Using the temp directory for Azure Functions

Viewed 2816

I have a set of Azure functions running on the same host, which scales up to many instances at times. I'd like to store a very small amount of ephemeral data (a few kb's) and opportunistically share those data between function executions. I know that the temp directory is only available to the functions running on that same instance. I also know that I could use the home directory, durable functions, or other Azure (such as blob) storage to share data between all functions persistently.

I have two main questions

  1. What are the security implications of using the temp directory? Who can access its contents outside of the running function?
  2. Is this still a reasonable solution? I can't find much in the way of Microsoft documentation outside of what looks like some outdated kudu documentation here.

Thanks!

3 Answers

Answer to Question 1 Yes, it is secure. The Function host process runs inside a sandbox. All access data stored to D:\local is self-contained and isolated to the processes within the sandbox. Kindly see https://github.com/projectkudu/kudu/wiki/Azure-Web-App-sandbox

Answer to Question 2 The data in D:\local\Temp exists as long as the Function host process is alive. The Functions host process can be recycled at any time due to unexpected events such as unhandled exceptions, timeouts, hitting resource usage limits for your plan. As long as your workflow accounts for the fact that the data stored in D:\local\Temp is ephemeral, then the answer is a 'yes'.

I believe this will answer your question :

enter image description here

Please refer to this for more details.

Also, when Folder/Files when created via code inside the “Temp” folder; you cannot view them when you visit KUDU site. But you can use those files/ folders.

How to view the files/ folders if created via KUDU? We will need to add - WEBSITE_DISABLE_SCM_SEPARATION = true in Configuration(app settings).

Note:- Another important note is that the Main site and the scm site do not share temp files. So if you write some files there from your site, you will not see them from Kudu Console (and vice versa). You can make them use the same temp space if you disable separation (via WEBSITE_DISABLE_SCM_SEPARATION). But note that this is a legacy flag, and its use is not recommended/supported. (ref : shared document link)

Security implications depend on the level of isolation you are seeking.

  1. In shared app-service plan or consumption plan you need to trust the sandbox isolation. This is not an isolated microvm like AWS lambda.
  2. If you have your own app-service plan then you need to trust the VM hypervisor isolation of your app-service plan.
  3. If you are really paranoid or running healtcare application, then you likely need to run your function in a ASE plan.

Reasonable solution is one where the cost is not exceeding the worth of data you are protecting :)

Related