Catalog
github/azure-container-registry-cli

github

azure-container-registry-cli

Manage Azure Container Registry via the az acr CLI including registries, images, cloud builds, ACR Tasks, authentication, tokens, geo-replication, and networking. Use when working with ACR, az acr commands, pushing/importing/purging container images in Azure, or when the user mentions Azure Container Registry.

v1.0LATEST
NewUpdated Jul 30, 2026

Azure Container Registry CLI

Manage Azure Container Registry (ACR) resources using the az acr command group of the Azure CLI.

CLI: az acr ships with core Azure CLI — no extension required (the acrtransfer extension is only needed for export/import pipelines).

Prerequisites

# Install Azure CLI
brew install azure-cli  # macOS
curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash  # Linux
winget install Microsoft.AzureCLI  # Windows

# Sign in and select subscription
az login
az account set --subscription {subscription-id}

Quick Start

# Create a registry (SKU: Basic | Standard | Premium)
az acr create --resource-group {rg} --name {registry} --sku Standard

# Authenticate Docker/Podman against the registry
az acr login --name {registry}

# Build and push in the cloud — no local Docker needed
az acr build --registry {registry} --image app:v1 .

# Copy an image from another registry without pull/push
az acr import --name {registry} --source mcr.microsoft.com/hello-world:latest

# List repositories and tags
az acr repository list --name {registry} --output table
az acr repository show-tags --name {registry} --repository app --orderby time_desc

# Diagnose registry connectivity and configuration
az acr check-health --name {registry} --yes

Key Principles

  • Prefer az acr build / ACR Tasks over local docker build + docker push: builds run in Azure, work without a local daemon, and integrate with triggers.
  • Prefer az acr import to move images between registries: it is server-side, faster, and requires no local storage.
  • Never enable the admin user for production — use Microsoft Entra identities (RBAC roles AcrPull/AcrPush, or Container Registry Repository Reader/Writer on ABAC-enabled registries), repository-scoped tokens, or managed identities.
  • Premium-only features: geo-replication, private endpoints, retention policies, connected registries, agent pools. (Repository-scoped tokens work in all tiers; zone redundancy is automatic in all tiers in supported regions.)

CLI Structure

az acr
├── create / delete / list / show / update   # Registry lifecycle
├── login                  # Docker credential helper (or --expose-token)
├── check-health / check-name / show-usage   # Diagnostics & quota
├── build                  # Cloud image build (quick task)
├── run                    # Run a command / multi-step task once
├── task                   # ACR Tasks (triggers, timers, logs, runs)
├── agentpool              # Dedicated task agent pools (Premium)
├── import                 # Server-side image copy into the registry
├── repository             # List/show/delete/untag repos & tags, lock images
├── manifest               # Manifest metadata, delete, OCI referrers
├── credential             # Admin user credentials (avoid in production)
├── token / scope-map      # Repository-scoped tokens (Premium)
├── replication            # Geo-replication (Premium)
├── network-rule           # IP network rules
├── private-endpoint-connection  # Private Link approvals
├── config                 # content-trust, retention, soft-delete, ...
├── cache / credential-set # Artifact cache (pull-through cache) rules
├── webhook                # Push/delete event webhooks
├── connected-registry     # On-premises / IoT connected registries
└── export-pipeline / import-pipeline / pipeline-run  # acrtransfer extension

Reference Files

Read the relevant reference file based on the user's task. Each file contains complete command syntax and examples for its domain.

File When to read Covers
references/auth-and-security.md Login failures, permissions, CI/CD or AKS pull access az acr login (incl. --expose-token), Entra RBAC roles, service principals, managed identities, --attach-acr for AKS, repository-scoped tokens & scope maps, admin user, content trust
references/build-and-tasks.md Building images in Azure, automation, CI triggers az acr build, az acr run, multi-step task YAML, az acr task (git/base-image/timer triggers, logs, runs), agent pools
references/images-and-artifacts.md Managing repos, tags, cleanup, storage costs az acr import, repository & manifest commands, untag vs delete, purge (acr purge), image locking, retention policy, soft delete, artifact cache, show-usage
references/networking-and-geo.md Multi-region, private access, edge scenarios Geo-replication, zone redundancy, private endpoints, network rules, dedicated data endpoints, connected registries, registry transfer pipelines
Files5
5 files · 27.8 KB

Select a file to preview

Overall Score

82/100

Grade

B

Good

Grades are signals, not a certification. Always review a skill yourself before use.

Safety

80

Quality

85

Clarity

84

Completeness

78

Summary

This skill guides agents through Azure Container Registry (ACR) management using the `az acr` CLI. It provides structured reference documentation across four domains: authentication/security, builds/tasks, image management, and networking. The skill emphasizes security best practices (Entra RBAC over admin credentials, repository-scoped tokens, no privilege escalation in normal operations) and includes comprehensive command examples with clear warnings for risky operations like purging images or disabling public access.

Static Analysis Findings

1 finding

Patterns detected by deterministic static analysis before AI scoring. Hover over any finding code for detailed information and remediation guidance.

Destructive Operation
SEC-002Privilege Escalation

Privilege escalation (sudo)

SKILL.mdsudo b

Detected Capabilities

shell execution (az acr commands)environment variable readsfile reading (reference documentation)network requests (Azure API calls)credential management (tokens, managed identities)RBAC assignmentoutbound network access (Azure services)

Trigger Keywords

Phrases that agents use to match this skill to user intent.

azure container registryacr image pushacr task schedulecontainer image purgeacr networking configdocker registry replicateacr authentication setupbuild container cloud

Risk Signals

WARNING

Privilege escalation (sudo bash) in Linux install prerequisite

SKILL.md:24
WARNING

Credential reads: service principal passwords, token credentials, admin user passwords

references/auth-and-security.md (multiple locations)
WARNING

Destructive operations: repository delete, manifest delete, purge with --untagged flag

references/images-and-artifacts.md:Untag vs Delete, Purge Old Images sections
INFO

Network-restricted registry access requires task network bypass policy or agent pool configuration

references/networking-and-geo.md:Public Network Rules
INFO

ABAC-enabled registries require explicit identity assignment; legacy RBAC roles not honored

references/auth-and-security.md:Microsoft Entra RBAC Roles, references/build-and-tasks.md:ACR Tasks section

Referenced Domains

External domains referenced in skill content, detected by static analysis.

aka.msgithub.com{account}.blob.core.windows.net{vault}.vault.azure.net

Use Cases

  • Deploy container images to Azure Container Registry via cloud builds
  • Manage multi-region image replication and geo-failover
  • Set up CI/CD triggers and automated task scheduling
  • Authenticate applications to ACR using managed identities and RBAC
  • Copy images between registries without local pull/push
  • Configure network isolation with private endpoints and firewall rules
  • Clean up old images and manage storage quotas
  • Debug registry connectivity and diagnose authentication failures

Quality Notes

  • Excellent structure: clear section hierarchy with table of contents and well-organized reference files by domain
  • Security best practices explicitly documented: caution against admin user in production, preference for Entra RBAC, warnings on untag vs delete semantics
  • Comprehensive examples: every major command has usage patterns and edge cases (e.g., dry-run before purge, platform-specific builds)
  • Clear scope boundaries: skill focuses on ACR CLI only, does not cover Docker/Podman configuration in detail, and notes when Premium SKU is required
  • Good warning callouts: dry-run for destructive operations, untagged manifest semantics, zone redundancy deprecation quirks, ABAC role assignment gotchas
  • Reference files are practical and self-contained — agents can complete tasks without external documentation
  • Slightly verbose in places (e.g., detailed credential rotation procedures) but necessary for security-sensitive operations
Model: claude-haiku-4-5-20251001Analyzed: Jul 30, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Use github/azure-container-registry-cli in your dev environment

Command Palette

Search for a command to run...