Azure Web and Mobile built-in role
Azure Spring Apps Spring Cloud Gateway Log Reader Role
Reads Azure Spring Apps and Spring Cloud Gateway resource metadata through control-plane reads and streams logs from Spring Cloud Gateway subcomponents through a DataAction. Azure Spring Apps is in retirement and retires on March 31, 2028.
Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.
Role definition ID: 4301dc2a-25a9-44b0-ae63-3636cf7f2bd2
Control-plane actions (2)
Microsoft.AppPlatform/Spring/readMicrosoft.AppPlatform/Spring/gateways/read
Data-plane actions (1)
Microsoft.AppPlatform/Spring/SpringCloudGateway/logstream/action
Excluded actions (0)
None
Assignable scopes (1)
/
Practical scope
The documented assignment is on the existing Azure Spring Apps service instance containing the gateway. Parent-scope assignments are inherited by gateways in other Spring Apps instances, while service-instance scope bounds the log stream to one deployment.
Common use cases (2)
- Stream real-time Spring Cloud Gateway and gateway-operator logs while diagnosing routing, startup, session, or rate-limit behavior in an existing Enterprise instance.
- Collect troubleshooting evidence needed to migrate the gateway workflow from Azure Spring Apps before retirement.
Prerequisites (2)
- An existing Enterprise-plan Azure Spring Apps instance must contain Spring Cloud Gateway, and Azure CLI must use the Azure Spring Apps extension version 1.24.0 or later.
- For a virtual-network-injected instance, use private access or deliberately enable and network-filter the public log-streaming endpoint.
Best practices (3)
- Use diagnostics settings for ongoing analysis and reserve live component logs for time-bounded troubleshooting.
- Assign directly on the service instance and protect any public endpoint with network security group rules.
- Remove the assignment after diagnosis and migrate the gateway workload before March 31, 2028.
Security considerations (3)
- Gateway logs can reveal routes, upstream behavior, sessions, rate-limit state, and operational failures even though the role cannot change gateway configuration.
- A public log-streaming endpoint adds a public inbound IP and requires network filtering in addition to Azure RBAC authentication.
- Parent-scope assignments expose managed-component logs from every inherited Spring Apps instance.
Assignment guidance
Assign the gateway log reader directly on the existing Azure Spring Apps service instance to the incident responder or migration engineer who needs the stream. Keep access private or network-filtered, time-bound the assignment, and remove it after troubleshooting or migration validation.
Editorial sources (7)
- Azure built-in roles for Web and Mobile - Azure RBAC | Microsoft Learn →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Understand Azure role definitions →
Supports: Description, Security considerations. Retrieved 2026-07-17.
- Steps to assign an Azure role →
Supports: Assignment guidance. Retrieved 2026-07-17.
- Understand scope for Azure RBAC →
Supports: Practical scope, Assignment guidance. Retrieved 2026-07-17.
- Best practices for Azure RBAC →
Supports: Best practices, Assignment guidance. Retrieved 2026-07-17.
- Stream Azure Spring Apps managed component logs in real time →
Supports: Description, Practical scope, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.
- Azure Spring Apps retirement announcement →
Supports: Description, Common use cases, Prerequisites, Best practices, Security considerations, Assignment guidance. Retrieved 2026-07-17.