affecting every image stored in the OpenShift registry.
- A broader customer-created external assignment or a human assignment would grant infrastructure permissions outside the documented ARO component boundary and bypass the separation among core operator identities.
Assignment guidance
Allow the ARO service to create Azure Red Hat OpenShift Image Registry Operator on the managed resource group. For customer-owned infrastructure, assign it only to the dedicated Image Registry operator identity at the ARO virtual network, exactly as listed in the current identity architecture and deployment examples. Do not duplicate the managed-resource-group assignment or extrapolate other external scopes from Actions, and do not grant the role to human administrators.
Related roles (1)
- Azure Red Hat OpenShift Federated Credential: Companion cluster-identity role used to create the federated credentials that let the operator identity authenticate.
Editorial sources (9)
- Azure built-in roles for Containers - Azure RBAC | Microsoft Learn →
Supports: Description, Practical scope, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Understand managed identities in Azure Red Hat OpenShift →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Create an Azure Red Hat OpenShift cluster with managed identities →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Manage account access keys →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.
- Use Azure CLI to create a user delegation SAS for a container or blob →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance, Related roles. Retrieved 2026-07-17.