gpt4 book ai didi

azure - Azure RBAC 是附加的还是最少允许的角色获胜?

转载 作者:行者123 更新时间:2023-12-03 01:24:08 25 4
gpt4 key购买 nike

我想了解 Azure RBAC 资源角色的效果。如果说我在存储帐户级别分配了一个“存储 blob 数据贡献者”角色,并在容器级别分配了一个“存储 blob 读取器角色”,则哪一个角色将生效,是容器角色还是在存储帐户设置的角色层,因为它处于更高的级别?

最佳答案

Azure RBAC 角色是累加的。从这里link :

So what happens if you have multiple overlapping role assignments?Azure RBAC is an additive model, so your effective permissions are thesum of your role assignments. Consider the following example where auser is granted the Contributor role at the subscription scope and theReader role on a resource group. The sum of the Contributorpermissions and the Reader permissions is effectively the Contributorrole for the subscription. Therefore, in this case, the Reader roleassignment has no impact.

在您的情况下,如果您在存储帐户级别分配了“存储 Blob 数据贡献者”角色,并在容器级别分配了“存储 Blob 读取者角色”,则该用户将具有“存储 Blob 数据贡献者”角色在容器级别。

关于azure - Azure RBAC 是附加的还是最少允许的角色获胜?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/67419543/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com