Permissions
The actions that govern function namespaces and functions, and the roles that hold them.
Actions
| Action | Allows |
|---|---|
functions/read |
See function namespaces and functions, their metrics and the namespace's build history |
functions/write |
Create and change function namespaces and functions, and deploy code. It also allows everything functions/delete allows |
functions/delete |
Delete function namespaces and functions |
functions/scale |
Set a function's number of replicas through the API's scale call |
functions/readLogs |
Stream a function's logs |
functions/readLogs is a data action: a role only grants it when it lists it as one.
Roles
| Role | See | Create, change, deploy | Delete | Logs |
|---|---|---|---|---|
| Reader | Yes | No | No | Yes |
| Functions Reader | Yes | No | No | Yes |
| Functions Operator | Yes | Yes | Yes | Yes |
| Contributor, Owner | Yes | Yes | Yes | Yes |
Functions Operator also holds functions/scale, and it can delete because functions/write includes
functions/delete; Contributor and Owner hold every action.
Where to assign them
Assign roles on the boundary or the resource group — see Role assignments. A function namespace's page has no Access Control tab.
The namespace's managed identity
What the functions themselves may do is decided by the roles of their namespace's managed
identity, not by yours. Giving the identity a role needs rbac/members/write, which the Owner
role has — see Secrets and the managed identity.