Skip to content

Commit 281a032

Browse files
Merge pull request #2555 from EyalGur74/docs-editor/containers-permissions-1772026493
Update containers-permissions.md
2 parents 02f302a + 35ac921 commit 281a032

1 file changed

Lines changed: 20 additions & 20 deletions

File tree

articles/defender-for-cloud/containers-permissions.md

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -62,26 +62,26 @@ The Azure Arc built-in role **Defender Kubernetes Agent Operator** to provision
6262
- sqs:*
6363
- s3:*
6464

65-
- AzureDefenderKubernetesScubaReaderRole:
66-
- sts:AssumeRole
67-
- sts:AssumeRoleWithWebIdentity
68-
- sqs:ReceiveMessage
69-
- sqs:DeleteMessage
70-
- s3:GetObject
71-
- s3:GetBucketLocation
72-
73-
- AzureDefenderCloudWatchToKinesisRole:
74-
- sts:AssumeRole
75-
- firehose:*
76-
77-
- AzureDefenderKinesisToS3Role:
78-
- sts:AssumeRole
79-
- s3:AbortMultipartUpload
80-
- s3:GetBucketLocation
81-
- s3:GetObject
82-
- s3:ListBucket
83-
- s3:ListBucketMultipartUploads
84-
- s3:PutObject
65+
- AzureDefenderKubernetesScubaReaderRole (default role name: **MDCContainersK8sDataCollectionRole**):
66+
- sts:AssumeRole
67+
- sts:AssumeRoleWithWebIdentity
68+
- sqs:ReceiveMessage
69+
- sqs:DeleteMessage
70+
- s3:GetObject
71+
- s3:GetBucketLocation
72+
73+
- AzureDefenderCloudWatchToKinesisRole (default role name: **MDCContainersK8sCloudWatchToKinesisRole**):
74+
- sts:AssumeRole
75+
- firehose:*
76+
77+
- AzureDefenderKinesisToS3Role (default role name: **MDCContainersK8sKinesisToS3Role**):
78+
- sts:AssumeRole
79+
- s3:AbortMultipartUpload
80+
- s3:GetBucketLocation
81+
- s3:GetObject
82+
- s3:ListBucket
83+
- s3:ListBucketMultipartUploads
84+
- s3:PutObject
8585

8686
- MDCContainersAgentlessDiscoveryK8sRole
8787
- sts:AssumeRoleWithWebIdentity

0 commit comments

Comments
 (0)