I am trying to setup a Blob Triggered Function, but I do not wish to share the Connection String to my storage account with said Function.
Theoretically, since Blob Storage is integrated with Azure Active Directory, it should be possible to provide the right RBAC permissions on my Blob Containers so that the Function's identity (Managed Service Identity) has whatever permissions are necessary to create the trigger and read from the blobs.
However, I haven't found a way to achieve this.
All the options I have found involve the use of a full Connection String, which would give full control of the Storage Account to the Function.
Is there any way to achieve what I want?