Deploy Azure Storage Account with Meshery

Learn how to deploy and manage Azure Storage account through Kubernetes with Meshery, utilizing ASO operator to enhance cloud resource management

Meshery enables you to manage Azure Storage Accounts declaratively through Kubernetes by leveraging the Azure Service Operator (ASO). In this tutorial, you’ll install the ASO operator (without CRD pattern configurations, which Meshery will manage), create a Service Principal and a Kubernetes secret with your Azure credentials, and use Meshery’s UI to visually design and deploy a Storage Account resource to your Azure subscription.

Before you begin, ensure you have the following:

  1. Meshery Installed A self-hosted Meshery instance running on your Kubernetes cluster (in-cluster or out-of-cluster).
  2. Kubernetes Cluster A running Kubernetes cluster (v1.16+) with kubectl configured.
  3. Azure Subscription An active Azure subscription where Storage Accounts will be provisioned.
  4. Azure CLI Installed and authenticated (az login) in your local shell.
  5. cert-manager Installed in your Kubernetes cluster (required by Azure Service Operator).
  6. Meshery Catalog Extension: The Meshery Catalog extension enabled within your Meshery environment to access pre-configured cloud-native design patterns.
  1. Create Azure Service Principal

  2. Connect Meshery to Your Cluster

  3. Install Azure Service Operator (Operator Only)

  4. Design and Deploy an Azure Storage Account

  5. Verify Deployment

  6. Conclusion

If you do not already have a Service Principal (SP) for Meshery, create one using the Azure CLI:

az ad sp create-for-rbac -n azure-service-operator --role contributor --scopes /subscriptions/<AZURE_SUBSCRIPTION_ID>

This command outputs the following credentials:

  • appId: Application ID (Client ID)
  • displayName: Service Principal Name
  • name: Azure Service Principal URL
  • password: Client Secret
  • tenant: Tenant ID

To export them, manually enter:

export AZURE_CLIENT_ID=<appId> export AZURE_CLIENT_SECRET=<password> export AZURE_TENANT_ID=<tenant> export AZURE_SUBSCRIPTION_ID=<subscriptionId>

If you haven’t already connected your cluster to Meshery, run:

mesheryctl system start

Then open the Meshery UI (default: http://localhost:9081) and ensure your cluster appears under Lifecycle β†’ Connections.

Apply the official ASO operator manifest (Meshery will manage CRDs):

kubectl apply -f https://github.com/Azure/azure-service-operator/releases/download/v2.13.0/azureserviceoperator_v2.13.0.yaml

Azure Service Operator requires a Kubernetes secret with your Azure identity:

kubectl create secret generic azure-credentials --namespace azureserviceoperator-system --from-literal=AZURE_CLIENT_ID=$AZURE_CLIENT_ID --from-literal=AZURE_CLIENT_SECRET=$AZURE_CLIENT_SECRET --from-literal=AZURE_TENANT_ID=$AZURE_TENANT_ID --from-literal=AZURE_SUBSCRIPTION_ID=$AZURE_SUBSCRIPTION_ID
  1. Click on Components, search for Azure Storage, and add the Storage Account to the design area. Select Components Search Storage Account
  2. Configure the Storage Account to fit your needs. Config Storage Account
  3. Configure the following properties:
    • resourceGroupName
    • location (e.g., eastus)
    • accountName
    • accessTier (Hot or Cool)
  4. Click Actions β†’ Deploy. Deploy Storage Account
  • Azure Portal: Confirm the new Storage Account appears in your specified resource group.

You have successfully:

  • Created an Azure Service Principal for Meshery
  • Connected your Kubernetes cluster to Meshery
  • Installed the Azure Service Operator (Meshery managed CRDs)
  • Created a Kubernetes secret for Azure credentials
  • Designed and deployed an Azure Storage Account using Meshery’s Kanvas

If you want to learn more about Azure Service Operator, visit the official ASO documentation.

Related Reading

Last modified June 1, 2026: [chore] add prerequisites (708d89de7c7)