Azure Container Registry
Azure Container Registry is Microsoft's private registry for container images and other Open Container Initiative (OCI) artifacts. The Azure Enterprise Baseline runs one registry for the whole organization, cracmeeus2artifacts in acme-core-artifacts, and every image of the Azure blueprints is pushed to it once and then locked.
What it does
A registry holds repositories of images. An image is addressed by a tag, which can move, or by its manifest digest, which cannot. Clients sign in with a Microsoft Entra token (az acr login) and act through built-in roles such as AcrPush and AcrPull; an admin user and anonymous pull exist but are optional. A lock on a tag or manifest (write and delete disabled) makes it immutable. ACR Tasks run builds and scheduled commands, such as acr purge, inside the registry. The Premium SKU adds zone redundancy, private endpoints and a native retention policy for untagged manifests.
How BuiltForProd uses it
The acr unit (module container-registry) creates the registry in its own resource group, <prefix>-acr-rg, under a CanNotDelete lock.
| Setting | Value in the unit file |
|---|---|
| SKU | Standard, @optional: for zone redundancy, the native retention policy and private endpoints |
| Authentication | Microsoft Entra only: no admin user, no anonymous pull |
| Network | Public endpoint with Entra authentication, because image builds run on GitHub-hosted runners; private-only needs Premium |
| Permission mode | Legacy registry permissions, so AcrPush and AcrPull apply to the whole registry |
| Untagged images | Nightly task purge-untagged (02:00 UTC) deletes untagged manifests older than 14 days; locked manifests are skipped |
| Logs | Repository and login events and all metrics to the audit Log Analytics workspace |
Three repositories live in it: github-runner, the image of the Container Apps runners, built inside the registry by the Baseline's runner-image.yml with az acr build; acme-azure-blueprint-webapp, the web application's API; and acme-azure-blueprint-etl-trigger, the ETL trigger.
| Identity | Role on the registry | Why |
|---|---|---|
| Deployer identities of the two code repositories and the Baseline | AcrPush | Push, re-tag and lock images |
| Deployer identities of the two blueprint infrastructure repositories | Role Based Access Control Administrator, limited by a condition to AcrPull | Grant AcrPull to the identities they create, nothing else |
| Kubelet identity of each AKS cluster, ETL trigger identity of each stage, runner job identity | AcrPull | Pull images |
In the legacy permission mode AcrPush covers the tag and manifest locks, so the pipelines need no extra role. Every pipeline runs az acr repository update --write-enabled false --delete-enabled false right after a push: main-<sha> and every vX.Y.Z release tag cannot be overwritten or deleted, and a release adds its tag to the manifest that was already tested. Microsoft Defender for Containers, on in every subscription, scans the registry's images; see Microsoft Defender for Cloud. The registry ID and login server are published in every stage's contract vault as platform--acr-id and platform--acr-login-server.
Terms you will see
| Term | Meaning |
|---|---|
| Repository | The images of one application, such as acme-azure-blueprint-webapp. |
| Tag lock | Write and delete disabled on a tag, which makes the tag immutable. |
| Manifest digest | The content hash of an image; a release tag points at the same digest. |
| AcrPush, AcrPull | The built-in roles for pushing and pulling images. |
| ACR Task | A build or scheduled command run by the registry, here purge-untagged. |
| Legacy permission mode | The mode in which AcrPush and AcrPull apply to every repository. |
Where to read more
- Azure Enterprise Baseline overview, Azure Web App Blueprint overview and Azure Data and ETL Blueprint overview.
- Docker for how the images are built and scanned.
- Immutable artifacts for why a tag never moves.