Blob Storage Container
A logical grouping inside an Azure Storage Account that holds blobs (unstructured files like images, logs, or backups), similar to a folder but with its own access policy and public-access setting.
Blob Storage Container
A container is the organizational layer between a Storage Account and individual blobs. Every blob must live inside exactly one container, and access permissions are set per container.
Why It Matters in Production
Swiggy stores order-invoice PDFs in a container like invoices-prod, kept fully private, while a separate app-assets-prod container serving app icons is set to public blob-level read so a CDN can fetch them directly.
az storage container create --name invoices-prod \ --account-name swiggyprodstorage --public-access offSecurityNever set a container's public access level to "Container" (full anonymous listing) for anything holding customer data.
Frequently Asked Questions
How is a Blob Storage Container different from a folder in a traditional file system?
A container is a flat namespace — blobs inside it don't have real directory structure even though tools display paths like `logs/2026/09/app.log` as if folders exist. That path is actually just part of the blob's name string; there's no separate folder object being created or permissioned. Each container also carries its own independent access policy and public-access setting, unlike a folder which typically inherits permissions from its parent, so access control is set at the container level, not per virtual 'folder'.
What's a common security mistake with Blob Storage Containers?
Setting a container's public access level to 'Blob' or 'Container' during testing to quickly share a file, then forgetting to revert it before the storage account goes to production. This exposes every blob in that container to anonymous internet read access via a guessable or leaked URL, with no authentication required. The safer default is private access plus time-limited SAS tokens or signed URLs for any file that genuinely needs to be shared externally.