Expand description
An Azure Blob Storage implementation of Blob storage.
Structsยง
- Azure
Blob - Implementation of Blob backed by Azure Blob Storage.
- Azure
Blob Config - Configuration for opening an AzureBlob.
- Chained
Credential ๐ - A TokenCredential that tries each of its sources in order and returns the first token obtained.
- Fixed
Assertion ๐ - A ClientAssertion that always supplies the same assertion.
- Refreshing
Workload ๐Identity Credential - A TokenCredential for AKS-style workload identity that re-reads the projected service account token file on every AAD access token refresh.
- Timeout
Credential ๐ - A TokenCredential that fails token requests of
innerthat take longer thantimeout.
Constantsยง
- AZURE_
CLIENT_ ๐ID - AZURE_
CLIENT_ ๐SECRET - AZURE_
FEDERATED_ ๐TOKEN - AZURE_
FEDERATED_ ๐TOKEN_ FILE - AZURE_
TENANT_ ๐ID - Environment variables that configure AKS-style workload identity and service principal credentials. The names match the ones the Azure SDKsโ default credential chains read.
- EMULATOR_
ACCOUNT ๐ - The account name of the Azurite emulator.
- EMULATOR_
ACCOUNT_ ๐KEY - The account key of the Azurite emulatorโs EMULATOR_ACCOUNT.
- GET_
CONCURRENCY ๐ - Maximum number of partitions a blob get fetches at once.
- GET_
PARTITION_ ๐SIZE - Size of the ranges a blob get fetches concurrently.
- MANAGED_
IDENTITY_ ๐TIMEOUT - Maximum time the default credential chain waits for a managed identity token before trying the next credential. Outside of Azure the IMDS endpoint is unreachable, and the credentialโs own retries would otherwise delay falling through to the Azure CLI by over a minute.
- TOKEN_
REFRESH_ ๐BUFFER - Time before an access tokenโs expiry at which its refresh task fetches a replacement, so requests keep being served from an unexpired token while the refresh round trip to AAD is in flight.
- TOKEN_
REFRESH_ ๐RETRY_ INTERVAL - Minimum time a refresh task waits between fetch attempts once a refresh is due. This paces retries after failures, e.g. when AAD is transiently unreachable, and prevents hot-looping if issued tokens are already within TOKEN_REFRESH_BUFFER of expiry.
Functionsยง
- download_
range ๐ - Downloads the partition of
blobthat starts atoffset, or returnsNoneif the blob does not exist. - download_
total_ ๐len - Returns the total size of the blob a download response is for.
- emulator_
sas_ ๐token - Returns an account SAS query string that grants full access to the emulatorโs blob service, signed with the emulatorโs well-known account key.
- fetch_
token ๐ - Reads the projected service account token file and exchanges its contents for an AAD access token.
- read_
body ๐ - Reads a downloadโs body to its end.
- redacted_
url ๐ - Returns
urlwithout its query string, which may hold a SAS token. - refresh_
task ๐ - Keeps
slotholding an unexpired token by fetching a replacement withinrefresh_bufferof the current tokenโs expiry. A failed fetch leaves the current token in place and is retried afterretry_interval. - token_
credential ๐ - Returns the token credential to use when the blob URL carries no SAS token.
Type Aliasesยง
- Exchange
Fn ๐ - Exchanges a client assertion (the projected service account token) for an AAD access token with the given scopes.
- Token
Slot ๐ - A shared slot holding the current access token for one scope set.