Hello ABP Team,
We are currently using ABP Framework with Azure Blob Storage integration and would like to implement authentication to Azure Storage using a System-Assigned Managed Identity instead of a connection string.
We have been following Microsoft's guidance: https://learn.microsoft.com/en-us/dotnet/azure/sdk/authentication/system-assigned-managed-identity
Our goal is to eliminate storage account keys and connection strings and use Azure Managed Identity for improved security and compliance.
We have a few questions:
Does the current ABP Azure Blob Storage module support authentication through Azure Managed Identity (DefaultAzureCredential / ManagedIdentityCredential)?
If it is not currently supported, is there any recommended extension point or customization approach for replacing the default BlobServiceClient initialization with a Managed Identity-based implementation?
Are there any plans on the ABP roadmap to support Azure SDK credential-based authentication for Azure Storage?
Has the ABP team published any sample projects, documentation, or best practices demonstrating Azure Storage integration using Managed Identity?
Our current environment:
- ABP Framework Version: 10.2.0
- Azure App Service with System-Assigned Managed Identity enabled
- Azure Storage Account
- Azure Blob Storage Provider
We attempted to customize the Azure Storage provider to use DefaultAzureCredential and ManagedIdentityCredential, but the storage operations are not working as expected.
Any guidance or recommended architecture would be greatly appreciated.
Thank you.
2 Answer(s)
-
0
(1) Managed Identity support in ABP’s Azure Blob provider (v10.2.0):
In ABP 10.2, the built-in Azure Blob Storage provider is configured viaazure.ConnectionStringand the documentation describes it as using the connection string (shared key) model. There is no documented option (in ABP 10.2 docs) to pass anAzure.Core.TokenCredential(e.g.,DefaultAzureCredential/ManagedIdentityCredential) to the provider.(2) Recommended extension/customization point:
ABP explicitly documents thatAzureBlobProvideris the main class and can be overridden/replaced via dependency injection (replace theAzureBlobProviderclass, notIBlobProvider). So the supported approach is:- Create your own provider class (either replace
AzureBlobProvidervia DI or create a custom blob provider). - In your implementation, initialize
BlobServiceClientusingnew BlobServiceClient(new Uri(accountUrl), new DefaultAzureCredential())(orManagedIdentityCredential) and implement required blob operations.
Practically, the most “ABP-aligned” options are:
- Replace
AzureBlobProvidervia DI (recommended if you want to keepcontainer.UseAzure(...)configuration style and just change authentication/initialization internals). - Or create a custom provider and switch containers to
ProviderType = typeof(YourProvider)(recommended if you want a clean separation and your own strongly-typed provider configuration options).
- Create your own provider class (either replace
(3) Roadmap plans:
No verified source available for ABP’s roadmap regarding “Azure SDK credential-based authentication for Azure Storage” (Managed Identity /TokenCredential) in the built-in provider.(4) Samples / best practices published by ABP:
No verified official ABP sample/documentation demonstrating Azure Blob Storage integration using Managed Identity. The available docs and community articles primarily show connection-string based configuration.
Links (validated):
- https://abp.io/docs/10.2/framework/infrastructure/blob-storing/azure
- https://abp.io/docs/10.2/framework/infrastructure/blob-storing/custom-provider
- https://learn.microsoft.com/en-us/dotnet/azure/sdk/authentication/system-assigned-managed-identity
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
There's no built-in Managed Identity option in the Azure blob provider yet — the config only takes a connection string. But you can plug in
DefaultAzureCredentialby overridingAzureBlobProvider, sinceGetBlobContainerClientisprotected virtual. We may add native support for this in a future release.Here's a working override (I verified it builds against
Volo.Abp.BlobStoring.Azure10.2.0 +Azure.Identity):using System; using Azure.Identity; using Azure.Storage.Blobs; using Volo.Abp.BlobStoring; using Volo.Abp.BlobStoring.Azure; using Volo.Abp.DependencyInjection; namespace MyCompanyName.MyProjectName; [Dependency(ReplaceServices = true)] [ExposeServices(typeof(IBlobProvider), typeof(AzureBlobProvider))] public class MyAzureBlobProvider : AzureBlobProvider { public MyAzureBlobProvider( IAzureBlobNameCalculator azureBlobNameCalculator, IBlobNormalizeNamingService blobNormalizeNamingService) : base(azureBlobNameCalculator, blobNormalizeNamingService) { } protected override BlobContainerClient GetBlobContainerClient(BlobProviderArgs args) { var configuration = args.Configuration.GetAzureConfiguration(); // Reuse the existing ConnectionString slot to carry the storage account URL, // e.g. "https://<account-name>.blob.core.windows.net". var serviceUri = new Uri(configuration.ConnectionString); var credential = new DefaultAzureCredential(); var blobServiceClient = new BlobServiceClient(serviceUri, credential); return blobServiceClient.GetBlobContainerClient(GetContainerName(args)); } }In your container configuration just put the storage account URL where the connection string used to go:
Configure<AbpBlobStoringOptions>(options => { options.Containers.ConfigureDefault(container => { container.UseAzure(azure => { azure.ConnectionString = "https://<your-account>.blob.core.windows.net"; azure.ContainerName = "my-container"; azure.CreateContainerIfNotExists = true; }); }); });Make sure the App Service's System-Assigned Managed Identity is granted the
Storage Blob Data Contributorrole on the storage account — that's whatDefaultAzureCredentialwill use at runtime. If you want to be explicit you can swapnew DefaultAzureCredential()fornew ManagedIdentityCredential().If you still see errors after this, set
AZURE_LOG_LEVEL=verboseon the App Service to captureAzure.Identitydiagnostic output and share the exception + relevant log snippet — we can take another look from there.Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)