
Important: This documentation is about an older version. It's relevant only to the release noted, many of the features and functions have been updated or replaced. Please view the current version.

Documentationbreadcrumb arrow Tempo Documentationbreadcrumb arrow Configurationbreadcrumb arrow Azure Permissions and Management
Open source

Azure Blob Storage Permissions and Management

In order for Tempo to authenticate to Azure blob storage, the following is required to access the container.

  • Storage account
  • Storage account access key
  • Storage account management policy

The AZURE_STORAGE_ACCOUNT and AZURE_STORAGE_KEY environment variables can be used instead of setting the credentials in the Tempo configuration file.

The following storage account management policy shows an example of cleaning up files from the container after they have been deleted for a period of time.

  "id": "/subscriptions/00000000-0000-0000000000000000000000/resourceGroups/resourceGroupName/providers/Microsoft.Storage/storageAccounts/accountName/managementPolicies/default",
  "lastModifiedTime": "2021-11-30T19:19:54.855455+00:00",
  "name": "DefaultManagementPolicy",
  "policy": {
    "rules": [
        "definition": {
          "actions": {
            "baseBlob": {
              "delete": {
                "daysAfterLastAccessTimeGreaterThan": null,
                "daysAfterModificationGreaterThan": 60.0
              "enableAutoTierToHotFromCool": null,
              "tierToArchive": null,
              "tierToCool": null
            "snapshot": null,
            "version": null
          "filters": {
            "blobIndexMatch": null,
            "blobTypes": [
            "prefixMatch": [
        "enabled": true,
        "name": "TempoBlobRetention",
        "type": "Lifecycle"
        "definition": {
          "actions": {
            "baseBlob": null,
            "snapshot": null,
            "version": {
              "delete": {
                "daysAfterCreationGreaterThan": 7.0
              "tierToArchive": null,
              "tierToCool": null
          "filters": {
            "blobIndexMatch": null,
            "blobTypes": [
            "prefixMatch": []
        "enabled": true,
        "name": "VersionRetention",
        "type": "Lifecycle"
  "resourceGroup": "resource-group-name",
  "type": "Microsoft.Storage/storageAccounts/managementPolicies"