Skip to content

Azure Blob Storage

FlexFS supports Azure Blob Storage as a block store backend using the Azure SDK for Go. Authentication uses shared key credentials (storage account access key) or Microsoft Entra ID tokens (managed identity).

Create a storage account or use an existing one. FlexFS uses the Blob Storage service.

Terminal window
# Create a resource group (if needed)
az group create --name <resource-group> --location eastus
# Create a storage account
az storage account create \
--name <storage-account> \
--resource-group <resource-group> \
--location eastus \
--sku Standard_LRS \
--kind StorageV2
  • Performance tier: Standard is sufficient for most workloads. For latency-sensitive deployments, use a premium block blob account, created with --kind BlockBlobStorage and --sku Premium_LRS or Premium_ZRS. An existing standard account cannot be converted to premium.
  • Redundancy: LRS (Locally Redundant Storage) is the minimum. Choose based on your durability requirements.
  • Public access: Disable blob public access. FlexFS authenticates all requests.
  • Hierarchical namespace (Data Lake): Not required. FlexFS uses flat blob storage.

Create a container within the storage account to hold flexFS blocks:

Terminal window
az storage container create \
--name flexfs-blocks \
--account-name <storage-account>

The simplest authentication method uses the storage account name and access key:

Terminal window
# Retrieve the access key
az storage account keys list \
--account-name <storage-account> \
--resource-group <resource-group> \
--query '[0].value' -o tsv

When configuring the flexFS block store credentials (--username and --password in configure.flexfs, or --blockUser and --blockPass in free.flexfs init creds for Community):

  • Username: The storage account name (e.g. <storage-account>)
  • Password: The storage account access key

When no address is configured, flexFS constructs the blob service URL automatically from the storage account name:

https://<storage-account>.blob.core.windows.net/

Setting an address replaces that URL outright; see the block store configuration below.

When the access key is empty, flexFS authenticates with Microsoft Entra ID:

  • Mount clients: The metadata server obtains a token from its host’s managed identity and passes it to mount clients. Only a managed identity works for this; service principal environment variables or an az login session on the metadata server host do not give mount clients access. The host’s default identity is used: its system-assigned identity, or its only user-assigned identity if it has no system-assigned one.
  • Proxy servers and the metadata server’s own storage access: These use the Azure default credential chain, which includes environment variables (AZURE_CLIENT_ID, AZURE_TENANT_ID, AZURE_CLIENT_SECRET), workload identity, managed identity, and Azure CLI credentials (az login). A proxy server reads the storage account name from blockUser in its own credentials file, so set it there as well unless the block store sets an address.

To use managed identity on an Azure VM:

Terminal window
# Assign a system-managed identity to the VM
az vm identity assign \
--name <vm-name> \
--resource-group <resource-group>
# Grant Storage Blob Data Contributor role
az role assignment create \
--assignee <principal-id> \
--role "Storage Blob Data Contributor" \
--scope "/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Storage/storageAccounts/<storage-account>"

Managed identity is the recommended authentication method for production deployments on Azure.

Azure Shared Access Signatures (SAS) are not supported. In Enterprise, configure.flexfs rejects an address containing ? with 400: invalid address. Community does not check --blockAddr, so do not add a SAS token to it. Use shared key or managed identity as described above.

When creating a block store via configure.flexfs (Enterprise) or the installer, provide:

FieldValue
Providerazure
RegionAzure region (e.g. eastus)
APIazure
BucketYour container name (e.g. flexfs-blocks)
PrefixOptional key prefix
AddressLeave empty for the public cloud (constructed as <storage-account>.blob.core.windows.net); set --address to the full service endpoint for a sovereign cloud, Azure Stack, a custom domain, or the Azurite emulator (http://127.0.0.1:10000/devstoreaccount1)
Username (--username)Storage account name (required for shared key, or when no address is set)
Password (--password)Storage account access key (or leave empty for managed identity)