Review resource locks for Azure Container Registry

Apply resource locks where needed to protect a registry from accidental deletion or management changes.

Description

Azure resource locks restrict management operations on a registry. CanNotDelete blocks deletion; ReadOnly blocks deletion and modification. Locks on a parent resource group or subscription are inherited.

A registry resource lock does not prevent image creation, overwriting or deletion. Use image attributes and access permissions to protect images separately.

Potential impact

Without a required lock, an administrator's mistake could delete the registry or change its configuration, interrupting image pulls and deployments.

Remediation

Check locks on the registry and its parent scopes, then choose the level needed for operation. In Ansible, can_not_delete prevents deletion and read_only applies a read-only lock. A group-level read-only lock also restricts updates to other resources, so check its scope before applying it.

Examples

This example creates a registry in an existing myResourceGroup and adds a group-level lock. The registry name must be globally unique.

Before

yaml
- name: Create an azure container registry
  azure_rm_containerregistry:
    name: myRegistry
    location: eastus
    resource_group: myResourceGroup
    admin_user_enabled: true
    sku: Premium

The registry creation configuration includes no resource lock.

After

yaml
- name: Create an azure container registry
  azure_rm_containerregistry:
    name: myRegistry
    location: eastus
    resource_group: myResourceGroup
    admin_user_enabled: true
    sku: Premium

- name: Create a lock for a resource group
  azure_rm_lock:
    resource_group: myResourceGroup
    name: myLock
    level: read_only

A read-only lock is added to the resource group. It restricts management changes to the registry and other resources in the group; image operations remain governed by separate permissions.

References