Description
Azure resource locks restrict management operations on a registry. CanNotDelete blocks deletion; ReadOnly blocks deletion and modification. Locks on a parent resource group or subscription are inherited.
A registry resource lock does not prevent image creation, overwriting or deletion. Use image attributes and access permissions to protect images separately.
Potential impact
Without a required lock, an administrator's mistake could delete the registry or change its configuration, interrupting image pulls and deployments.
Remediation
Check locks on the registry and its parent scopes, then choose the level needed for operation. In Ansible, can_not_delete prevents deletion and read_only applies a read-only lock. A group-level read-only lock also restricts updates to other resources, so check its scope before applying it.
Examples
This example creates a registry in an existing myResourceGroup and adds a group-level lock. The registry name must be globally unique.
Before
- name: Create an azure container registry
azure_rm_containerregistry:
name: myRegistry
location: eastus
resource_group: myResourceGroup
admin_user_enabled: true
sku: Premium
The registry creation configuration includes no resource lock.
After
- name: Create an azure container registry
azure_rm_containerregistry:
name: myRegistry
location: eastus
resource_group: myResourceGroup
admin_user_enabled: true
sku: Premium
- name: Create a lock for a resource group
azure_rm_lock:
resource_group: myResourceGroup
name: myLock
level: read_only
A read-only lock is added to the resource group. It restricts management changes to the registry and other resources in the group; image operations remain governed by separate permissions.