Description
Container soft delete retains a deleted container and its contents for recovery during a defined period. A single container deletion can affect many blobs, making separate recovery protection important.
This feature restores whole containers. Recovering individual blobs deleted from a container that still exists requires blob soft delete or versioning. Deletion of the storage account itself also needs separate protection.
Potential impact
- Missing the recovery window for a deleted container can mean losing many blobs together.
- Depending on backup restoration of large data sets can increase costs and delay service recovery.
Remediation
- Set
daysinblob_properties.container_delete_retention_policybased on the time needed to discover and respond to deletion. - Review retention costs and test actual container recovery. Creating another container with the original name can prevent restoration.
- Also configure blob soft delete and any required versioning or backups, and restrict deletion permissions.
Examples
These examples compare container retention of 5 and 49 days. Five days provides a recovery window, but Microsoft recommends at least 7 days and longer where operations require it. Keep other account attributes unchanged when modifying an existing account and inspect the Terraform plan.
Before
resource "azurerm_storage_account" "storage_account" {
name = "appcontainerstore"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
blob_properties {
container_delete_retention_policy {
days = 5
}
}
}
The container can be recovered for 5 days after deletion. A shorter period than your detection and response needs can eliminate the recovery opportunity.
After
resource "azurerm_storage_account" "storage_account" {
name = "protectedstore01"
resource_group_name = "testRG"
location = "northeurope"
account_tier = "Premium"
account_replication_type = "LRS"
blob_properties {
container_delete_retention_policy {
days = 49
}
}
}
The container recovery window is extended to 49 days. Adjust it according to data importance and retention costs.