azure-storage-user-delegation-key

A user-delegation key can sign Blob SAS tokens for its validity window.

azurecritical service: azure:storage emits ExposesCredential

Where it sits

locationBlobService getUserDelegationKey response.{SignedOid,SignedTid,SignedStart,SignedExpiry,SignedService,SignedVersion,Value}
location kindoutput_value
data kindscredential signing_secret
emits edgeExposesCredential
serviceStorage Accounts (Blob/File/Queue/Table) (azure:storage)

Collection recipe

access modedata_plane
operationBlob Service - Get User Delegation Key
response path$value
encodingxml
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action

References

move · open · esc close