Description
The Azure Container Registry admin account provides a username and passwords that users or systems can share. Its access spans the registry’s images, making it harder to separate permissions and accountability for individual operations.
Potential impact
Exposed or shared credentials can allow broad access to read or modify images and make it harder to identify the actor behind an operation.
Remediation
Grant suitable registry permissions to managed identities or service principals, migrate consumers, and then disable admin_user_enabled. Disabling the account does not configure replacement authentication.
Examples
The examples compare only the admin account setting. Configure alternative authentication and permissions for pulling and publishing images separately.
Before
- name: Container Registry 생성
azure.azcollection.azure_rm_containerregistry:
name: myRegistry
location: eastus
resource_group: myResourceGroup
admin_user_enabled: true
sku: Premium
After
- name: Container Registry 생성
azure.azcollection.azure_rm_containerregistry:
name: myRegistry
location: eastus
resource_group: myResourceGroup
admin_user_enabled: false
sku: Premium