Mods
Azure

IAM Role: Azure/AKS/metadata

PermissionGrant
microsoft.containerservice/containerservices/readmetadata
microsoft.containerservice/managedclusters/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/diagnosticsettings/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/metricdefinitions/readmetadata
microsoft.containerservice/managedclusters/accessprofiles/readmetadata
microsoft.containerservice/managedclusters/providers/microsoft.insights/logdefinitions/readmetadata
microsoft.containerservice/locations/operations/readmetadata
microsoft.containerservice/locations/orchestrators/readmetadata
microsoft.containerservice/managedclusters/upgradeprofiles/readmetadata
microsoft.containerservice/operations/readmetadata
microsoft.containerservice/locations/operationresults/readmetadata
microsoft.containerservice/openshiftmanagedclusters/readmetadata
microsoft.containerservice/openshiftclusters/readmetadata
microsoft.containerservice/managedclusters/agentpools/readmetadata
microsoft.containerservice/managedclusters/detectors/readmetadata
microsoft.containerservice/managedclusters/agentpools/upgradeProfiles/readmetadata
microsoft.containerservice/managedclusters/diagnosticsstate/readmetadata
microsoft.containerservice/managedclusters/availableagentpoolversions/readmetadata
microsoft.resources/deployments/operations/readmetadata
microsoft.resources/deployments/readmetadata
microsoft.resources/subscriptions/resourcegroups/readmetadata