
Azure Storage SFTP is Microsoft's managed file transfer service built on Azure Blob Storage that provides SFTP endpoint access to cloud storage containers. It abstracts server management but ties teams to continuous hourly endpoint charges, Azure AD authentication, and Microsoft's storage ecosystem.
SFTPGo is an open-source file transfer server that provides SFTP, FTP/S, and WebDAV with native Azure Blob Storage support, web-based user management, and flexible authentication. It delivers the same file transfer capabilities on any infrastructure without continuous hourly charges or cloud provider lock-in.
This article explains how to deploy SFTPGo as a self-hosted alternative to Azure Storage SFTP using Docker Compose with Traefik for automatic HTTPS. It covers user authentication, Azure Blob Storage backend configuration, multi-protocol access (SFTP, FTP/S, WebDAV), and migration strategies from Azure Storage SFTP.
SFTPGo maps directly to Azure Storage SFTP features while providing additional flexibility. The following table compares Azure Storage SFTP components with their SFTPGo equivalents:
Key components of SFTPGo include:
Before you begin, you need to:
sftp.example.com).The stack consists of two containers: SFTPGo handles file transfer and user management, and Traefik acts as a reverse proxy that provisions a Let's Encrypt TLS certificate and routes HTTPS traffic to the SFTPGo admin interface on port 8080. Deploying Traefik from the start ensures that all credentials and configuration data transit over TLS from the first request.
Create the project directory with subdirectories for data and configuration persistence.
data: Stores user files served over SFTP.config: Holds SFTPGo configuration and the SQLite database.Switch to the project directory.
Create an environment file for domain configuration. Replace sftp.example.com with your domain and admin@example.com with your email address for Let's Encrypt notifications.
Add the following variables:
Save and close the file.
Create the Docker Compose configuration file.
Add the following service definition:
Save and close the file.
This configuration exposes:
The web admin interface on port 8080 is not exposed directly to the host. Traefik proxies requests to it internally over the Docker network.
Launch the stack.
Confirm all containers are running and healthy.
Review the container logs to verify that no startup errors occurred.
For more information on managing a Docker Compose stack, see the How To Use Docker Compose article.
The web-based administration interface handles initial setup and ongoing server configuration.
Open a web browser and navigate to https://sftp.example.com/web/admin, replacing sftp.example.com with your configured domain.
Create an administrator account on first access:
admin)The dashboard loads.
Navigate to Server Manager > Configurations in the sidebar to review default settings.
Review the SFTP, ACME, and SMTP sections to confirm that the default configuration matches your requirements.
SFTPGo supports password authentication, SSH public keys, and multi-factor authentication. Azure Storage SFTP local users can be recreated with equivalent access controls.
Navigate to Users in the sidebar.
Click Add to create a new user.
Configure the account settings:
Under File system, keep Local disk selected for local storage.
Set the Root directory to /srv/sftpgo/USERNAME, replacing USERNAME with the SFTP username configured in the previous step.
Click Save.
SSH keys provide passwordless authentication similar to Azure Storage SFTP's SSH key support.
Generate an SSH key pair on the client machine if one does not exist.
When prompted for a passphrase, press Enter twice to create the key without a passphrase for passwordless authentication.
Display the public key.
Output:
In the SFTPGo web interface, navigate to Users, click Actions next to the target user, and select Edit.
Locate the Public keys section.
Paste the public key string into the text field.
Click Save.
Test key-based authentication from the client. Replace USERNAME with your SFTPGo username.
Navigate to Users, click Actions next to the target user, and select Edit.
Expand the ACLs section and locate Require 2FA for.
Select the protocols requiring two-factor authentication.
Click Save.
The user configures their authenticator app on next login via the WebClient portal.
SFTPGo supports local storage and S3-compatible object storage.
Local storage is the default backend. Files are stored under /srv/sftpgo/data/USERNAME/.
Navigate to Users, click Actions next to the target user, and select Edit.
Under File system, verify that Local disk is selected in the Storage dropdown.
Set the Root directory to /srv/sftpgo/USERNAME, replacing USERNAME with the SFTP username.
Click Save.
SFTPGo supports any S3-compatible storage service as a user backend, including MinIO and Vultr Object Storage.
Gather the following credentials from your S3-compatible storage provider:
https://ewr1.vultrobjects.com).In the SFTPGo web interface, navigate to Users, click Actions next to the target user, and select Edit.
Under File system, select S3 (Compatible) from the Storage dropdown.
Fill in the S3 backend fields:
ewr1).https://ewr1.vultrobjects.com).Enable Use path-style addressing for S3-compatible endpoints.
Click Save.
Create a test file on the client machine.
Connect via SFTP to verify the configuration. Replace USERNAME with your SFTPGo username and sftp.example.com with your configured domain.
Upload the test file.
Verify that the file appears in the bucket.
Close the SFTP session.
S3-compatible backends have behavioral differences from local storage:
chmod and chown operations are silently ignored.SFTPGo runs SFTP on port 2022 by default and also supports FTP with TLS (FTP/S) and WebDAV for legacy clients and HTTP-based file access. Each protocol uses its own listener port and shares the same user accounts, authentication backends, and storage configuration.
SFTPGo enforces quotas, bandwidth limits, IP restrictions, and per-directory permissions at the user level. Configure these controls to replicate Azure Storage SFTP access policies.
Navigate to Users, click Actions next to the target user, and select Edit.
Expand the Disk quota and bandwidth limits section.
Configure quota settings:
10 GB or 500 MB).Click Save.
Navigate to Users, click Actions next to the target user, and select Edit.
Expand the Disk quota and bandwidth limits section.
Set bandwidth restrictions:
5120 for 5 MB/s)5120 for 5 MB/s)Click Save.
Navigate to Users, click Actions next to the target user, and select Edit.
Expand the ACLs section and locate Allowed IP/Mask.
Add permitted IP addresses or CIDR ranges:
Optionally configure Denied IP/Mask to block specific addresses.
Click Save.
Navigate to Users, click Actions next to the target user, and select Edit.
Expand the ACLs section and under Per-directory permissions, configure access:
/uploads)Click Save.
Set up logging and event hooks to replace Azure Monitor integration.
Create a logs directory for persistent log storage.
Open docker-compose.yml to add logging configuration.
Append the logs volume to the existing volumes: block under the sftpgo service:
Append the following logging environment variables to the existing environment: block under the sftpgo service:
Save and close the file.
Apply the updated configuration.
SFTPGo supports HTTP webhooks for event notifications, replacing Azure Monitor alerts.
Navigate to Event Manager, then click Actions in the left sidebar.
Click Add to create a new action.
Configure the action:
webhook-action).Click Save.
Click Rules in the left sidebar.
Click Add to create a new event rule.
Configure the event trigger:
upload-notification).Under Actions, select the previously created action.
Click Save.
Forward logs to a centralized logging system as an alternative to Azure Monitor.
Open docker-compose.yml and add syslog configuration. Replace SYSLOG-SERVER with your syslog server address.
Append the following environment variables to the existing environment: block under the sftpgo service:
Save and close the file.
Apply the updated configuration.
Verify the deployment by testing file transfer operations.
Create a test file on the client machine.
Connect to the SFTP server. Replace USERNAME with your SFTPGo username.
Enter the password when prompted.
List directory contents.
Upload the test file.
Download the file to verify.
Exit the session.
Connect using your private key. Replace USERNAME with your SFTPGo username.
Verify that the connection is established without a password prompt.
Exit the session.
Install an FTP client such as lftp.
Connect with explicit TLS. Replace USERNAME with your FTP username.
List files to verify the connection.
Exit the session.
Migrating from Azure Storage SFTP requires recreating user accounts in SFTPGo, transferring stored data to the new storage backend, and updating client connection settings to point to the new server.
Export local user configurations from Azure Storage and recreate them in SFTPGo.
List Azure Storage SFTP local users using the Azure CLI. Replace STORAGE-ACCOUNT with your storage account name and RESOURCE-GROUP with your resource group name.
Export user details including SSH keys. Replace USERNAME with the local user name to export.
For each user, record:
Generate an API access token using your SFTPGo admin credentials. Replace ADMIN-USERNAME and ADMIN-PASSWORD with your SFTPGo admin credentials and sftp.example.com with your configured domain.
The response contains an access_token value. The token expires after 15 minutes. Copy it and complete the next step before it expires.
Create the user via the REST API. Replace ACCESS-TOKEN with the token from the previous step.
Replace:
sftp.example.com with your configured domain.USERNAME with the migrated SFTP username.PASSWORD with a strong password for the user.SSH-PUBLIC-KEY with the user's SSH public key string. The "status": 1 field activates the user account. Without it, the user is created in a disabled state and cannot log in.
Transfer data from Azure Blob Storage to the SFTPGo storage backend.
If using Azure Blob as the SFTPGo backend, point users to the same container. No data migration is required.
For local filesystem backend, download data using Azure CLI. Replace the placeholders with your storage account details.
Set correct ownership on downloaded files.
Convert Azure authentication methods to SFTPGo equivalents.
For Azure AD integration, configure an external authentication hook that validates against your identity provider.
Update SFTP client applications with the new endpoint.
Document the new connection parameters:
sftp.example.com (your SFTPGo server)2022 (SFTP)Distribute updated connection details to users.
Update automated scripts and integrations.
Test each client before disabling Azure Storage SFTP.
Address Azure-specific features when migrating:
Hierarchical Namespace: Azure Storage SFTP requires HNS. SFTPGo simulates directories without this requirement, which may affect applications that depend on HNS behavior.
Container-Level Permissions: Azure assigns permissions per container. Map these to SFTPGo's per-directory permissions under the ACLs section.
Azure AD Authentication: If using Azure AD (preview), configure SFTPGo with an external authentication hook or LDAP plugin to integrate with your identity provider.
Storage Lifecycle Policies: SFTPGo does not manage Azure Blob lifecycle rules. Configure lifecycle policies directly in Azure Storage if continuing to use Azure Blob as the backend.
Azure Monitor Integration: Replace Azure Monitor logging with SFTPGo's built-in logging, syslog forwarding, or webhook integrations.
Managed SSH Host Keys: Export the SSH host key from SFTPGo (/var/lib/sftpgo/id_*) and distribute the fingerprint to clients to avoid host key warnings.
You have deployed SFTPGo as a self-hosted alternative to Azure Storage SFTP using Docker Compose. The setup includes SFTP protocol support, Azure Blob Storage backend integration, user authentication with SSH keys and passwords, and access controls matching Azure Storage SFTP capabilities. This configuration eliminates the $0.30/hour (~$220/month) charge while providing equivalent file transfer functionality. For additional features including plugins, clustering, and enterprise options, refer to the official SFTPGo documentation.
0 Comments
Be the first to comment and share your perspective with the community.