Is it possible to disable storage account key access on CVO Storage Accounts?
Applies to
- Cloud Volume ONTAP (CVO)
- Microsoft Azure
- Storage Account Shared Access Signature (SAS)
Answer
- During CVO deployment, the NetApp Console creates a new storage account with a container for each Cloud Volumes ONTAP system.
- The Console creates thestorage account with the following default settings automatically:
- Access tier: Hot
- Performance: Standard
- Redundancy: Accordingly to Cloud Volume ONTAP Deployment
- Account: StorageV2 (general purpose v2)
- Require secure transfer for REST API operations: Enabled
- Storage account key access: Enabled
- Minimum TLS version: Version 1.2
- Infrastructure encryption: Disabled
- It is recommended to not change any Azure resource setting directly from Azure portal.
-
When disabling the access for the storage account any requests to the account that are authorized with Shared Key, including shared access signatures (SAS), will be denied. Therefore the action is not supported as it will cause communication disruption between the CVO system and storage account.
Partner Notes
partnerNotes_text
Additional Information
additionalInformation_text
Internal Notes
internalNotes_text
