How to use ManagedIdentity in Azure Function storage account connection string

Viewed 841

I have an Azure Function that is using durable functions:

local.settings.json

"Values": {
  "AzureWebJobsStorage": "UseDevelopmentStorage=true",
  "DurableFunctionsStorageConnectionString": "UseDevelopmentStorage=true"
}

host.json

"extensions": {
        "durableTask": {
            "storageProvider": {
                "connectionStringName": "DurableFunctionsStorageConnectionString"
            }
        }
    }

Instead of using connection string with an access key in Azure environment, I would like to use a managed identity and give it access. Is there a version of the connection string that is supported that can use managed identity?

This is an example of a similar access for SignalR connection string:

Endpoint={signalr_service_endpoint};AuthType=aad;Version=1.0;

It's even better if there is a possibility for DefaultAzureCredential from Azure.Identity, but it will suffice for me to "turn on" Managed Identity.

P.S. I am not looking on how to connect to a storage account in my code, but how to make Azure Function infrastructure to do it for the accounts that it needs.

2 Answers

Thanks to useful comments by @Thomas, I figured out that:

  1. It is possible to do for ordinary storage account by providing this variable:

    AzureWebJobsStorage__accountName: the value is just the name of storage account. Documentation here.

  2. It is not possible for Durable functions yet. See this issue.

I come from the Azure SignalR Service team.

It is not recommended to use ConnectionString while configuring AAD Auth.

Even us is updating our docs to recommend our customers to configure AAD Auth in codes.

I'm not sure what feature of Azure storage that you're using. For Blobs, you could configure a BlobClient through the following codes:

var client = new BlobClient(new Uri("<your endpoint>"), new DefaultAzureCredential(), new BlobClientOptions());

BlobClient Class

To learn more about other derived TokenCredential class, see TokenCredential class

Related