table of contents
| BLOB(1) | User Commands | BLOB(1) |
NAME¶
blob - APT method helper for Azure Blob Storage repositories
SYNOPSIS¶
blob
DESCRIPTION¶
blob is the APT method helper shipped by apt-transport-blob. When installed, APT can retrieve repository metadata and packages from Azure Blob Storage URLs that use the blob:// scheme.
The helper implements the APT method protocol and is normally invoked by APT, not run directly by users.
URL FORMAT¶
APT source entries may use URLs of the form:
blob://ACCOUNT.blob.core.windows.net/CONTAINER/PATH
The helper translates these to HTTPS requests against the same host and path, using Azure Storage bearer-token authentication.
AUTHENTICATION¶
The selected Azure credential must be authorized to read the blob container, for example with the Storage Blob Data Reader role.
Credentials are tried in this order:
- AZURE_STORAGE_BEARER_TOKEN
- A bearer token for Azure Storage. It can be obtained with:
-
az account get-access-token --output tsv --query accessToken --resource https://storage.azure.com
- Workload identity
- Set AZURE_TENANT_ID, AZURE_CLIENT_ID, and AZURE_FEDERATED_TOKEN_FILE.
- Client secret
- Set AZURE_TENANT_ID, AZURE_CLIENT_ID, and AZURE_CLIENT_SECRET.
- Azure CLI
- Uses an existing Azure CLI login session (for example after az login).
- Managed identity
- On Azure compute, the helper can obtain a token from the Instance Metadata Service. This is tried last because it requires a network request that can time out outside Azure.
ENVIRONMENT¶
- AZURE_AUTHORITY_HOST
- Overrides the Azure Active Directory authority host used for workload identity and client-secret authentication.
- AZURE_STORAGE_BEARER_TOKEN
- Bearer token used directly for Azure Storage requests.
- AZURE_TENANT_ID
- Tenant ID used for workload identity and client-secret authentication.
- AZURE_CLIENT_ID
- Client ID used for workload identity and client-secret authentication.
- AZURE_FEDERATED_TOKEN_FILE
- Path to a federated identity token file used for workload identity.
- AZURE_CLIENT_SECRET
- Client secret used for client-secret authentication.
FILES¶
- /usr/lib/apt/methods/blob
- APT method helper installed by this package.
- /var/log/apt-transport-blob.log
- Debug log written by the helper.
SEE ALSO¶
apt(8), sources.list(5), az(1)
| June 2026 | apt-transport-blob |