Skip to main content
provisioning · azure

Azure Container Registry

category
Container Registry

What does zop.dev create for Azure Container Registry?

zop.dev provisions the ACR registry in 1 of 3 SKUs (Basic, Standard, or Premium, defaulting to region eastus) and wires access from two directions: the AKS module assigns the cluster's ACR pull role, and each namespace gets dedicated AAD service principals for registry authentication.

Module backing Azure Container Registry.
Field Value
Cloudazure

Azure Container Registry stores container images for AKS deployments. zop.dev provisions the registry and wires pull access into the cluster and per-namespace service principals.

Registry with cluster and namespace pull access

ACR registry; the AKS module assigns the ACR pull role, and namespaces get dedicated AAD service principals for registry access.

SKU choice and the eastus default region

Terminal window
sku Basic|Standard|Premium; region default eastus.

Exposed as the artifact resource type

Exposed in the provisioner API as the artifact resource type for Azure.

Pull access arrives from two directions

The registry itself is one resource; the access wiring is the substance. The AKS module assigns an ACR pull role to the cluster identity, so nodes can pull images with no stored password at all. Namespaces additionally get their own AAD service principals for registry access, one for services and one for cron jobs. These are real credentials with expiring passwords. When pulls fail in exactly one namespace while the rest of the cluster is healthy, the namespace’s service principal is the first suspect.

SKU is a daily fee plus storage

ACR bills a per-day rate by SKU with included storage, and per-GB beyond it. Basic, Standard, and Premium differ in storage, throughput, and features. The one hard feature gate worth knowing is geo-replication, which is Premium-only. The registry accumulates weight the same way every registry does: each CI push adds layers, nothing removes them by default, and the included-storage line gets crossed silently. Retention discipline is a policy decision to make early, not a cleanup project to schedule later.

The name is global and permanent

A registry name is globally unique across Azure: it becomes the login server hostname (<name>.azurecr.io), and it cannot be changed after creation. Every deployment manifest and pipeline that references images embeds it, so a rename is really a new registry plus a migration of images and references. Choose it like a domain name.

Where it sits in the provisioner

The provisioner API exposes this as the artifact resource type for Azure, the same noun the platform uses for registries on other clouds. Registry lifecycle is therefore drivable through the API rather than only through cluster provisioning.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·