Azure Storage Flashcards
Azure Storage Basic Options
Blobs
Queues
Tables (Structured Data)
Azure Files (SMB)
Blob Storage - Types
BLOCK Blob
Optimized for streaming content.
APPEND Blob
Optimized for append operations (log files)
PAGE Blob
Optimized for random read/write operations. Used for VM disks.
Azure Files
Built for centralized data and SMB Connectivity
Provides a True Folder Hierarchy
Connectivity to file share via SMB 2.1 (only region), SMB 3.0+ and REST/HTTP.
Disable SMB2.1 for secure transport
Account keys and SAS can be used via REST.
Account keys/Azure AD domain Services can be used via SMB.
Blob Storage and VHD files
Blob Storage is NOT for storing Virtual machine VHD files
Blob storage is for block blobs and append blobs and not page blobs)
Storage Account Types
General-Purpose v2 accounts
- Basic storage account type for blobs, files, queues, and tables
General-Purpose v1 accounts
- Legacy account type for blobs, files, queues, and tables.
- Use general-purpose v2 accounts instead when possible.
Block Blob storage accounts
- Blob-only storage accounts with premium performance
characteristics.
- Recommended for scenarios with high transactions rates, using
smaller objects or requiring consistently low storage latency.
FileStorage storage accounts
- Files-only storage accounts with premium performance
characteristics. Recommended for enterprise or high-performance
scale applications.
Blob Storage accounts
- Blob-only storage accounts.
- Use general-purpose v2 accounts instead when possible.
Azure storage - 3 categories
Structured Data
- Tables, Cosmos DB, and Azure SQL DB are examples of structured data.
Unstructured Data
- Blobs and Data Lake Store.
Storage for Virtual Machines
- Virtual machine storage like disks and files.
Storage Account Tiers
Standard Uses : (HDD) and provides the lowest cost per GB.
Premium Uses : Solid-state drives (SSD) and offers consistent low-latency performance.
Replication Types
LRS
ZRS
GRS/RA-GRS ( Read-access geo-redundant storage)
GZRS/RA-GZRS
Blob storage - 3 types of resources
Storage Account
Containers in the storage account
Blobs in a container
Blob - Access Tiers
Hot : For frequent access of objects in the storage account.
Cool : For storing data that is infrequently accessed and stored for at least 30 days.
Archive : Data that will remain in the Archive tier for at least 180 days.
Blob Object Replication
Storage Security
Encryption : All data written to Storage is automatically encrypted using Storage Service Encryption (SSE)
Authentication : AAD/AzRBAC supported for Resource management & data operations
Data in transit : Client-Side Encryption, HTTPS, or SMB 3.0.
Disk encryption : Azure Disk Encryption
Shared Access Signatures :
Shared Access Signatures
Delegated access to the data objects in Azure Storage can be granted using SAS
SAS gives you granular control over the type of access
- Account-level SAS can delegate access to multiple storage services.
- Interval over which the SAS is valid, including the start time and the expiry time.
- Permissions