Skip to content
Proud to collaborate with Microsoft for Startups

spad.ltip.azure.restrict_blob_to_front_door ​

Grant Front Door managed identity Storage Blob Data Reader access on the storage account

Enable system-assigned managed identity on the Front Door profile and assign Storage Blob Data Reader so Front Door can read from the private Blob account. Skips gracefully when either profile_name or account_name is absent.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-spad
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
cloud_connection_uuidstringYes—Azure CloudConnection.id
azure_storage_account_namestringNo—Storage account whose RBAC should be set; step skips when omitted
azure_front_door_profile_namestringNo—Front Door profile whose managed identity will be granted access; step skips when omitted
site_uuidstringNo—SpadSite.id for context propagation
organization_uuidstringNo—Organization that owns the site
workflow_run_idstringNo——
workflow_run_uuidstringNo—Parent workflow run ID stamped by the DAG engine (legacy alias)

Output Schema ​

FieldTypeRequiredDefaultDescription
blob_restricted_to_front_doorbooleanNo—True when RBAC was assigned (assigned path only)
front_door_principal_refstringNo—Managed-identity principalId used for the role assignment
rbac_skippedbooleanNo—True when step skipped because profile/account was missing
rbac_skip_reasonstringNo—Reason recorded on the skip path
completed_atstringNo—ISO8601 timestamp when the step reached COMPLETED
failed_atstringNo—ISO8601 timestamp when the step reached FAILED
failure_reasonstringNo—Reason recorded on the failure path
workflow_run_idstringNo——
cloud_connection_uuidstringNo—Azure CloudConnection.id
azure_storage_account_namestringNo—Storage account whose RBAC should be set; step skips when omitted
azure_front_door_profile_namestringNo—Front Door profile whose managed identity will be granted access; step skips when omitted
site_uuidstringNo—SpadSite.id for context propagation
organization_uuidstringNo—Organization that owns the site
workflow_run_uuidstringNo—Parent workflow run ID stamped by the DAG engine (legacy alias)
errorstringNo—Engine-stamped failure metadata
error_typestringNo—Engine-stamped failure metadata
failed_at_statejsonNo—Engine-stamped failure metadata
failed_layerjsonNo—Engine-stamped failure metadata
failed_stepjsonNo—Engine-stamped failure metadata

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—runStep accepted
runNoNo—completeAssigning RBAC role
completedNoYesYes—RBAC assigned
failedNoYesNo—RBAC assignment failed

State Diagram ​

Transitions ​

FromActionToDescription
initiatedrunrunStart RBAC assignment
runcompletecompletedMark step completed
* (any state)failfailedMark step failed

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "spad.ltip.azure.restrict_blob_to_front_door",
  "initial_data": {
    "cloud_connection_uuid": "value"
  }
}