Azure Web and Mobile built-in role

Azure Spring Apps Spring Cloud Gateway Log Reader Role

Reads Azure Spring Apps and Spring Cloud Gateway resource metadata through control-plane reads and streams logs from Spring Cloud Gateway subcomponents through a DataAction. Azure Spring Apps is in retirement and retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4301dc2a-25a9-44b0-ae63-3636cf7f2bd2

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance containing the gateway. Parent-scope assignments are inherited by gateways in other Spring Apps instances, while service-instance scope bounds the log stream to one deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the gateway log reader directly on the existing Azure Spring Apps service instance to the incident responder or migration engineer who needs the stream. Keep access private or network-filtered, time-bound the assignment, and remove it after troubleshooting or migration validation.

Editorial sources (7)

Official Microsoft Learn documentation →