Azure Blob Storage
FlexFS supports Azure Blob Storage as a block store backend using the Azure SDK for Go. Authentication uses shared key credentials (storage account access key) or Microsoft Entra ID tokens (managed identity).
Storage account
Section titled “Storage account”Create a storage account or use an existing one. FlexFS uses the Blob Storage service.
# Create a resource group (if needed)az group create --name <resource-group> --location eastus
# Create a storage accountaz storage account create \ --name <storage-account> \ --resource-group <resource-group> \ --location eastus \ --sku Standard_LRS \ --kind StorageV2Recommended settings
Section titled “Recommended settings”- Performance tier: Standard is sufficient for most workloads. For latency-sensitive deployments, use a premium block blob account, created with
--kind BlockBlobStorageand--sku Premium_LRSorPremium_ZRS. An existing standard account cannot be converted to premium. - Redundancy: LRS (Locally Redundant Storage) is the minimum. Choose based on your durability requirements.
- Public access: Disable blob public access. FlexFS authenticates all requests.
- Hierarchical namespace (Data Lake): Not required. FlexFS uses flat blob storage.
Container creation
Section titled “Container creation”Create a container within the storage account to hold flexFS blocks:
az storage container create \ --name flexfs-blocks \ --account-name <storage-account>Authentication
Section titled “Authentication”Shared key credentials
Section titled “Shared key credentials”The simplest authentication method uses the storage account name and access key:
# Retrieve the access keyaz storage account keys list \ --account-name <storage-account> \ --resource-group <resource-group> \ --query '[0].value' -o tsvWhen configuring the flexFS block store credentials (--username and --password in configure.flexfs, or --blockUser and --blockPass in free.flexfs init creds for Community):
- Username: The storage account name (e.g.
<storage-account>) - Password: The storage account access key
When no address is configured, flexFS constructs the blob service URL automatically from the storage account name:
https://<storage-account>.blob.core.windows.net/Setting an address replaces that URL outright; see the block store configuration below.
Managed identity
Section titled “Managed identity”When the access key is empty, flexFS authenticates with Microsoft Entra ID:
- Mount clients: The metadata server obtains a token from its host’s managed identity and passes it to mount clients. Only a managed identity works for this; service principal environment variables or an
az loginsession on the metadata server host do not give mount clients access. The host’s default identity is used: its system-assigned identity, or its only user-assigned identity if it has no system-assigned one. - Proxy servers and the metadata server’s own storage access: These use the Azure default credential chain, which includes environment variables (
AZURE_CLIENT_ID,AZURE_TENANT_ID,AZURE_CLIENT_SECRET), workload identity, managed identity, and Azure CLI credentials (az login). A proxy server reads the storage account name fromblockUserin its own credentials file, so set it there as well unless the block store sets an address.
To use managed identity on an Azure VM:
# Assign a system-managed identity to the VMaz vm identity assign \ --name <vm-name> \ --resource-group <resource-group>
# Grant Storage Blob Data Contributor roleaz role assignment create \ --assignee <principal-id> \ --role "Storage Blob Data Contributor" \ --scope "/subscriptions/<subscription-id>/resourceGroups/<resource-group>/providers/Microsoft.Storage/storageAccounts/<storage-account>"Managed identity is the recommended authentication method for production deployments on Azure.
SAS tokens
Section titled “SAS tokens”Azure Shared Access Signatures (SAS) are not supported. In Enterprise, configure.flexfs rejects an address containing ? with 400: invalid address. Community does not check --blockAddr, so do not add a SAS token to it. Use shared key or managed identity as described above.
Block store configuration
Section titled “Block store configuration”When creating a block store via configure.flexfs (Enterprise) or the installer, provide:
| Field | Value |
|---|---|
| Provider | azure |
| Region | Azure region (e.g. eastus) |
| API | azure |
| Bucket | Your container name (e.g. flexfs-blocks) |
| Prefix | Optional key prefix |
| Address | Leave empty for the public cloud (constructed as <storage-account>.blob.core.windows.net); set --address to the full service endpoint for a sovereign cloud, Azure Stack, a custom domain, or the Azurite emulator (http://127.0.0.1:10000/devstoreaccount1) |
Username (--username) | Storage account name (required for shared key, or when no address is set) |
Password (--password) | Storage account access key (or leave empty for managed identity) |