Skip to main content

Module azure

Module azure 

Source
Expand description

An Azure Blob Storage implementation of Blob storage.

Structsยง

AzureBlob
Implementation of Blob backed by Azure Blob Storage.
AzureBlobConfig
Configuration for opening an AzureBlob.
ChainedCredential ๐Ÿ”’
A TokenCredential that tries each of its sources in order and returns the first token obtained.
FixedAssertion ๐Ÿ”’
A ClientAssertion that always supplies the same assertion.
RefreshingWorkloadIdentityCredential ๐Ÿ”’
A TokenCredential for AKS-style workload identity that re-reads the projected service account token file on every AAD access token refresh.
TimeoutCredential ๐Ÿ”’
A TokenCredential that fails token requests of inner that take longer than timeout.

Constantsยง

AZURE_CLIENT_ID ๐Ÿ”’
AZURE_CLIENT_SECRET ๐Ÿ”’
AZURE_FEDERATED_TOKEN ๐Ÿ”’
AZURE_FEDERATED_TOKEN_FILE ๐Ÿ”’
AZURE_TENANT_ID ๐Ÿ”’
Environment variables that configure AKS-style workload identity and service principal credentials. The names match the ones the Azure SDKsโ€™ default credential chains read.
EMULATOR_ACCOUNT ๐Ÿ”’
The account name of the Azurite emulator.
EMULATOR_ACCOUNT_KEY ๐Ÿ”’
The account key of the Azurite emulatorโ€™s EMULATOR_ACCOUNT.
GET_CONCURRENCY ๐Ÿ”’
Maximum number of partitions a blob get fetches at once.
GET_PARTITION_SIZE ๐Ÿ”’
Size of the ranges a blob get fetches concurrently.
MANAGED_IDENTITY_TIMEOUT ๐Ÿ”’
Maximum time the default credential chain waits for a managed identity token before trying the next credential. Outside of Azure the IMDS endpoint is unreachable, and the credentialโ€™s own retries would otherwise delay falling through to the Azure CLI by over a minute.
TOKEN_REFRESH_BUFFER ๐Ÿ”’
Time before an access tokenโ€™s expiry at which its refresh task fetches a replacement, so requests keep being served from an unexpired token while the refresh round trip to AAD is in flight.
TOKEN_REFRESH_RETRY_INTERVAL ๐Ÿ”’
Minimum time a refresh task waits between fetch attempts once a refresh is due. This paces retries after failures, e.g. when AAD is transiently unreachable, and prevents hot-looping if issued tokens are already within TOKEN_REFRESH_BUFFER of expiry.

Functionsยง

download_range ๐Ÿ”’
Downloads the partition of blob that starts at offset, or returns None if the blob does not exist.
download_total_len ๐Ÿ”’
Returns the total size of the blob a download response is for.
emulator_sas_token ๐Ÿ”’
Returns an account SAS query string that grants full access to the emulatorโ€™s blob service, signed with the emulatorโ€™s well-known account key.
fetch_token ๐Ÿ”’
Reads the projected service account token file and exchanges its contents for an AAD access token.
read_body ๐Ÿ”’
Reads a downloadโ€™s body to its end.
redacted_url ๐Ÿ”’
Returns url without its query string, which may hold a SAS token.
refresh_task ๐Ÿ”’
Keeps slot holding an unexpired token by fetching a replacement within refresh_buffer of the current tokenโ€™s expiry. A failed fetch leaves the current token in place and is retried after retry_interval.
token_credential ๐Ÿ”’
Returns the token credential to use when the blob URL carries no SAS token.

Type Aliasesยง

ExchangeFn ๐Ÿ”’
Exchanges a client assertion (the projected service account token) for an AAD access token with the given scopes.
TokenSlot ๐Ÿ”’
A shared slot holding the current access token for one scope set.