Azure Containers built-in role

Azure Red Hat OpenShift Machine API Operator

Azure Red Hat OpenShift Machine API Operator is a service-agent role for the user-assigned managed identity associated with the Machine API operator. It allows that operator to manage cluster machine lifecycle through Azure virtual machines, disks, identities, network interfaces, load balancers, public IPs, and related infrastructure. Azure Red Hat OpenShift creates a separate assignment of this role on the ARO managed resource group for the service-managed resources. Its published permissions are Azure control-plane Actions with no DataActions; it is not a human OpenShift administration role.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 0358943c-7e01-48ba-8889-02cc51d78637

Control-plane actions (35)

Data-plane actions (0)

None — this role grants no data-plane (data access) actions.

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The ARO service creates the assignment on the managed resource group. For customer-owned resources outside that group, Microsoft documents customer-created assignments to the corresponding Machine API operator identity only at the control-plane and worker subnets plus the documented optional NSG, route table, and Disk Encryption Set resources. Do not infer additional external assignment scopes from the role's Actions.

Common use cases (1)

Prerequisites (2)

Best practices (2)

Security considerations (2)

Assignment guidance

Allow the ARO service to create Azure Red Hat OpenShift Machine API Operator on the managed resource group. For customer-owned infrastructure, assign it only to the dedicated Machine API operator identity at the control-plane and worker subnets plus the documented optional NSG, route table, and Disk Encryption Set resources, exactly as listed in the current identity architecture and deployment examples. Do not duplicate the managed-resource-group assignment or extrapolate other external scopes from Actions, and do not grant the role to human administrators.

Related roles (1)

Editorial sources (7)

Official Microsoft Learn documentation →