skip to content
Alvin Lucillo

Granting role to kubelet

/ 1 min read

Below is a series of commands that permits the kubelet to perform the role of “Storage Account Contributor”. This allows kubelet to create and manage Azure Storage accounts in a specified resource group.

First, retrieve the kubetlet identity.

az aks show --resource-group rg-aks-demo --name aks-demo-cluster --query identityProfile.kubeletidentity.clientId -o tsv
The behavior of this command has been altered by the following extension: aks-preview
11111111-1111-4111-8111-111111111111

Then retrieve your subscription ID:

az account show --query id -o tsv
22222222-2222-4222-8222-222222222222

Retrieve the node resource group of your aks cluster:

az aks show --resource-group rg-aks-demo --name aks-demo-cluster --query nodeResourceGroup -o tsv
The behavior of this command has been altered by the following extension: aks-preview
MC_rg-aks-demo_aks-demo-cluster_eastus

Create the role using the details fetched in the previous steps:

az role assignment create --role "Storage Account Contributor" --assignee 11111111-1111-4111-8111-111111111111 --scope "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus"
{
  "createdBy": "33333333-3333-4333-8333-333333333333",
  "createdOn": "2026-10-07T00:00:00+00:00",
  "id": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus/providers/Microsoft.Authorization/roleAssignments/44444444-4444-4444-8444-444444444444",
  "name": "44444444-4444-4444-8444-444444444444",
  "principalId": "55555555-5555-4555-8555-555555555555",
  "principalName": "11111111-1111-4111-8111-111111111111",
  "principalType": "ServicePrincipal",
  "resourceGroup": "MC_rg-aks-demo_aks-demo-cluster_eastus",
  "roleDefinitionId": "/subscriptions/22222222-2222-4222-8222-222222222222/providers/Microsoft.Authorization/roleDefinitions/17d1049b-9a84-46fb-8f53-869881c3d3ab",
  "roleDefinitionName": "Storage Account Contributor",
  "scope": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus",
  "type": "Microsoft.Authorization/roleAssignments",
  "updatedBy": "33333333-3333-4333-8333-333333333333",
  "updatedOn": "2026-10-07T00:00:00+00:00"
}

The role appears in the listing:

az role assignment list
[
  {
    "createdBy": "33333333-3333-4333-8333-333333333333",
    "createdOn": "2026-10-07T00:00:00+00:00",
    "id": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus/providers/Microsoft.Authorization/roleAssignments/44444444-4444-4444-8444-444444444444",
    "name": "44444444-4444-4444-8444-444444444444",
    "principalId": "55555555-5555-4555-8555-555555555555",
    "principalName": "11111111-1111-4111-8111-111111111111",
    "principalType": "ServicePrincipal",
    "resourceGroup": "MC_rg-aks-demo_aks-demo-cluster_eastus",
    "roleDefinitionId": "/subscriptions/22222222-2222-4222-8222-222222222222/providers/Microsoft.Authorization/roleDefinitions/17d1049b-9a84-46fb-8f53-869881c3d3ab",
    "roleDefinitionName": "Storage Account Contributor",
    "scope": "/subscriptions/22222222-2222-4222-8222-222222222222/resourceGroups/MC_rg-aks-demo_aks-demo-cluster_eastus",
    "type": "Microsoft.Authorization/roleAssignments",
    "updatedBy": "33333333-3333-4333-8333-333333333333",
    "updatedOn": "2026-10-07T00:00:00+00:00"
  }
]