spad.ltip.azure.restrict_blob_to_front_door ​
Grant Front Door managed identity Storage Blob Data Reader access on the storage account
Enable system-assigned managed identity on the Front Door profile and assign Storage Blob Data Reader so Front Door can read from the private Blob account. Skips gracefully when either profile_name or account_name is absent.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Linear |
| Library | App-spad |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
cloud_connection_uuid | string | Yes | — | Azure CloudConnection.id |
azure_storage_account_name | string | No | — | Storage account whose RBAC should be set; step skips when omitted |
azure_front_door_profile_name | string | No | — | Front Door profile whose managed identity will be granted access; step skips when omitted |
site_uuid | string | No | — | SpadSite.id for context propagation |
organization_uuid | string | No | — | Organization that owns the site |
workflow_run_id | string | No | — | — |
workflow_run_uuid | string | No | — | Parent workflow run ID stamped by the DAG engine (legacy alias) |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
blob_restricted_to_front_door | boolean | No | — | True when RBAC was assigned (assigned path only) |
front_door_principal_ref | string | No | — | Managed-identity principalId used for the role assignment |
rbac_skipped | boolean | No | — | True when step skipped because profile/account was missing |
rbac_skip_reason | string | No | — | Reason recorded on the skip path |
completed_at | string | No | — | ISO8601 timestamp when the step reached COMPLETED |
failed_at | string | No | — | ISO8601 timestamp when the step reached FAILED |
failure_reason | string | No | — | Reason recorded on the failure path |
workflow_run_id | string | No | — | — |
cloud_connection_uuid | string | No | — | Azure CloudConnection.id |
azure_storage_account_name | string | No | — | Storage account whose RBAC should be set; step skips when omitted |
azure_front_door_profile_name | string | No | — | Front Door profile whose managed identity will be granted access; step skips when omitted |
site_uuid | string | No | — | SpadSite.id for context propagation |
organization_uuid | string | No | — | Organization that owns the site |
workflow_run_uuid | string | No | — | Parent workflow run ID stamped by the DAG engine (legacy alias) |
error | string | No | — | Engine-stamped failure metadata |
error_type | string | No | — | Engine-stamped failure metadata |
failed_at_state | json | No | — | Engine-stamped failure metadata |
failed_layer | json | No | — | Engine-stamped failure metadata |
failed_step | json | No | — | Engine-stamped failure metadata |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
initiated | Yes | No | — | run | Step accepted |
run | No | No | — | complete | Assigning RBAC role |
completed | No | Yes | Yes | — | RBAC assigned |
failed | No | Yes | No | — | RBAC assignment failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
initiated | run | run | Start RBAC assignment |
run | complete | completed | Mark step completed |
* (any state) | fail | failed | Mark step failed |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "spad.ltip.azure.restrict_blob_to_front_door",
"initial_data": {
"cloud_connection_uuid": "value"
}
}