1
0
mirror of https://github.com/distribution/distribution synced 2024-11-12 05:45:51 +01:00
distribution/docs/content/storage-drivers/azure.md
Milos Gajdos d3cc664fa2
Update docs: JWKS credentials and AZ identity
Signed-off-by: Milos Gajdos <milosthegajdos@gmail.com>
2024-07-06 10:13:29 +01:00

3.7 KiB

description keywords title
Explains how to use the Azure storage drivers registry, service, driver, images, storage, azure Microsoft Azure storage driver

An implementation of the storagedriver.StorageDriver interface which uses Microsoft Azure Blob Storage for object storage.

Parameters

Parameter Required Description
accountname yes Name of the Azure Storage Account.
accountkey yes Primary or Secondary Key for the Storage Account.
container yes Name of the Azure root storage container in which all registry data is stored. Must comply the storage container name requirements. For example, if your url is https://myaccount.blob.core.windows.net/myblob use the container value of myblob.
realm no Domain name suffix for the Storage Service API endpoint. For example realm for "Azure in China" would be core.chinacloudapi.cn and realm for "Azure Government" would be core.usgovcloudapi.net. By default, this is core.windows.net.
copy_status_poll_max_retry no Max retry number for polling of copy operation status. Retries use a simple backoff algorithm where each retry number is multiplied by copy_status_poll_delay, and this number is used as the delay. Set to -1 to disable retries and abort if the copy does not complete immediately. Defaults to 5.
copy_status_poll_delay no Time to wait between retries for polling of copy operation status. This time is multiplied by N on each retry, where N is the retry number. Defaults to 100ms

Azure identity

In order to use managed identity to access Azure blob storage you can use Microsoft Bicep.

The following will configure credentials that will be used by the Azure storage driver to construct AZ Identity that will be used to access the blob storage:

properties: {
  azure: {
    accountname: accountname
    container: containername
    credentials: {
      type: default
    }
  }
}