Azure Container Registry
A managed, private Docker registry service in Azure used to store and manage container images, integrated with AKS, ACI, and App Service for authenticated image pulls without exposing images publicly.
Azure Container Registry
ACR is where you push built container images before deploying them to AKS, ACI, or App Service — private by default, with fine-grained RBAC over who can push or pull.
Why It Matters in Production
CRED's CI pipeline builds and pushes images to credprodacr.azurecr.io, and its AKS cluster is granted pull-only access via a Managed Identity, so no registry credentials are ever stored in cluster secrets.
az acr create --resource-group cred-prod-rg --name credprodacr --sku Premiumaz aks update --name cred-prod-aks --resource-group cred-prod-rg \ --attach-acr credprodacrSecurityEnable ACR's content trust / image signing on Premium tier for production registries to prevent unsigned or tampered images from being deployed.
Frequently Asked Questions
Why use ACR instead of just pulling images from Docker Hub in Azure workloads?
Docker Hub's public images work fine for open-source bases, but private application images need authenticated, access-controlled storage tightly integrated with the platform running them. ACR integrates natively with AKS, ACI, and App Service using managed identities, so pulls happen without embedding credentials anywhere, and it keeps proprietary images inside the Azure trust boundary rather than a third-party public registry.
What's a common mistake teams make with ACR?
Hitting Docker Hub's public rate limits by having every AKS node pull common base images (like nginx or postgres) directly from Docker Hub instead of caching them through ACR, which can cause pull failures during high-traffic scaling events. Setting up ACR as a pull-through cache for frequently used public images avoids depending on Docker Hub's availability and rate limits in production.