Azure Container Registries averaging under one image pull and push for 30 days
What does ZopNight detect here?
ZopNight flags an Azure Container Registry when its average `TotalPullCount` and average `TotalPushCount` both stay below 1 across at least 30 distinct days, and the registry has a known cost. Every Basic, Standard and Premium registry is billed a daily rate whether images move or not, so a registry nobody pulls from is a standing charge.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1371 |
| Category | idle |
| Severity | low |
| Metric | TotalPullCount, TotalPushCount |
| Threshold | both averages < 1 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.ContainerRegistry/registries/read · Microsoft.Insights/Metrics/Read |
Where it applies
A registry’s price is a daily rate, not per pull
Azure Container Registry pricing charges each registry a price per day for its service tier, Basic, Standard or Premium. Each tier includes storage, 10, 100 and 500 GiB respectively according to the SKU reference, and storage beyond that adds a daily rate per GiB. Pulls and pushes do not change the tier charge.
Registries get created per project, per team, per proof of concept, and they are rarely deleted when the project ends. Each one keeps billing its daily rate, and Premium features such as geo-replication multiply that.
Seeing whether anyone uses a registry
az acr list --query "[].{name:name, rg:resourceGroup, sku:sku.name, location:location}" -o table
az monitor metrics list --resource <registry-resource-id> \ --metric TotalPullCount TotalPushCount --offset 30d --interval PT24H --aggregation Totalaz acr repository list --name myregistry shows what images are stored, which helps decide what
to keep before deleting.
Thresholds for calling a registry idle
- Both the pull and push series exist for the registry.
- Each series covers at least 30 distinct days. Days with zero activity can be missing from a summed series, so ZopNight counts the span of days covered rather than the number of data points, which keeps a registry pulled once a day from looking thinly observed.
- The average pull count and the average push count across the window are both below 1.
- The registry has a known monthly cost above zero.
When a quiet registry is not reported
A few pulls or pushes do not clear the registry, because the check uses the average, not the peak. A missing series, or fewer than 30 days of coverage, also means no finding: silence in the data is not proof of silence in the registry. There is no fallback to tags or guesses.
The registry’s whole bill is the saving
saving = current monthly cost of the registry (tier daily rate plus extra storage)cost after fix = 0If you keep the registry but move it to a cheaper tier, the saving is the difference between tier rates instead.
Deleting or shrinking an unused registry
- Search deployment manifests, Helm charts, pipelines and AKS image pull settings for the registry’s login server name.
- Export any image you must keep, for example with
az acr importinto another registry. - Delete the registry:
az acr delete --resource-group my-rg --name myregistry. - If it must stay but sees little use, downgrade instead:
az acr update --name myregistry --sku Basic(check that the smaller tier’s included storage and features still fit).