BlobContainer
resourceType blobstorage · provider azure · sharing Private · cleanup Orphan
Provisions a private Azure Blob Storage container in the environment's storage account and grants the requesting application's workload identity owner access to it. The container's server-side name is namespaced ({namespace}-{containerName}) because the storage account is shared across the environment — read containerName from the connection secret rather than assuming the literal value. No credentials are published: the pod authenticates with its workload identity.
Request it
Add this to your PlatformApplication's spec.resourceRequirements (optional parameters are in the table below):
resourceRequirements:
- resourceType: blobstorage
provider: azure # selects this backend — the cluster default may differ
resourceName: my-blobstorage # your handle — drives the env-var prefix + secret name
Parameters
| Name | Type | Required | Default | Description |
|---|---|---|---|---|
containerName | string | no | — | Container name. Defaults to the claim name. The actual server-side name is namespaced ({namespace}-{containerName}) and sanitized to Azure's container rules, because the storage account is environment-wide — read containerName from the connection secret for the real value. Requesting two blobstorage resources with the same containerName points both at ONE Azure container: a composition cannot see its sibling claims, so nothing detects it. Leave this unset and the claim name keeps them distinct. |
Connection
On grant, a connection secret is published with these tokens and injected into your workload as {RESOURCENAME}_{TOKEN} (UPPER_SNAKE) — e.g. resourceName: my-blobstorage → MY_BLOBSTORAGE_ACCOUNT_NAME, MY_BLOBSTORAGE_CONTAINER_NAME, …:
accountNamecontainerNameendpointcontainerUrl
Status
| Field | Description |
|---|---|
accountName | Storage account holding the container. |
containerName | Server-side container name actually created (namespaced). |
endpoint | Blob service endpoint of the storage account. |
resourceId | Azure Resource Manager ID of the container. |
granted | 'true' once the requesting application's identity has been granted owner access; 'false' while either that identity or the container's resource ID is still unresolved. Ready does not imply granted. |
Auto-generated from the BlobContainer XRD + blobstorage--azure ResourceCapability. Do not edit by hand.