Azure Storage
Azure Storage holds blobs, queues, files and tables in storage accounts. The Azure platform uses storage accounts for its state, its audit record, shared build inputs, the Unity Catalog root, the web application's front end and the data lake, and gives every one of them the same baseline: Microsoft Entra authorization only, TLS 1.2, zone redundancy and deletion protection.
What it does
A storage account is the unit of naming, networking, redundancy and encryption. Inside it, containers hold blobs. Redundancy options include ZRS (three copies across the zones of one region) and GZRS (ZRS plus an asynchronous copy in the paired region). Data can be authorized with account keys and SAS tokens or with Microsoft Entra ID and Azure RBAC roles such as Storage Blob Data Reader and Contributor. Protection features include blob versioning, soft delete for blobs and containers, time-based immutability (WORM: write once, read many) and lifecycle rules that move blobs to the cool and archive tiers. Data is always encrypted; infrastructure encryption adds a second layer, and a customer-managed key (CMK) from Key Vault replaces the platform-managed key.
How BuiltForProd uses it
| Account | Product, subscription | Holds |
|---|---|---|
stacmeeus2roottfstate | Baseline, acme-core-root | Container tfstate: the OpenTofu state of every repository, versioned, with change feed and 90-day soft delete |
stacmeeus2auditlogs | Baseline, acme-core-audit | The audit record: Activity Log, Entra ID logs, flow logs, exported tables; 365-day WORM, CMK |
stacmeeus2artshared | Baseline, acme-core-artifacts | Container shared: build inputs every repository may read, written by Platform Leads |
stacmeeus2ucmetastore | Baseline, acme-core-artifacts | Container metastore: the Unity Catalog metastore root of the region (ADLS Gen2) |
stacmeeus2<stage>frontend | Web App Blueprint, each stage | The single-page application's static website, with versioning and 7-day soft delete |
stacmeeus2<stage>datalake | Data and ETL Blueprint, each stage | The data lake; see Azure Data Lake Storage |
Names follow st<namespace><region slug><purpose> and stop at 24 characters, which is why the shared account is artshared.
Controls on every account.
- Entra-only access: shared keys are disabled and OAuth is the default, so there are no account keys or SAS tokens to leak; access is a role assignment, such as Storage Blob Data Contributor for the code pipeline on the front-end account.
- No anonymous access to blobs, HTTPS only and TLS 1.2 at minimum.
- Infrastructure encryption on every Baseline account and on the data lake.
- ZRS, with GZRS as the per-unit option for a copy in the paired region.
- Soft delete for blobs and containers, and versioning wherever the account has no hierarchical namespace.
- Deletion protection:
prevent_destroyin code and aCanNotDeletelock on the resource group of the state, audit and metastore accounts, and of the data lake in prod. - Network: the state storage has a private endpoint in the runner network (Private Link); the Premium web stages reach the front end only through Private Link; the other Baseline accounts keep public endpoints with Entra authorization, each behind
public_network_access_enabled.
The audit account. One per region, in acme-core-audit. Account-level WORM keeps every blob version for 365 days (the policy starts unlocked; lock_immutability_policy locks it permanently), lifecycle rules move blobs to cool after 90 days and archive after 365, and the customer-managed key audit-storage from Key Vault encrypts it through a user-assigned identity. The tag Purpose = audit puts it under the audit-protection policy initiative, which denies deleting it.
Terms you will see
| Term | Meaning |
|---|---|
| ZRS, GZRS | Zone-redundant storage, and the same with a copy in the paired region. |
| Shared key | The account key and the SAS tokens signed with it; disabled here. |
| WORM | Time-based immutability: no change or delete during the retention period. |
| Soft delete | Deleted blobs and containers stay recoverable for a set number of days. |
| Infrastructure encryption | A second layer of encryption at the storage infrastructure level. |
| Lifecycle rule | A rule that moves blobs to cooler tiers, or deletes them, by age. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Azure Data and ETL Blueprint overview.
- Network Watcher for the flow logs the audit account keeps.
- Recoverable for how state and data come back after a mistake.