Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Container in context, with comparison tables and the common traps.
Terms in this definition
- Blob storage
Azure's object store for unstructured content like images and video; a single block blob can reach roughly 190.7 TiB.
- Storage account
The top-level resource in Azure Storage, giving a unique namespace for table, queue, file and blob data. Location, performance and kind are set when it is created and cannot change.
- Cosmos DB
NoSQL database distributed globally, offering writes in multiple regions, automatic indexing and latency below 10 ms.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.
- Partitioning
Splits a table into directories, one per value of the column or columns named in
PARTITIONED BY. Learn favours liquid clustering in most cases and keeps this technique for very large tables.
Related terms
- --attach-acr
Option on
az aks createoraz aks updatethat links a container registry to an AKS cluster by assigning AcrPull to the kubelet identity, so nodes can pull its images. - AADDC Computers
Container built into an Entra Domain Services managed domain, holding joined VMs' computer accounts, with a GPO of its own.
- AADDC Users
Container built into an Entra Domain Services managed domain, holding groups and users synchronised there, with a GPO of its own.
- acr purge
A container command, currently in preview, that runs as an ACR task either on demand or on a schedule. It removes tags matching a repository and tag regex once they pass a given age, can also clear untagged manifests, and anything it deletes is gone for good.
- Admin user (ACR)
Built-in admin account on a container registry, turned off by default, with one username and two passwords that can be regenerated. It grants full push and pull rights under a single shared identity.
- AdminSDHolder
An Active Directory container whose permissions the SDProp process on the PDC emulator stamps onto protected group members every 60 minutes, undoing any changes made to them.
- allowBlobPublicAccess
Account-level storage property; setting it to false blocks anonymous reads on all containers regardless of what each container's access level says.
- Amazon ECR
Amazon's registry service for container images, which Defender for Containers can scan once the AWS connector is in place.