- Resource Group
- Contributor or Owner role to create and manage resource groups.
- Virtual Network
- Network Contributor role to create and manage virtual networks and subnets.
- Key Vault
- Key Vault Contributor role to create key vaults.
- Key Vault Secrets User role for the agent’s managed identity to list and get secret values.
- Key Vault Administrator or Key Vault Secrets Officer role for other users to list and edit key vault secrets if the ARM template creates the key vault.
- Managed Identity
- Managed Identity Contributor role to create and manage managed identities.
- Container App
- Container App Contributor role to deploy and manage container apps.
- Log Analytics Workspace
- Log Analytics Contributor role to create and manage log analytics workspaces.
- General Permissions
- Contributor or Owner role on the subscription to manage overall resources and permissions.
Deploying resources
The ARM template creates or edits multiple different resources, and the user will need roles capable of deploying these specific resources, as well as the correct role to deploy an ARM template. These resources are:
To create the necessary resources, you will need the following permissions:
