How should ADLS Blob Storage ACLs be inherited?

Viewed 226

We have an Azure Data Lake Storage Account Gen 2 with hierarchical namespacing activated and a container c and folders f inside as follows:
/c/f1/f2/f3

We set the access permissions A and the default permissions D for read r, write w and execute x. We want to provide access to a service principal my_sp to write into a specific folder f3 and its subfolders, but read only on the parent folders f1 and f2.

Directory Principal A r A w A x D r D w D x
c Owner:$superuser
c mask x x x x x x
c my_sp x x x x x
f1 Owner:$superuser not configured not configured not configured
f1 mask x x not configured not configured not configured
f1 my_sp x x not configured not configured not configured
f2 Owner:$superuser not configured not configured not configured
f2 mask x x x not configured not configured not configured
f2 my_sp x x not configured not configured not configured
f3 Owner:$superuser Owner: x Owner: x Owner: x
f3 mask x x x x x x
f3 my_sp x x x x x x
f4 Owner:my_sp Owner: x Owner: x Owner: x
f4 mask x x x x x x
f4 my_sp x x x x x x

When we try to run the function upload_blob from azure.storage.blob.BlobClient link that is authenticated as my_sp to upload to /c/f1/f2/f3/f4/f5/f6/file.txt it will fail with the error message This request is not authorized to perform this operation using this permission.. Nevertheless it will create the subfolder f4 with the rights as mentioned in the table above. That also explains why it can not write into f4 after creation, because it is the owner without rights.

The question is how do we need to set the ACLs so that my_sp can create multiple folders inside f3 where it is the owner with the proper rights. Is this a problem with the python client library, the API or our configuration of the ACLs?

0 Answers
Related