Skip to main content

Azure Container Registry

Azure Container Registry is Microsoft's private registry for container images and other Open Container Initiative (OCI) artifacts. The Azure Enterprise Baseline runs one registry for the whole organization, cracmeeus2artifacts in acme-core-artifacts, and every image of the Azure blueprints is pushed to it once and then locked.

What it does​

A registry holds repositories of images. An image is addressed by a tag, which can move, or by its manifest digest, which cannot. Clients sign in with a Microsoft Entra token (az acr login) and act through built-in roles such as AcrPush and AcrPull; an admin user and anonymous pull exist but are optional. A lock on a tag or manifest (write and delete disabled) makes it immutable. ACR Tasks run builds and scheduled commands, such as acr purge, inside the registry. The Premium SKU adds zone redundancy, private endpoints and a native retention policy for untagged manifests.

How BuiltForProd uses it​

The acr unit (module container-registry) creates the registry in its own resource group, <prefix>-acr-rg, under a CanNotDelete lock.

SettingValue in the unit file
SKUStandard, $20/month; Premium ($50/month) is the @optional: for zone redundancy, the native retention policy and private endpoints
AuthenticationMicrosoft Entra only: no admin user, no anonymous pull
NetworkPublic endpoint with Entra authentication, because image builds run on GitHub-hosted runners; private-only needs Premium
Permission modeLegacy registry permissions, so AcrPush and AcrPull apply to the whole registry
Untagged imagesNightly task purge-untagged (02:00 UTC) deletes untagged manifests older than 14 days; locked manifests are skipped
LogsRepository and login events and all metrics to the audit Log Analytics workspace

Three repositories live in it: github-runner, the image of the Container Apps runners, built inside the registry by the Baseline's runner-image.yml with az acr build; acme-azure-blueprint-webapp, the web application's API; and acme-azure-blueprint-etl-trigger, the ETL trigger.

IdentityRole on the registryWhy
Deployer identities of the two code repositories and the BaselineAcrPushPush, re-tag and lock images
Deployer identities of the two blueprint infrastructure repositoriesRole Based Access Control Administrator, limited by a condition to AcrPullGrant AcrPull to the identities they create, nothing else
Kubelet identity of each AKS cluster, ETL trigger identity of each stage, runner job identityAcrPullPull images

In the legacy permission mode AcrPush covers the tag and manifest locks, so the pipelines need no extra role. Every pipeline runs az acr repository update --write-enabled false --delete-enabled false right after a push: main-<sha> and every vX.Y.Z release tag cannot be overwritten or deleted, and a release adds its tag to the manifest that was already tested. Microsoft Defender for Containers, on in every subscription, scans the registry's images; see Microsoft Defender for Cloud. The registry ID and login server are published in every stage's contract vault as platform--acr-id and platform--acr-login-server.

Terms you will see​

TermMeaning
RepositoryThe images of one application, such as acme-azure-blueprint-webapp.
Tag lockWrite and delete disabled on a tag, which makes the tag immutable.
Manifest digestThe content hash of an image; a release tag points at the same digest.
AcrPush, AcrPullThe built-in roles for pushing and pulling images.
ACR TaskA build or scheduled command run by the registry, here purge-untagged.
Legacy permission modeThe mode in which AcrPush and AcrPull apply to every repository.

Where to read more​