Azure Blob Storage

Official · maintained by Marmot
marmotdata/azureblob

Discover containers from Azure Blob Storage accounts

Storage Assets Experimental

The Azure Blob Storage plugin discovers containers from Azure Storage accounts. It captures container metadata including access levels, lease status, and custom metadata.

Connection Examples

Required Permissions

The following Azure RBAC role is recommended:

  • Storage Blob Data Reader - Read access to containers and blobs

Or use a custom role with these permissions:

  • Microsoft.Storage/storageAccounts/blobServices/containers/read
  • Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read

Keyless authentication

On Marmot Cloud or Marmot Enterprise the pipeline can present its own identity instead of an account key. Add a federated identity credential to an app registration or user-assigned managed identity with your Marmot instance as issuer, the pipeline's subject, pipeline:<name> as reported by the pipeline API, and audience api://AzureADTokenExchange; grant that identity Storage Blob Data Reader on the account; set account_name, tenant_id and client_id. No key exists anywhere; Marmot mints a short-lived token for each run.