Skip to main content

Module azure

Module azure 

Source
Expand description

Azure Blob Storage: logins, finding storage accounts, and listing what is in them.

A signed-in az is asked for tokens, as object_store itself does, rather than its token cache being read: the cache is an internal format, encrypted to the user on Windows, and asking keeps MFA and conditional access working without datui knowing about either. One Resource Graph query finds every storage account the login can see across its subscriptions, so nobody has to name an account to browse it.

Everything here that touches the network or runs az blocks, and is only called from a worker.

Structs§

Account
One storage account, as Resource Graph describes it.
AzureSettings
How to reach Azure Blob Storage for one source.
ServicePrincipal
An application’s identity in Entra ID: a client secret, or a federated token file (AKS workload identity) exchanged for a token each time.

Enums§

AzureAuth
How a request to one account is authorized.

Constants§

API_VERSION
Sent on every request. Without it, anonymous requests are refused with FeatureVersionMismatch, and newer response fields are left out.
MANAGEMENT_SCOPE
The scope of a token for Resource Graph, which finds storage accounts.
STORAGE_SCOPE
The scope of a token for reading blobs.

Functions§

az_login_evidence
Whether az has been used on this machine: its config directory exists. Not proof the login is still good, which only asking can tell.
check_read
Whether settings may read at path in container: one listing of at most one blob, which needs the same data permission a read does.
describe_error
403 AuthorizationPermissionMismatch: ... from an error document, with what fixes the one that trips up people who manage their storage in the Portal.
discover_accounts
Every storage account the signed-in identity can see, across its subscriptions.
fetch_account_key
The first access key of account, as the Portal fetches them for someone with Owner or Contributor and no data role: Resource Graph for the account’s ID and whether it allows shared keys, then listKeys with a management token from identity.
from_environment
What the environment says about Azure, if anything: a connection string, an account with a key or SAS token, or a service principal (with an account, or to find them).
identity_token
A token for scope from an identity: az, Azure PowerShell or a service principal.
is_folder_marker
Whether a listed object is only a folder marker. Accounts with hierarchical namespace list every directory twice, once as a prefix and once as an empty blob of the same name; the blob is not data.
is_permission_mismatch
Whether a refusal is the one account keys get past: a sign-in with no data role.
list_containers
Containers in one account. settings must already hold a token or key, not AzCli.
not_signed_in
Azure tooling on this machine with no sign-in to show for it: az on PATH, or the Az.Accounts PowerShell module installed. The fix, naming what is there, when so.
paginated_store
The same store, for one page of a listing at a time.
parse_account_id
The resource ID and shared-key setting of the one account a Resource Graph query found.
parse_accounts
The accounts in one Resource Graph response, and the token for the next page.
parse_connection_string
The settings a connection string describes: AccountName, AccountKey, SharedAccessSignature, BlobEndpoint, EndpointSuffix, DefaultEndpointsProtocol, or UseDevelopmentStorage=true for Azurite.
parse_containers
Container names from a List Containers response, and the marker for the next page.
parse_entra_token
The access token and expiry from an Entra ID token response.
parse_keys
The first key from a listKeys response.
parse_powershell_tokens
(resource, token, expiry) for each scope in the PowerShell script’s output.
parse_token
The token and expiry from az account get-access-token --output json. Newer az gives expires_on in seconds; older gives only expiresOn in local time, which is not worth guessing at, so such a token is refreshed on the next request.
polars_options
Polars’ view of the same settings, for scan_parquet on an abfss:// URL.
powershell_login_evidence
Whether Azure PowerShell has been signed in on this machine: its context file exists.
remember_token_reads
Note that a sign-in’s token read from account.
remembered_key
The key this session reads account with, when a token was refused and its keys were fetched.
service_principal
A service principal from AZURE_TENANT_ID, AZURE_CLIENT_ID and either AZURE_CLIENT_SECRET or AZURE_FEDERATED_TOKEN_FILE, the variables the Azure SDKs and AKS workload identity set.
store
An object store for one container. settings must already hold a token or key.
token
A token for scope from the signed-in az.
token_reads
Whether a sign-in’s token has read from account this session.
with_account_key
After a 403 on a sign-in’s token: the same settings with the account’s key, when the fallback is on and the account allows it, else the refusal with the reason.