Review Azure Container Registry deletion locks

Check deletion protection for important Azure Container Registry resources.

Description

Accidental or unauthorized deletion of a container registry can interrupt image deployment and service recovery. A management lock provides deletion protection separately from access permissions.

A CanNotDelete lock blocks management-plane deletion of the registry, but does not protect data operations on images or tags. Check locks inherited from the resource group or subscription as well.

Potential impact

  • Missing images can delay new deployments or recovery.
  • Rebuilding the registry and restoring images can take time and incur costs.

Remediation

Apply an azurerm_management_lock with CanNotDelete to important registries, or verify an effective inherited lock. Restrict permissions to remove locks and establish a change procedure. Manage image deletion permissions and image recovery separately.

Examples

These excerpts add a deletion lock to the same registry.

Before

hcl
resource "azurerm_container_registry" "acr" {
  name                = "containerRegistry1"
  resource_group_name = azurerm_resource_group.rg.name
  location            = azurerm_resource_group.rg.location
  sku                 = "Standard"
  admin_enabled       = false
}

This excerpt has no individual lock. Check whether protection is inherited from a parent scope.

After

hcl
resource "azurerm_container_registry" "acr" {
  name                = "containerRegistry1"
  resource_group_name = azurerm_resource_group.rg.name
  location            = azurerm_resource_group.rg.location
  sku                 = "Standard"
  admin_enabled       = false
}

resource "azurerm_management_lock" "acr_lock" {
  name       = "acr-lock"
  scope      = azurerm_container_registry.acr.id
  lock_level = "CanNotDelete"
  notes      = "Protect registry from accidental deletion"
}

The added lock blocks registry deletion. Identities permitted to remove locks can disable it, so access control remains necessary.

References