Azure Container Registry holds the images that AKS, App Service, and Container Instances pull and run, which makes it both a credential store and a supply-chain foothold. The admin account and repository rights give read and write to images; ACR Tasks run build steps in-registry as a managed identity.
Pages#
- Registry access: admin credentials and repository pull and push.
- Tasks: ACR Tasks running as a managed identity, and image poisoning.