Skip to main content

BlobContainer

resourceType blobstorage · provider azure · sharing Private · cleanup Orphan

Provisions a private Azure Blob Storage container in the environment's storage account and grants the requesting application's workload identity owner access to it. The container's server-side name is namespaced ({namespace}-{containerName}) because the storage account is shared across the environment — read containerName from the connection secret rather than assuming the literal value. No credentials are published: the pod authenticates with its workload identity.

Request it​

Add this to your PlatformApplication's spec.resourceRequirements (optional parameters are in the table below):

resourceRequirements:
- resourceType: blobstorage
provider: azure # selects this backend — the cluster default may differ
resourceName: my-blobstorage # your handle — drives the env-var prefix + secret name

Parameters​

NameTypeRequiredDefaultDescription
containerNamestringno—Container name. Defaults to the claim name. The actual server-side name is namespaced ({namespace}-{containerName}) and sanitized to Azure's container rules, because the storage account is environment-wide — read containerName from the connection secret for the real value. Requesting two blobstorage resources with the same containerName points both at ONE Azure container: a composition cannot see its sibling claims, so nothing detects it. Leave this unset and the claim name keeps them distinct.

Connection​

On grant, a connection secret is published with these tokens and injected into your workload as {RESOURCENAME}_{TOKEN} (UPPER_SNAKE) — e.g. resourceName: my-blobstorage → MY_BLOBSTORAGE_ACCOUNT_NAME, MY_BLOBSTORAGE_CONTAINER_NAME, …:

  • accountName
  • containerName
  • endpoint
  • containerUrl

Status​

FieldDescription
accountNameStorage account holding the container.
containerNameServer-side container name actually created (namespaced).
endpointBlob service endpoint of the storage account.
resourceIdAzure Resource Manager ID of the container.
granted'true' once the requesting application's identity has been granted owner access; 'false' while either that identity or the container's resource ID is still unresolved. Ready does not imply granted.

Auto-generated from the BlobContainer XRD + blobstorage--azure ResourceCapability. Do not edit by hand.