Function App: Deployment fails during package staging with storage access issues

Garcia, Luis 0 Reputation points
2026-09-16T18:01:51.86+00:00

Problem description

I am experiencing deployment failures with my Function App during the initial package staging phase. The deployments are failing before the remote build starts, with errors indicating inaccessible storage. Despite reproducing the issue with different network configurations and restoring storage settings afterward, the problem persists. I need assistance understanding why the deployment cannot access the private storage endpoint and how to configure my environment for successful private endpoint-only storage access during deployment.

Environment

Azure Function App, deployed in a private network with Blob storage using a private endpoint, located in the specified region.

What I've already tried

I have reproduced the issue with storage access enabled, route-all disabled, and VNet integration detached. After testing, I restored the storage and networking settings to their original configurations. I have also checked the deployment process and storage settings but have not yet obtained logs confirming whether the upload reached Blob storage during the failure window.

Current status

I am seeking guidance on how to configure my Function App deployment to work with private-only storage endpoints and to understand the cause of the current access failures during package staging.

Azure Functions
Azure Functions

An Azure service that provides an event-driven serverless compute platform.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Rakesh Mishra 11,350 Reputation points Microsoft External Staff Moderator
    2026-09-16T20:03:22.1633333+00:00

    Hi @Garcia, Luis ,

    Welcome to Microsoft Q&A portal. Thank you for asking your question here.

    The error text (Resource temporarily unavailable on :443) is a connectivity/name-resolution failure, not 403 AuthorizationFailure. Deployment traffic and runtime traffic do not take the same path on Flex: runtime blob access flows through your VNet integration, while the package-staging path does not necessarily egress from your integration subnet. With blob public network access set to Disabled and connectivity private-endpoint-only, the staging operation has no reachable path to stplxxxxxxxxxxrics001.blob.core.windows.net, which matches your symptom precisely.

     

    Mitigation that preserves managed identity and keeps keys disabled:

    Keep allowSharedKeyAccess = false and keep managed identity authentication — no change needed there.

    On stpxxxxxxxxxxxcs001, change blob public network access from Disabled to Enabled from selected virtual networks and IP addresses, then add the Function App's VNet-integration subnet as a network rule and enable the exception Allow Azure services on the trusted services list to access this storage account.

    • Confirm VNet integration is attached and vnetRouteAllEnabled = true on the app, and that privatelink.blob.core.windows.net is linked to the VNet the app integrates with (you confirmed the link to AZ-xxxxxx-UE2-xxxxxxx-VNET-001 — please confirm the app's integration subnet resides in that same VNet).

    This keeps data-plane access private and identity-based; it does not re-open the account to the public internet.

     

    Please retest with az functionapp deploy after applying the storage network rule above, with blob diagnostics enabled, and share the new deployment ID and UTC timestamp. If the failure reproduces on the supported OneDeploy path with the subnet rule and trusted-services exception in place, we will raise this with the Azure Functions Flex Consumption product group with your deployment IDs and correlation window for backend log correlation.  

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.