@@ -44,38 +44,38 @@ The Azure Arc built-in role **Defender Kubernetes Agent Operator** to provision
4444
4545## AWS Agentless threat protection permissions
4646
47- - AzureDefenderKubernetesRole:
48- - sts: AssumeRole
49- - sts: AssumeRoleWithWebIdentity
50- - logs: PutSubscriptionFilter
51- - logs: DescribeSubscriptionFilters
52- - logs: DescribeLogGroups
53- - logs: PutRetentionPolicy
54- - firehose:*
55- - iam: PassRole
56- - eks: UpdateClusterConfig
57- - eks: DescribeCluster
58- - eks: CreateAccessEntry
59- - eks: ListAccessEntries
60- - eks: AssociateAccessPolicy
61- - eks: ListAssociatedAccessPolicies
62- - sqs:*
63- - s3:*
47+ - AzureDefenderKubernetesRole (default role name: ** MDCContainersK8sRole** ):
48+
49+ - sts: AssumeRole
50+ - sts: AssumeRoleWithWebIdentity
51+ - logs: PutSubscriptionFilter
52+ - logs: DescribeSubscriptionFilters
53+ - logs: DescribeLogGroups
54+ - logs: PutRetentionPolicy
55+ - firehose:*
56+ - iam: PassRole
57+ - eks: UpdateClusterConfig
58+ - eks: DescribeCluster
59+ - eks: CreateAccessEntry
60+ - eks: ListAccessEntries
61+ - eks: AssociateAccessPolicy
62+ - eks: ListAssociatedAccessPolicies
63+ - sqs:*
64+ - s3:*
6465
6566- AzureDefenderKubernetesScubaReaderRole (default role name: ** MDCContainersK8sDataCollectionRole** ):
67+ - sts: AssumeRole
68+ - sts: AssumeRoleWithWebIdentity
69+ - sqs: ReceiveMessage
70+ - sqs: DeleteMessage
71+ - s3: GetObject
72+ - s3: GetBucketLocation
73+
6674- AzureDefenderCloudWatchToKinesisRole (default role name: ** MDCContainersK8sCloudWatchToKinesisRole** ):
6775 - sts: AssumeRole
6876 - firehose:*
6977
7078- AzureDefenderKinesisToS3Role (default role name: ** MDCContainersK8sKinesisToS3Role** ):
71- - sts: AssumeRole
72- - s3: AbortMultipartUpload
73- - s3: GetBucketLocation
74- - s3: GetObject
75- - s3: ListBucket
76- - s3: ListBucketMultipartUploads
77- - s3: PutObject
78-
7979- MDCContainersAgentlessDiscoveryK8sRole
8080 - sts: AssumeRoleWithWebIdentity
8181 - eks: UpdateClusterConfig
0 commit comments