Prerequisites to use DefaultAzureCredentials in Azure Function with Http Client/Request
- Azure CLI
- Azure Function Core Tools
- .Net Core 3.1 SDK
- Terraform CLI
The following steps used to create and deploy the resources to Azure:
1. Deploy resources to Azure:
az login
az account set --subscription < target subscription ID>
cd terraform
terraform apply --var basename="< resourcename>" --var resource_group_name="<resource group name>" --var location="<Azure region name>"
2. Deploy Function App To Azure:
It asks you if you have multiple Functions core tools versions installed (like v1, v2, v3). After deployment completes, a deploy.app.sh file will be created and executed within a bash shell, which fully deploys the Function App to Azure.
3. Observe the config of the Function App
Observe the connection strings under Configuration Menu of the Function App in the Portal which contains the associated storage account connection string, where this storage account contains the uploaded .zip package of Functions File Content when it's published.
4. Rolling the Keys in storage account using Managed Identity
Under the Function App in Azure portal > Identity > System Assigned (Switch the status to ON) and click on Save.
No need to restart the function app to start using the new keys from the storage account.
Execute the below command to generate a SAS URL:
curl --location --request GET 'https://fxnxxxxxx.azurewebsites.net/api/GetSASUrl?code=3TR6xxxxxx&blobUri=https://fxxxx.blob.core.windows.net/sample/my.file'
Here the blobUri is the full Http URL to your target blob.
To download the blob, hit this URL in an InPrivate Browser:
https://fxn_____.blob.core.windows.net/sample/my.file?skoid=......pxLSpVwuML%2B3UXrxBmC6XGA%3D
Below Command gets the storage account keys:
curl --location --request GET 'https://fxnxxxxxxx.azurewebsites.net/api/GetAccountKeys?code=GKUxxxxxxxx&accountName=fxnxxxx`
accountName is the Storage account name which is equivalent to the basename variable passed in above Terraform command.
- The Response comes in JSON Format contains of key-value pairs related to keyName, value and permissions.
As Part of normal security protocol, regenerate the storage account keys by going to Azure Portal > Storage account > Access Keys > regenerate.
Check the change in keys using this command:
curl --location --request POST 'https://fxnxxxxxx.azurewebsites.net/api/RegenerateKey?code=9OZxxxxx&accountName=fxnstormsisampsc&keyName=key2`
The response will be in Http Status Code 200 OK and check in Azure Portal > Storage account > Access Keys.
Here is the reference code and documentation.