Theme
Microsoft Azure Blob Storage
Azure Blob Storage is Microsoft's object storage. It is not S3 compatible, so the Storage Connector talks to it through its own Azure VFS type rather than the S3 one.
Step 1: in the Azure portal
- Create a storage account, or pick an existing one. Open Storage accounts and choose Create. Pick the region you want the data in; every performance tier and redundancy option works with SFTP.cloud.
- Create a container. Open the storage account, then Data storage, then Containers, and choose + Container. Keep the anonymous access level at Private.
- Choose how the Connector will authenticate. There are two options:
- An account key: under Security + networking, Access keys, choose Show next to
key1and copy it. The key grants full access to every container in the account, so use it only when the account holds nothing else. - A SAS token, the better choice: open the container, choose Shared access tokens, grant the Read, Add, Create, Write, Delete and List permissions, set an expiry, and choose Generate SAS token and URL. Copy the Blob SAS token. A SAS token is scoped to that one container and expires, which is exactly what you want, as long as you remember that transfers stop when it expires: put the renewal in your calendar.
- An account key: under Security + networking, Access keys, choose Show next to
That is it for the Azure side. Now to the SFTP.cloud side.
Step 2: in your SFTP.cloud Storage Connector
Best performance
Deploy the Storage Connector as close as possible to the storage it handles. For Azure Blob Storage, a virtual machine or a container in Azure Kubernetes Service in the storage account's region are the ideal choices.
Add a new Virtual File System of type Azure. The fields are:
- Container name: the container you created
- Path inside: optional; a folder prefix inside the container, if you do not want the VFS at its root
- Endpoint: leave it empty. Only a sovereign cloud (Azure Government, Azure China) needs its blob service domain here, for example
blob.core.usgovcloudapi.net. - Account name: the storage account
- Authentication method:
Account keyorSAS token, then the corresponding secret
WARNING
Do not forget to press the Save button next to the secret after typing it in, or it will not be saved and nothing will work.
When you save, the Connector tests the storage right away. If it cannot reach it, the form stays open and says why.
Then, still in the Storage Connector UI, go to the Users page and give your users the desired access to the new VFS.
Finally
Test it. Connect through your SFTP.cloud WebClient, create a folder, upload some files, then check in the portal that they landed in the container.
In the manual