Expand description
Azure Blob Storage: logins, finding storage accounts, and listing what is in them.
A signed-in az is asked for tokens, as object_store itself does, rather than its
token cache being read: the cache is an internal format, encrypted to the user on
Windows, and asking keeps MFA and conditional access working without datui knowing
about either. One Resource Graph query finds every storage account the login can
see across its subscriptions, so nobody has to name an account to browse it.
Everything here that touches the network or runs az blocks, and is only called
from a worker.
Structs§
- Account
- One storage account, as Resource Graph describes it.
- Azure
Settings - How to reach Azure Blob Storage for one source.
- Service
Principal - An application’s identity in Entra ID: a client secret, or a federated token file (AKS workload identity) exchanged for a token each time.
Enums§
- Azure
Auth - How a request to one account is authorized.
Constants§
- API_
VERSION - Sent on every request. Without it, anonymous requests are refused with
FeatureVersionMismatch, and newer response fields are left out. - MANAGEMENT_
SCOPE - The scope of a token for Resource Graph, which finds storage accounts.
- STORAGE_
SCOPE - The scope of a token for reading blobs.
Functions§
- az_
login_ evidence - Whether
azhas been used on this machine: its config directory exists. Not proof the login is still good, which only asking can tell. - check_
read - Whether
settingsmay read atpathincontainer: one listing of at most one blob, which needs the same data permission a read does. - describe_
error 403 AuthorizationPermissionMismatch: ...from an error document, with what fixes the one that trips up people who manage their storage in the Portal.- discover_
accounts - Every storage account the signed-in identity can see, across its subscriptions.
- fetch_
account_ key - The first access key of
account, as the Portal fetches them for someone with Owner or Contributor and no data role: Resource Graph for the account’s ID and whether it allows shared keys, thenlistKeyswith a management token fromidentity. - from_
environment - What the environment says about Azure, if anything: a connection string, an account with a key or SAS token, or a service principal (with an account, or to find them).
- identity_
token - A token for
scopefrom an identity:az, Azure PowerShell or a service principal. - is_
folder_ marker - Whether a listed object is only a folder marker. Accounts with hierarchical namespace list every directory twice, once as a prefix and once as an empty blob of the same name; the blob is not data.
- is_
permission_ mismatch - Whether a refusal is the one account keys get past: a sign-in with no data role.
- list_
containers - Containers in one account.
settingsmust already hold a token or key, notAzCli. - not_
signed_ in - Azure tooling on this machine with no sign-in to show for it:
azonPATH, or the Az.Accounts PowerShell module installed. The fix, naming what is there, when so. - parse_
account_ id - The resource ID and shared-key setting of the one account a Resource Graph query found.
- parse_
accounts - The accounts in one Resource Graph response, and the token for the next page.
- parse_
connection_ string - The settings a connection string describes:
AccountName,AccountKey,SharedAccessSignature,BlobEndpoint,EndpointSuffix,DefaultEndpointsProtocol, orUseDevelopmentStorage=truefor Azurite. - parse_
containers - Container names from a
List Containersresponse, and the marker for the next page. - parse_
entra_ token - The access token and expiry from an Entra ID token response.
- parse_
keys - The first key from a
listKeysresponse. - parse_
powershell_ tokens (resource, token, expiry)for each scope in the PowerShell script’s output.- parse_
token - The token and expiry from
az account get-access-token --output json. Newerazgivesexpires_onin seconds; older gives onlyexpiresOnin local time, which is not worth guessing at, so such a token is refreshed on the next request. - polars_
options - Polars’ view of the same settings, for
scan_parqueton anabfss://URL. - powershell_
login_ evidence - Whether Azure PowerShell has been signed in on this machine: its context file exists.
- remember_
token_ reads - Note that a sign-in’s token read from
account. - remembered_
key - The key this session reads
accountwith, when a token was refused and its keys were fetched. - service_
principal - A service principal from
AZURE_TENANT_ID,AZURE_CLIENT_IDand eitherAZURE_CLIENT_SECRETorAZURE_FEDERATED_TOKEN_FILE, the variables the Azure SDKs and AKS workload identity set. - store
- An object store for one container.
settingsmust already hold a token or key. - token
- A token for
scopefrom the signed-inaz. - token_
reads - Whether a sign-in’s token has read from
accountthis session. - with_
account_ key - After a 403 on a sign-in’s token: the same settings with the account’s key, when the fallback is on and the account allows it, else the refusal with the reason.