Permissions
The actions that govern SQL Server instances, their connection strings, product keys and Data Explorer, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
sqlservercluster/read |
See instances, their configuration, revisions, snapshots, health and external address, and the text of the statements recently submitted in the Data Explorer |
sqlservercluster/write |
Create and change instances; start, stop and restart them; schedule backups. Includes sqlservercluster/delete |
sqlservercluster/delete |
Delete instances |
sqlservercluster/scale |
Set the instance count through the scale route; only one instance is supported |
sqlservercluster/createSnapshot |
Take a snapshot |
sqlservercluster/restoreSnapshot |
Restore a snapshot in place |
sqlservercluster/deleteSnapshot |
Delete a snapshot |
sqlservercluster/readSecrets |
Reveal the connection strings, which carry the sa password |
sqlservercluster/writeSecrets |
Nothing yet: no SQL Server route uses it |
sqlservercluster/manageLicense |
Set or rotate the product key of a paid edition on the License section |
sqlservercluster/readSecrets, sqlservercluster/writeSecrets, sqlservercluster/manageLicense
and the Data Explorer actions below are data actions: a role grants them only when it lists them as
such, so a role that can manage an instance does not by that alone read its credentials or its data.
Important
sqlservercluster/writecan also supply a product key: the create and update routes accept alicenseKeyfield and store it without checkingsqlservercluster/manageLicense.
Data Explorer
| Action | Allows |
|---|---|
sqlservercluster/dataRead |
Open the Data Explorer and browse rows |
sqlservercluster/dataWrite |
Add, change and delete rows on the Browse tab |
sqlservercluster/schemaRead |
List schemas, tables and columns |
sqlservercluster/queryExecute |
Run SELECT |
sqlservercluster/queryExecuteWrite |
Run INSERT, UPDATE, DELETE and MERGE |
sqlservercluster/schemaWrite |
Run CREATE and ALTER |
sqlservercluster/schemaDrop |
Run DROP and TRUNCATE TABLE, together with sqlservercluster/schemaWrite |
Each statement is checked against these before it runs, and running any statement also needs
sqlservercluster/read. See What runs.
sqlservercluster/schemaWrite and sqlservercluster/schemaDrop are declared as data actions, but
the Data Explorer checks them as ordinary actions. A role therefore grants them only when it lists
them among its ordinary actions — as Owner, Contributor, Platform Owner and Platform Contributor do
through */* — and not when it lists them as data actions, as Database Explorer does.
Roles
| Role | See | Create, change | Delete | Snapshots | Connection strings, product key | Data Explorer |
|---|---|---|---|---|---|---|
| Reader, Databases Reader | Yes | No | No | See | No | No |
| Database Explorer | Yes | No | No | See | No | Browse and edit rows, run SELECT, INSERT, UPDATE, DELETE and MERGE; not create, change or drop objects |
| Databases Operator | Yes | Yes | Yes | Take, restore, delete | Yes | No |
| Contributor | Yes | Yes | Yes | Take | Yes | Everything |
| Owner | Yes | Yes | Yes | Take, restore, delete | Yes | Everything |
Platform Owner and Platform Contributor hold every action in every boundary, the Data Explorer included; Platform Reader can see instances. On SQL Server, unlike PostgreSQL, the Data Explorer actions come with Owner and Contributor, so the Database Explorer role is needed only by people who should query without managing the instance — see Database Explorer.
Assign roles on the boundary, the resource group or the instance itself — see Role assignments. An action you lack can be requested as temporary access — see Request access.