You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从AKS访问Azure Blob Storage的技术方案咨询

Hey Ramesh, sorry to hear your .NET Core API is hitting a snag accessing Azure Blob Storage from AKS—you’re already halfway there since SQL is working, so let’s focus on the Blob Storage piece. Below are the most secure and reliable methods to get this working, along with troubleshooting tips:

This is the best practice because it eliminates hardcoding credentials entirely. Here’s how to set it up:

Step 1: Create a User-Assigned Managed Identity (or use System-Assigned)

  • Head to the Azure Portal → Managed Identities → Create a new user-assigned identity.
  • Or use Azure CLI for faster setup:
    az identity create --name <mi-name> --resource-group <rg-name>
    

Step 2: Grant the Identity Blob Storage Permissions

  • Navigate to your Storage Account → IAM → Add role assignment.
  • Assign the Storage Blob Data Reader role (or Contributor if you need write access) directly to your new managed identity.

Step 3: Bind the Identity to Your AKS Pod

  • Update your API’s deployment YAML to link the identity to your pods:
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: your-api-deployment
    spec:
      template:
        metadata:
          labels:
            app: your-api
        spec:
          containers:
          - name: your-api-container
            image: your-api-image:latest
            env:
            # Optional: Pass the MI's client ID for easier debugging
            - name: AZURE_CLIENT_ID
              value: <your-mi-client-id>
          identity:
            type: UserAssigned
            userAssignedIdentities:
              <your-mi-resource-id>: {}
    

Step 4: Update Your .NET Core Code

Use DefaultAzureCredential to authenticate automatically—no credentials needed in your code:

using Azure.Storage.Blobs;
using Azure.Identity;

// Initialize BlobServiceClient with managed identity
var blobServiceClient = new BlobServiceClient(
    new Uri("https://<your-storage-account>.blob.core.windows.net"),
    new DefaultAzureCredential());

// Example: Fetch a PDF from your container
var containerClient = blobServiceClient.GetBlobContainerClient("<your-container-name>");
var blobClient = containerClient.GetBlobClient("<target-pdf-name>.pdf");
var blobContent = await blobClient.DownloadStreamingAsync();

2. Use Storage Account Access Keys (Quick Testing Only)

If you need a fast way to validate connectivity, you can store your storage account’s access key in an AKS Secret and reference it in your app:

Step 1: Create an AKS Secret

kubectl create secret generic storage-secrets --from-literal=storage-key="<your-storage-access-key>"

Step 2: Inject the Secret into Your Deployment

Add this snippet under the container section of your deployment YAML:

env:
- name: STORAGE_ACCOUNT_KEY
  valueFrom:
    secretKeyRef:
      name: storage-secrets
      key: storage-key

Step 3: Update Your Code

Use the access key to authenticate the Blob client:

using Azure.Storage.Blobs;
using Azure.Storage;

var storageAccountName = "<your-storage-account-name>";
var storageKey = Environment.GetEnvironmentVariable("STORAGE_ACCOUNT_KEY");
var credential = new StorageSharedKeyCredential(storageAccountName, storageKey);

var blobServiceClient = new BlobServiceClient(
    new Uri($"https://{storageAccountName}.blob.core.windows.net"),
    credential);

⚠️ Note: Access keys are long-lived and sensitive, so this method isn’t recommended for production environments.

3. Use SAS Tokens (Temporary Access Scenarios)

For short-lived, scoped access (e.g., granting access to specific blobs), generate a SAS token for your container/blob, store it in an AKS Secret, and reference it in your code:

var sasToken = Environment.GetEnvironmentVariable("BLOB_SAS_TOKEN");
var blobUri = new Uri($"https://<your-storage-account>.blob.core.windows.net/<container>/<target-pdf-name>.pdf?{sasToken}");
var blobClient = new BlobClient(blobUri);

Troubleshooting Common Issues

  • Network Restrictions: If your Storage Account has firewall rules enabled, allow traffic from your AKS cluster’s VNet (use Service Endpoints or Private Endpoints for Azure Storage) or add the AKS node pool’s public IPs to the allowed list.
  • Permission Validation: Double-check that your managed identity/access key has the correct IAM role (e.g., Storage Blob Data Reader, not the generic Reader role which doesn’t grant blob access).
  • Debugging Credentials: Add logging to your API to confirm which authentication method DefaultAzureCredential is using (it will log if it’s falling back to a different method than expected).

Hope these steps get your API pulling PDFs from Blob Storage smoothly!

内容的提问来源于stack exchange,提问作者Ramesh Gowda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 16:47:32