Azure Blob Storage
Azure Blob is a first-class destination: streaming uploads, container creation, server-side copies for version history, and — uniquely — change notifications Caryvane can set up for itself.
What you need #
- Either the storage account's connection string, or its account name and an account key.
- A default container name (Caryvane creates it if it does not exist).
- For realtime only: someone who can run a script in Azure Cloud Shell with rights on the subscription.
Add it as a storage target #
- Storage → Add → Azure Blob.
- Paste the connection string (or name + key) and the container.
- Test.
- Optional — Set up Event Grid. On the target, Set up Event Grid produces a script for Azure Cloud Shell that creates a service principal and hands its credentials back to Caryvane. From then on Caryvane registers and maintains an Event Grid subscription (
BlobCreated,BlobDeleted) itself, so a cloud copy from this account can run continuously.
Test on the target's row proves the credentials; a target that fails shows the provider's own message until it is fixed. From then on it can be a job's destination, a cloud-to-cloud source, a cloud drive, or an archive.
What it supports #
| Capability | Azure Blob Storage |
|---|---|
| Streams uploads | Yes |
| Version history | Sidecar, written with server-side copies (no download) |
| Realtime cloud-copy source | Yes — Event Grid, registered by Caryvane |
| Cloud-drive mount | Yes |
| Reachable from the Cloud Agent | Yes |
| Browse in the console | Yes |
Things to know #
Least privilege for Event Grid. The generated script asks for Owner on the subscription because assigning roles needs it. If that is more than your policy allows, create the service principal yourself with EventGrid EventSubscription Contributor scoped to the storage account and enter its tenant, client ID and secret on the target instead; Caryvane only ever uses them to manage its own aurawolf-* subscriptions.
Hand-made subscription. Point it at the webhook URL and add a static delivery attribute aeg-sas-key with the target's webhook secret (Configure webhook shows it).
Without ARM credentials the target works normally on a schedule; only continuous mode needs them.