Permissions
The actions that govern metrics, alerts and the Health page, the scope each is checked at, and the roles that hold them.
Actions
| Action | Allows | Checked at |
|---|---|---|
monitoring/read |
Seeing a resource's metrics and alerts; listing the alerts firing in a boundary | The resource, its resource group or its boundary |
monitoring/platform/read |
Opening the Health page and its Nodes tab: node capacity, unhealthy volumes and platform alerts | The platform root only |
monitoring/platform/alerts/write |
Raising and clearing a platform alert | The platform root only |
monitoring/platform/alerts/write is meant for platform components, which hold it through the
service role Platform Alert Publisher. Platform Owner and Platform Contributor hold it too, through
their */* wildcard.
Important
Whoever holds
monitoring/platform/alerts/writeat the root can raise a platform alert under any id that is not one of the module's own rules, and can resolve any alert raised that way — including one another platform component raised, such as the backups' alert about a filling database volume. Platform Owners and Platform Contributors can do this through the API.
Roles
| Role | monitoring/read |
monitoring/platform/read |
monitoring/platform/alerts/write |
|---|---|---|---|
| Reader | Yes, where assigned | No | No |
| Contributor, Owner | Yes, where assigned | Not from a boundary or below | Not from a boundary or below |
| Every scoped reader and operator role, such as Apps Reader, Databases Operator or Storage Reader, and Database Explorer | Yes, where assigned | No | No |
| Platform Reader | Yes | Yes | No |
| Platform Contributor, Platform Owner | Yes | Yes | Yes |
| Platform Alert Publisher | No | No | Yes |
A role assigned on a boundary or below never reaches the root-only actions, whatever it lists:
Owner and Contributor list both through */*, but only an assignment at the root would give them —
see Root-scoped actions. The roles themselves are
described in Built-in roles, and a custom role can list these actions
like any other — see Custom roles.
The Health page's other tabs need actions of the platform's core: Map needs
kernel/platform/read, held by the three platform roles, and Database needs
kernel/platform/diagnose, held by Platform Owner only — see
The Health page.
What the portal shows
- Without
monitoring/readon a resource, its Active alerts card and Alerts tab are not shown, and its Metrics card shows an error instead of charts. - Health is in the sidebar only for those who hold
monitoring/platform/readat the root.
The platform checks every request as well.