Description
Accidental or unauthorized deletion of a container registry can interrupt image deployment and service recovery. A management lock provides deletion protection separately from access permissions.
A CanNotDelete lock blocks management-plane deletion of the registry, but does not protect data operations on images or tags. Check locks inherited from the resource group or subscription as well.
Potential impact
- Missing images can delay new deployments or recovery.
- Rebuilding the registry and restoring images can take time and incur costs.
Remediation
Apply an azurerm_management_lock with CanNotDelete to important registries, or verify an effective inherited lock. Restrict permissions to remove locks and establish a change procedure. Manage image deletion permissions and image recovery separately.
Examples
These excerpts add a deletion lock to the same registry.
Before
resource "azurerm_container_registry" "acr" {
name = "containerRegistry1"
resource_group_name = azurerm_resource_group.rg.name
location = azurerm_resource_group.rg.location
sku = "Standard"
admin_enabled = false
}
This excerpt has no individual lock. Check whether protection is inherited from a parent scope.
After
resource "azurerm_container_registry" "acr" {
name = "containerRegistry1"
resource_group_name = azurerm_resource_group.rg.name
location = azurerm_resource_group.rg.location
sku = "Standard"
admin_enabled = false
}
resource "azurerm_management_lock" "acr_lock" {
name = "acr-lock"
scope = azurerm_container_registry.acr.id
lock_level = "CanNotDelete"
notes = "Protect registry from accidental deletion"
}
The added lock blocks registry deletion. Identities permitted to remove locks can disable it, so access control remains necessary.