What it is

Blob Storage holds objects in containers inside a storage account. Files, backups, images, the European supplier pack. Same job as S3 with Microsoft labels: hot, cool, cold, archive.

Access is the plot. Public anonymous access, shared access signatures, and identity-based access are choices. Defaults are not a strategy.

If your AWS brain says bucket, think container. If it says Block Public Access, think "did we actually disable anonymous access on this account?"

Why it matters in the meeting

Multi-cloud often starts because a partner lives on Azure. Raja suggests Blob. Selena opens the portal. The interface is different. The "leave it open" failure mode is identical.

Bart will ask about access policies in #infrastructure-general. Two reads. One is Selena. Act on the message anyway.

Real world

Lifecycle tiers save money when access patterns are real. Hot forever is simple and wasteful. Archive for data you need hourly is a self-own.

A SAS token in a wiki page is an access key with a sunny name. Treat it like one.

In plain terms

Blob is Azure's big drawer. Same as S3. Lock the drawer. Put cold things on the cheap shelf. Do not celebrate multi-cloud until the access story is boring.

What to ask

  • Is anonymous public access disabled on production storage accounts?
  • Which containers hold customer or pricing data, and who can read them?
  • Do lifecycle policies match how often we actually touch the data?
  • Where do SAS tokens live, and when do they expire?

You just knew a little more Jack than you did five minutes ago.

All concepts