Skip to main content

Azure Storage

Azure Storage holds blobs, queues, files and tables in storage accounts. The Azure platform uses storage accounts for its state, its audit record, shared build inputs, the Unity Catalog root, the web application's front end and the data lake, and gives every one of them the same baseline: Microsoft Entra authorization only, TLS 1.2, zone redundancy and deletion protection.

What it does​

A storage account is the unit of naming, networking, redundancy and encryption. Inside it, containers hold blobs. Redundancy options include ZRS (three copies across the zones of one region) and GZRS (ZRS plus an asynchronous copy in the paired region). Data can be authorized with account keys and SAS tokens or with Microsoft Entra ID and Azure RBAC roles such as Storage Blob Data Reader and Contributor. Protection features include blob versioning, soft delete for blobs and containers, time-based immutability (WORM: write once, read many) and lifecycle rules that move blobs to the cool and archive tiers. Data is always encrypted; infrastructure encryption adds a second layer, and a customer-managed key (CMK) from Key Vault replaces the platform-managed key.

How BuiltForProd uses it​

AccountProduct, subscriptionHolds
stacmeeus2roottfstateBaseline, acme-core-rootContainer tfstate: the OpenTofu state of every repository, versioned, with change feed and 90-day soft delete
stacmeeus2auditlogsBaseline, acme-core-auditThe audit record: Activity Log, Entra ID logs, flow logs, exported tables; 365-day WORM, CMK
stacmeeus2artsharedBaseline, acme-core-artifactsContainer shared: build inputs every repository may read, written by Platform Leads
stacmeeus2ucmetastoreBaseline, acme-core-artifactsContainer metastore: the Unity Catalog metastore root of the region (ADLS Gen2)
stacmeeus2<stage>frontendWeb App Blueprint, each stageThe single-page application's static website, with versioning and 7-day soft delete
stacmeeus2<stage>datalakeData and ETL Blueprint, each stageThe data lake; see Azure Data Lake Storage

Names follow st<namespace><region slug><purpose> and stop at 24 characters, which is why the shared account is artshared.

Controls on every account.

  • Entra-only access: shared keys are disabled and OAuth is the default, so there are no account keys or SAS tokens to leak; access is a role assignment, such as Storage Blob Data Contributor for the code pipeline on the front-end account.
  • No anonymous access to blobs, HTTPS only and TLS 1.2 at minimum.
  • Infrastructure encryption on every Baseline account and on the data lake.
  • ZRS, with GZRS as the per-unit option for a copy in the paired region.
  • Soft delete for blobs and containers, and versioning wherever the account has no hierarchical namespace.
  • Deletion protection: prevent_destroy in code and a CanNotDelete lock on the resource group of the state, audit and metastore accounts, and of the data lake in prod.
  • Network: the state storage has a private endpoint in the runner network (Private Link); the Premium web stages reach the front end only through Private Link; the other Baseline accounts keep public endpoints with Entra authorization, each behind public_network_access_enabled.

The audit account. One per region, in acme-core-audit. Account-level WORM keeps every blob version for 365 days (the policy starts unlocked; lock_immutability_policy locks it permanently), lifecycle rules move blobs to cool after 90 days and archive after 365, and the customer-managed key audit-storage from Key Vault encrypts it through a user-assigned identity. The tag Purpose = audit puts it under the audit-protection policy initiative, which denies deleting it.

Terms you will see​

TermMeaning
ZRS, GZRSZone-redundant storage, and the same with a copy in the paired region.
Shared keyThe account key and the SAS tokens signed with it; disabled here.
WORMTime-based immutability: no change or delete during the retention period.
Soft deleteDeleted blobs and containers stay recoverable for a set number of days.
Infrastructure encryptionA second layer of encryption at the storage infrastructure level.
Lifecycle ruleA rule that moves blobs to cooler tiers, or deletes them, by age.

Where to read more​