Review Azure Container Registry permission scope

Limit Azure Container Registry permissions for identities that only pull images.

Description

Giving publishing permissions to a workload that only pulls images can let a compromised identity upload images or change tags. Separate the permissions needed to consume images, publish them and manage the registry. AcrPush permits image reads and writes, but does not grant registry configuration management.

Potential impact

  • Unnecessary write access can allow image or tag changes that cause modified images to be deployed.
  • A compromised workload can affect other deployments.

Remediation

Give pull-only identities a read role appropriate to the registry permission mode. Use AcrPull in RBAC Registry Permissions mode; for ABAC-enabled mode, consider Container Registry Repository Reader scoped to the required repositories. Separate publishing and administrative identities, and review effective access including other role assignments.

Examples

These excerpts compare the role of a kubelet identity that consumes images in RBAC Registry Permissions mode.

Before

hcl
resource "azurerm_role_assignment" "workload" {
  principal_id         = azurerm_kubernetes_cluster.example.kubelet_identity[0].object_id
  role_definition_name = "AcrPush"
  scope                = azurerm_container_registry.example.id
}

AcrPush allows both pulling and publishing images. A workload that only pulls images does not need the write permission.

After

hcl
resource "azurerm_role_assignment" "workload" {
  principal_id         = azurerm_kubernetes_cluster.example.kubelet_identity[0].object_id
  role_definition_name = "AcrPull"
  scope                = azurerm_container_registry.example.id
}

This assignment grants image read access through AcrPull. Check that other roles or credentials do not retain write access.

References