Azure Web and Mobile built-in role

Azure Spring Apps Spring Cloud Gateway Log Reader Role

Reads Azure Spring Apps and Spring Cloud Gateway resource metadata through control-plane reads and streams logs from Spring Cloud Gateway subcomponents through a DataAction. Azure Spring Apps is in retirement and retires on March 31, 2028.

Role-definition permissions are imported from Microsoft Learn. Practical scope, use cases, prerequisites, best practices, security considerations, assignment guidance, and relationships have been reviewed against the official sources below.

Role definition ID: 4301dc2a-25a9-44b0-ae63-3636cf7f2bd2

Control-plane actions (2)

Data-plane actions (1)

Excluded actions (0)

None

Assignable scopes (1)

Practical scope

The documented assignment is on the existing Azure Spring Apps service instance containing the gateway. Parent-scope assignments are inherited by gateways in other Spring Apps instances, while service-instance scope bounds the log stream to one deployment.

Common use cases (2)

Prerequisites (2)

Best practices (3)

Security considerations (3)

Assignment guidance

Assign the gateway log reader directly on the existing Azure Spring Apps service instance to the incident responder or migration engineer who needs the stream. Keep access private or network-filtered, time-bound the assignment, and remove it after troubleshooting or migration validation.

Common questions

When should I assign the Azure Spring Apps Spring Cloud Gateway Log Reader Role Azure role?

Assign Azure Spring Apps Spring Cloud Gateway Log Reader Role when you need to: Stream real-time Spring Cloud Gateway and gateway-operator logs while diagnosing routing, startup, session, or rate-limit behavior in an existing Enterprise instance.; and Collect troubleshooting evidence needed to migrate the gateway workflow from Azure Spring Apps before retirement.. Practical scope: The documented assignment is on the existing Azure Spring Apps service instance containing the gateway. Parent-scope assignments are inherited by gateways in other Spring Apps instances, while service-instance scope bounds the log stream to one deployment.

What permissions does the Azure Spring Apps Spring Cloud Gateway Log Reader Role Azure role grant?

The role definition grants 3 combined control-plane and data-plane actions. Representative operations include: Microsoft.AppPlatform/Spring/read; Microsoft.AppPlatform/Spring/gateways/read; and Microsoft.AppPlatform/Spring/SpringCloudGateway/logstream/action. Review the permission sections above for the complete definition and exclusions.

What are the security risks of the Azure Spring Apps Spring Cloud Gateway Log Reader Role Azure role?

Key considerations when assigning Azure Spring Apps Spring Cloud Gateway Log Reader Role: Gateway logs can reveal routes, upstream behavior, sessions, rate-limit state, and operational failures even though the role cannot change gateway configuration.; A public log-streaming endpoint adds a public inbound IP and requires network filtering in addition to Azure RBAC authentication.; and Parent-scope assignments expose managed-component logs from every inherited Spring Apps instance.. Follow the assignment guidance above and use the narrowest practical scope.

Editorial sources (7)

Official Microsoft Learn documentation →