Azure Blob Storage
Official · maintained by Marmotmarmotdata/azureblob Discover containers from Azure Blob Storage accounts
The Azure Blob Storage plugin discovers containers from Azure Storage accounts. It captures container metadata including access levels, lease status, and custom metadata.
Connection Examples
Required Permissions
The following Azure RBAC role is recommended:
- Storage Blob Data Reader - Read access to containers and blobs
Or use a custom role with these permissions:
Microsoft.Storage/storageAccounts/blobServices/containers/readMicrosoft.Storage/storageAccounts/blobServices/containers/blobs/read
Keyless authentication
On Marmot Cloud or Marmot Enterprise the pipeline can present its own identity instead of an account key. Add a federated identity credential to an app registration or user-assigned managed identity with your Marmot instance as issuer, the pipeline's subject, pipeline:<name> as reported by the pipeline API, and audience api://AzureADTokenExchange; grant that identity Storage Blob Data Reader on the account; set account_name, tenant_id and client_id. No key exists anywhere; Marmot mints a short-lived token for each run.
In the UI
Point-and-click, no config file needed.
- 1 Open Runs Create pipeline
- 2 Pick Azure Blob Storage from the plugin list.
- 3 Fill in the wizard, set a schedule, save.
With the CLI
Save a YAML config, then run marmot ingest.
name: my-azureblob-pipeline
runs:
- azureblob:
# No required fields — see the Configuration tab.$ marmot ingest -c ingest.yamlNot using plugins? Other ways to populate Marmot
Configuration
12 top-level fields. * marks required fields.
tags multiselect Tags to apply to discovered assets
external_links object[] External links to show on all assets
name string Display name for the link
icon string Icon identifier for the link
url string URL to the external resource
filter object Filter discovered assets by name (regex)
include multiselect Include patterns for resource names (regex)
exclude multiselect Exclude patterns for resource names (regex)
audience string Audience of the Marmot identity token. Derived from the credentials' federation settings; set it only when the cloud side expects another
connection_string password Azure Storage connection string
account_name string Azure Storage account name
account_key password Azure Storage account key
tenant_id string Entra tenant of the identity the Marmot identity token is exchanged for. Set with client_id and account_name to federate: no key is needed; grant the identity Storage Blob Data Reader on the account
client_id string Application (client) ID of the app registration or user-assigned managed identity whose federated credential trusts the Marmot issuer
endpoint string Custom endpoint URL (for Azurite or other emulators)
include_metadata bool Include container metadata
- default
- true
include_blob_count bool Count blobs in each container (can be slow for large containers)
- default
- false
Assets emitted
Metadata this plugin attaches to each discovered asset.
Container
AzureBlobContainerFieldsAzureBlobContainerFields defines metadata fields for Azure Blob containers
container_name stringName of the container
last_modified stringLast modification timestamp
etag stringEntity tag for the container
lease_status stringLease status (locked/unlocked)
lease_state stringLease state (available/leased/expired/breaking/broken)
has_immutability_policy boolWhether container has an immutability policy
has_legal_hold boolWhether container has a legal hold
public_access stringPublic access level (none/blob/container)
blob_count intNumber of blobs in the container