Below is a series of commands that permits the kubelet to perform the role of “Storage Account Contributor”. This allows kubelet to create and manage Azure Storage accounts in a specified resource group.
First, retrieve the kubetlet identity.
az aks show --resource-group rg-aks-demo --name aks-demo-cluster --query identityProfile.kubeletidentity.clientId -o tsv
The behavior of this command has been altered by the following extension: aks-preview
11111111-1111-4111-8111-111111111111
Then retrieve your subscription ID:
az account show --query id -o tsv
22222222-2222-4222-8222-222222222222
Retrieve the node resource group of your aks cluster:
az aks show --resource-group rg-aks-demo --name aks-demo-cluster --query nodeResourceGroup -o tsv
The behavior of this command has been altered by the following extension: aks-preview
MC_rg-aks-demo_aks-demo-cluster_eastus
Create the role using the details fetched in the previous steps:
az role assignment create --role "Storage Account Contributor" --assignee 11111111-1111-4111-8111-111111111111 --scope "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus"
{
"createdBy": "33333333-3333-4333-8333-333333333333",
"createdOn": "2026-10-07T00:00:00+00:00",
"id": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus/providers/Microsoft.Authorization/roleAssignments/44444444-4444-4444-8444-444444444444",
"name": "44444444-4444-4444-8444-444444444444",
"principalId": "55555555-5555-4555-8555-555555555555",
"principalName": "11111111-1111-4111-8111-111111111111",
"principalType": "ServicePrincipal",
"resourceGroup": "MC_rg-aks-demo_aks-demo-cluster_eastus",
"roleDefinitionId": "/subscriptions/22222222-2222-4222-8222-222222222222/providers/Microsoft.Authorization/roleDefinitions/17d1049b-9a84-46fb-8f53-869881c3d3ab",
"roleDefinitionName": "Storage Account Contributor",
"scope": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus",
"type": "Microsoft.Authorization/roleAssignments",
"updatedBy": "33333333-3333-4333-8333-333333333333",
"updatedOn": "2026-10-07T00:00:00+00:00"
}
The role appears in the listing:
az role assignment list
[
{
"createdBy": "33333333-3333-4333-8333-333333333333",
"createdOn": "2026-10-07T00:00:00+00:00",
"id": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus/providers/Microsoft.Authorization/roleAssignments/44444444-4444-4444-8444-444444444444",
"name": "44444444-4444-4444-8444-444444444444",
"principalId": "55555555-5555-4555-8555-555555555555",
"principalName": "11111111-1111-4111-8111-111111111111",
"principalType": "ServicePrincipal",
"resourceGroup": "MC_rg-aks-demo_aks-demo-cluster_eastus",
"roleDefinitionId": "/subscriptions/22222222-2222-4222-8222-222222222222/providers/Microsoft.Authorization/roleDefinitions/17d1049b-9a84-46fb-8f53-869881c3d3ab",
"roleDefinitionName": "Storage Account Contributor",
"scope": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus",
"type": "Microsoft.Authorization/roleAssignments",
"updatedBy": "33333333-3333-4333-8333-333333333333",
"updatedOn": "2026-10-07T00:00:00+00:00"
}
]