本文へ移動
cccskills
無料GitHub で公開

azure-container-registry

Expert knowledge for Azure Container Registry development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring ACR Tasks, geo-replication, connected registries, image signing/verification, or Defender scanning, and other Azure Container Registry related development tasks. Not for Azure Container Apps (use azure-container-apps), Azure Container Instances (use azure-container-instances), Azure Kubernetes Service (AKS) (use azure-kubernetes-service), Azure Red Hat OpenShift (use azure-redhat-openshift).

インストール方法を見る

含まれるファイル(1)

  • SKILL.md18.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Azure Container Registry Skill

This skill provides expert guidance for Azure Container Registry. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L52Diagnosing and fixing ACR issues: health checks, error codes, login/auth, network, performance, transfer, logs, artifact cache/streaming, Arc extension, and customer-managed keys.
Best PracticesL53-L60Best practices for ACR operations: managing public image dependencies, safe image deletion and storage cleanup, and robust image tagging/versioning strategies.
Decision MakingL61-L67Guidance on choosing Kubernetes auth methods for ACR, deciding geo-replication strategy, and migrating image signing from Docker Content Trust to Notary Project
Architecture & Design PatternsL68-L73Patterns for ACR performance and governance: caching image pulls, geo-replication strategies, connected registries for edge/offline, and gated import workflows for public images.
Limits & QuotasL74-L79Details on ACR SKUs (Basic/Standard/Premium) feature differences, performance and throughput limits, and how image storage capacity and quotas are calculated and enforced.
SecurityL80-L118Securing ACR access: auth methods (Entra, managed identity, tokens), RBAC/ABAC, network/firewall/VNet rules, policy/compliance, encryption keys, image signing/verification, and Defender scanning.
ConfigurationL119-L139Configuring ACR behavior: caching, retention/soft delete, purge, locks, IPv6, metrics/logs, webhooks, and setting up/automating ACR Tasks (YAML, timers, agent pools, patching).
Integrations & Coding PatternsL140-L157Integrating ACR with Kubernetes, ACI, GitHub Actions, ORAS, Helm, and webhooks; configuring auth, caching, transfers, image builds, and Notation-based signing/verification.
DeploymentL158-L162Using ARM templates to automate ACR quick tasks and data transfer, and deploying/managing ACR connected registries via Azure Arc extension

Troubleshooting

TopicURL
Run az acr check-health for quick ACR diagnosticshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-check-health
Troubleshoot common Azure Container Registry issueshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-faq
Interpret az acr check-health error codes and fixeshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-health-error-reference
View and manage Azure Container Registry task run logshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-logs
Troubleshoot Azure Container Registry Transfer issueshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-transfer-troubleshooting
Troubleshoot Azure Container Registry network connectivityhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-troubleshoot-access
Troubleshoot ACR login, authentication, and authorization issueshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-troubleshoot-login-authn-authz
Troubleshoot Azure Container Registry performance problemshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-troubleshoot-performance
Troubleshoot Azure Container Registry artifact cache issueshttps://learn.microsoft.com/en-us/azure/container-registry/troubleshoot-artifact-cache
Diagnose and fix Azure Container Registry artifact streaming issueshttps://learn.microsoft.com/en-us/azure/container-registry/troubleshoot-artifact-streaming
Troubleshoot connected registry Arc extension issueshttps://learn.microsoft.com/en-us/azure/container-registry/troubleshoot-connected-registry-arc
Troubleshoot customer-managed keys in Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/tutorial-troubleshoot-customer-managed-keys

Best Practices

TopicURL
Manage public image dependencies using ACRhttps://learn.microsoft.com/en-us/azure/container-registry/buffer-gate-public-content
Follow operational best practices for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-best-practices
Delete ACR images safely to manage registry storagehttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-delete
Apply image tagging and versioning best practices in ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-image-tag-version

Decision Making

TopicURL
Select Kubernetes authentication options for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/authenticate-kubernetes-options
Migrate ACR signing from DCT to Notary Projecthttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-content-trust-deprecation
Decide when and how to use ACR geo-replicationhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-geo-replication

Architecture & Design Patterns

TopicURL
Design and use connected registries with ACRhttps://learn.microsoft.com/en-us/azure/container-registry/intro-connected-registry
Implement gated import workflow for public images in ACRhttps://learn.microsoft.com/en-us/azure/container-registry/tasks-consume-public-content

Limits & Quotas

TopicURL
Compare Azure Container Registry SKU features and limitshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-skus
Review Azure Container Registry image storage limitshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-storage

Security

TopicURL
Allow trusted Azure services to access network-restricted ACRhttps://learn.microsoft.com/en-us/azure/container-registry/allow-access-trusted-services
Enable anonymous pull access for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/anonymous-pull-access
Configure cross-tenant AKS authentication to Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/authenticate-aks-cross-tenant
Restrict Azure Container Registry public access by IP ruleshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-access-selected-networks
Use Microsoft Entra service principals to access ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-auth-service-principal
Choose and configure authentication methods for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-authentication
Configure managed identity authentication to Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-authentication-managed-identity
Use Azure Policy to audit ACR compliancehttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-azure-policy
Configure Microsoft Entra Conditional Access policies for ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-configure-conditional-access
Enable Docker Content Trust for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-content-trust
Use dedicated data endpoints to secure ACR traffichttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-dedicated-data-endpoints
Control accepted Microsoft Entra auth scopes for ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-disable-authentication-as-arm
Configure firewall rules for Azure Container Registry accesshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-firewall-rules
Configure Azure ABAC repository permissions in Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-rbac-abac-repository-permissions
Reference for Azure Container Registry built-in RBAC roleshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-rbac-built-in-roles-directory-reference
Assign and manage ACR RBAC built-in roleshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-rbac-built-in-roles-overview
Create and assign custom RBAC roles for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-rbac-custom-roles
Use Azure Container Registry service tags for network ruleshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-service-tag
Access Key Vault secrets from ACR Tasks via managed identityhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-authentication-key-vault
Configure managed identity for ACR Taskshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-authentication-managed-identity
Use managed identity for cross-registry auth in ACR Taskshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-cross-registry-authentication
Configure token-based repository permissions in Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-token-based-repository-permissions
Sign ACR images with CA certs via Key Vaulthttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-sign-trusted-ca
Enforce AKS image signature verification with Ratifyhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-verify-with-ratify-aks
Restrict ACR access with virtual network service endpointshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-vnet
Disable artifact export to prevent ACR data exfiltrationhttps://learn.microsoft.com/en-us/azure/container-registry/data-loss-prevention
Manage ACR Tasks network bypass policy with trusted serviceshttps://learn.microsoft.com/en-us/azure/container-registry/manage-network-bypass-policy-for-tasks
Reference of built-in Azure Policy definitions for ACRhttps://learn.microsoft.com/en-us/azure/container-registry/policy-reference
Configure client tokens to pull from connected registrieshttps://learn.microsoft.com/en-us/azure/container-registry/pull-images-from-connected-registry
Scan ACR images with Microsoft Defender for Cloudhttps://learn.microsoft.com/en-us/azure/container-registry/scan-images-defender
Apply Azure Policy compliance controls to ACRhttps://learn.microsoft.com/en-us/azure/container-registry/security-controls-policy
Secure connected registry Arc extension deploymentshttps://learn.microsoft.com/en-us/azure/container-registry/tutorial-connected-registry-arc
Configure customer-managed encryption keys for ACRhttps://learn.microsoft.com/en-us/azure/container-registry/tutorial-customer-managed-keys
Enable customer-managed keys on Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/tutorial-enable-customer-managed-keys
Rotate and revoke customer-managed keys for ACRhttps://learn.microsoft.com/en-us/azure/container-registry/tutorial-rotate-revoke-customer-managed-keys

Configuration

TopicURL
Enable and configure artifact cache in ACR using Azure CLIhttps://learn.microsoft.com/en-us/azure/container-registry/artifact-cache-cli
Enable artifact cache in Azure Container Registry via portalhttps://learn.microsoft.com/en-us/azure/container-registry/artifact-cache-portal
Configure acr purge for automated image cleanup in ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-auto-purge
Reference Azure Container Registry endpoint types and flagshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-endpoint-reference
Configure image and repository locks in Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-image-lock
Enable IPv6 dual-stack endpoints for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-ipv6-dual-stack
Configure retention policy for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-retention-policy
Configure and use ACR soft delete retention policyhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-soft-delete-policy
Use multi-step ACR Tasks to build, test, and patch imageshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-multi-step
YAML schema reference for Azure Container Registry Taskshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-reference-yaml
Schedule Azure Container Registry Tasks with timershttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-scheduled
Configure multi-step ACR Tasks for build workflowshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-multistep-task
Webhook payload schema for Azure Container Registry eventshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-webhook-reference
Configure continuous patching for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/how-to-continuous-patching
Reference monitoring metrics and logs for Azure Container Registryhttps://learn.microsoft.com/en-us/azure/container-registry/monitor-container-registry-reference
Configure dedicated agent pools for ACR Taskshttps://learn.microsoft.com/en-us/azure/container-registry/tasks-agent-pools
Configure wildcard rules for ACR artifact cachehttps://learn.microsoft.com/en-us/azure/container-registry/wildcards-artifact-cache

Integrations & Coding Patterns

TopicURL
Configure ACR-to-ACR artifact caching with managed identityhttps://learn.microsoft.com/en-us/azure/container-registry/artifact-cache-acr-to-acr-cli
Grant Azure Container Instances access to ACR with service principalshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-auth-aci
Create Kubernetes pull secrets for Azure Container Registry accesshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-auth-kubernetes
Host and manage Helm chart repositories in ACRhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-helm-repos
Import images and artifacts into Azure Container Registry via Azure APIshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-import-images
Manage OCI and supply chain artifacts in ACR with ORAShttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-manage-artifact
Build images with Buildpacks using az acr pack buildhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tasks-pack-build
Automate ACR Transfer using ARM templateshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-transfer-arm-template
Use ACR Transfer with Azure CLI extensionhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-transfer-cli
Build, push, and sign ACR images in GitHub Actions with Notationhttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-github-sign-notation-artifact-signing
Verify signed ACR images in GitHub Actions workflowshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-github-verify-notation-artifact-signing
Sign ACR images with Notation using Azure Key Vault certificateshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-sign-build-push
Sign and verify ACR images using Notation and Artifact Signinghttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-tutorial-sign-verify-notation-artifact-signing
Configure ACR webhooks for registry event notificationshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-webhook

Deployment

TopicURL
Queue ACR quick task runs with ARM templateshttps://learn.microsoft.com/en-us/azure/container-registry/container-registry-task-run-template
Deploy the ACR connected registry Arc extensionhttps://learn.microsoft.com/en-us/azure/container-registry/quickstart-connected-registry-arc-cli

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Expert knowledge for Azure Active Directory B2C development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building B2C user flows/custom policies, configuring IdPs/MFA, securing APIs, automating CI/CD, or monitoring with Sentinel, and other Azure Active Directory B2C related development tasks. Not for Azure Role-based access control (use azure-rbac), Azure Information Protection (use azure-information-protection), Azure Security (use azure-security), Azure Sentinel (use azure-sentinel).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure Advisor development including best practices, decision making, limits & quotas, security, configuration, and integrations & coding patterns. Use when configuring Advisor alerts/digests, managing rec states, using workbooks, Resource Graph, or RBAC for access, and other Azure Advisor related development tasks. Not for Cost Management (use azure-cost-management), Azure Monitor (use azure-monitor), Azure Policy (use azure-policy), Azure Security (use azure-security).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure AI Vision development including decision making, limits & quotas, configuration, integrations & coding patterns, and deployment. Use when using Image Analysis, Read OCR containers, smart-crop thumbnails, background removal, or video frame analysis, and other Azure AI Vision related development tasks. Not for Azure AI Custom Vision (use azure-custom-vision), Azure AI Video Indexer (use azure-video-indexer), Azure AI Document Intelligence (use azure-document-intelligence), Azure AI Immersive Reader (use azure-immersive-reader).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure Kubernetes Service Edge Essentials development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when managing AKS Edge/Hybrid with Arc, GitOps, IoT/OPC/ONVIF, TPM/Key Vault secrets, or AI model workloads, and other Azure Kubernetes Service Edge Essentials related development tasks. Not for Azure Kubernetes Service (AKS) (use azure-kubernetes-service), Azure IoT Edge (use azure-iot-edge), Azure Stack Edge (use azure-stack-edge), Azure Container Apps (use azure-container-apps).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure Analysis Services development including troubleshooting. Use when resolving server connectivity, firewall/VNet, DNS, client connection, or network error issues, and other Azure Analysis Services related development tasks. Not for Azure Synapse Analytics (use azure-synapse-analytics), Azure SQL Database (use azure-sql-database), Azure SQL Managed Instance (use azure-sql-managed-instance), SQL Server on Azure Virtual Machines (use azure-sql-virtual-machines).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment. Use when tuning Docker-based Anomaly Detector, ACI or IoT Edge deployments, univariate/multivariate APIs, or service limits, and other Azure AI Anomaly Detector related development tasks. Not for Azure AI Metrics Advisor (use azure-metrics-advisor), Azure Monitor (use azure-monitor), Azure Machine Learning (use azure-machine-learning).

日本語の概要は準備中です。原文の説明を表示しています。

MicrosoftDocs/Agent-Skills7772026年10月11日 更新

MicrosoftDocs のスキルをすべて見る

このスキルの問題を報告する