registries
Creates, updates, deletes, gets or lists a registries resource.
Overview
| Name | registries |
| Type | Resource |
| Id | azure.container_registry.registries |
Fields
The following fields are returned by SELECT queries:
- get_private_link_resource
- get
- check_name_availability
- list_by_resource_group
- list
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the private link resource. |
groupId | string | The private link resource group id. |
requiredMembers | array | The private link resource required member names. |
requiredZoneNames | array | The private link resource private link DNS zone name. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the private link resource. |
adminUserEnabled | boolean | The value that indicates whether the admin user is enabled. |
anonymousPullEnabled | boolean | Enables registry-wide pull from unauthenticated clients. |
autoGeneratedDomainNameLabelScope | string | Determines the domain name label reuse scope. Known values are: "Unsecure", "TenantReuse", "SubscriptionReuse", "ResourceGroupReuse", and "NoReuse". (Unsecure, TenantReuse, SubscriptionReuse, ResourceGroupReuse, NoReuse) |
creationDate | string (date-time) | The creation date of the container registry in ISO8601 format. |
dataEndpointEnabled | boolean | Enable a single data endpoint per region for serving data. |
dataEndpointHostNames | array | List of host names that will serve data when dataEndpointEnabled is true. |
encryption | object | The encryption settings of container registry. |
endpointProtocol | string | The connectivity protocol for the registry, such as IPv4 or dual stack (IPv4 and IPv6). Known values are: "IPv4" and "IPv4AndIPv6". (IPv4, IPv4AndIPv6) |
identity | object | The identity of the container registry. |
location | string | The geo-location where the resource lives. Required. |
loginServer | string | The URL that can be used to log into the container registry. |
metadataSearch | string | Determines whether registry artifacts are indexed for metadata search. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
networkRuleBypassAllowedForTasks | boolean | Whether or not Tasks allowed to bypass the network rules for this container registry. |
networkRuleBypassOptions | string | Whether to allow trusted Azure services to access a network restricted registry. Known values are: "AzureServices" and "None". (AzureServices, None) |
networkRuleSet | object | The network rule set for a container registry. |
policies | object | The policies for a container registry. |
privateEndpointConnections | array | List of private endpoint connections for a container registry. |
provisioningState | string | The provisioning state of the container registry at the time the operation was called. Known values are: "Creating", "Updating", "Deleting", "Succeeded", "Failed", and "Canceled". (Creating, Updating, Deleting, Succeeded, Failed, Canceled) |
publicNetworkAccess | string | Whether or not public network access is allowed for the container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regionalEndpointHostNames | array | List of host names that will serve registry when RegionalEndpoints is enabled. |
regionalEndpoints | string | Enable per-region endpoints for accessing registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
roleAssignmentMode | string | Determines registry role assignment mode. Known values are: "AbacRepositoryPermissions" and "LegacyRegistryPermissions". (AbacRepositoryPermissions, LegacyRegistryPermissions) |
sku | object | The SKU of the container registry. Required. |
status | object | The status of the container registry at the time the operation was called. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
zoneRedundancy | string | Whether or not zone redundancy is enabled for this container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
| Name | Datatype | Description |
|---|---|---|
availableLoginServerName | string | The complete login server name with domain name label (DNL) hash, if available. |
message | string | If any, the error message that provides more detail for the reason that the name is not available. |
nameAvailable | boolean | The value that indicates whether the name is available. |
reason | string | If any, the reason that the name is not available. |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the private link resource. |
adminUserEnabled | boolean | The value that indicates whether the admin user is enabled. |
anonymousPullEnabled | boolean | Enables registry-wide pull from unauthenticated clients. |
autoGeneratedDomainNameLabelScope | string | Determines the domain name label reuse scope. Known values are: "Unsecure", "TenantReuse", "SubscriptionReuse", "ResourceGroupReuse", and "NoReuse". (Unsecure, TenantReuse, SubscriptionReuse, ResourceGroupReuse, NoReuse) |
creationDate | string (date-time) | The creation date of the container registry in ISO8601 format. |
dataEndpointEnabled | boolean | Enable a single data endpoint per region for serving data. |
dataEndpointHostNames | array | List of host names that will serve data when dataEndpointEnabled is true. |
encryption | object | The encryption settings of container registry. |
endpointProtocol | string | The connectivity protocol for the registry, such as IPv4 or dual stack (IPv4 and IPv6). Known values are: "IPv4" and "IPv4AndIPv6". (IPv4, IPv4AndIPv6) |
identity | object | The identity of the container registry. |
location | string | The geo-location where the resource lives. Required. |
loginServer | string | The URL that can be used to log into the container registry. |
metadataSearch | string | Determines whether registry artifacts are indexed for metadata search. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
networkRuleBypassAllowedForTasks | boolean | Whether or not Tasks allowed to bypass the network rules for this container registry. |
networkRuleBypassOptions | string | Whether to allow trusted Azure services to access a network restricted registry. Known values are: "AzureServices" and "None". (AzureServices, None) |
networkRuleSet | object | The network rule set for a container registry. |
policies | object | The policies for a container registry. |
privateEndpointConnections | array | List of private endpoint connections for a container registry. |
provisioningState | string | The provisioning state of the container registry at the time the operation was called. Known values are: "Creating", "Updating", "Deleting", "Succeeded", "Failed", and "Canceled". (Creating, Updating, Deleting, Succeeded, Failed, Canceled) |
publicNetworkAccess | string | Whether or not public network access is allowed for the container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regionalEndpointHostNames | array | List of host names that will serve registry when RegionalEndpoints is enabled. |
regionalEndpoints | string | Enable per-region endpoints for accessing registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
roleAssignmentMode | string | Determines registry role assignment mode. Known values are: "AbacRepositoryPermissions" and "LegacyRegistryPermissions". (AbacRepositoryPermissions, LegacyRegistryPermissions) |
sku | object | The SKU of the container registry. Required. |
status | object | The status of the container registry at the time the operation was called. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
zoneRedundancy | string | Whether or not zone redundancy is enabled for this container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the private link resource. |
adminUserEnabled | boolean | The value that indicates whether the admin user is enabled. |
anonymousPullEnabled | boolean | Enables registry-wide pull from unauthenticated clients. |
autoGeneratedDomainNameLabelScope | string | Determines the domain name label reuse scope. Known values are: "Unsecure", "TenantReuse", "SubscriptionReuse", "ResourceGroupReuse", and "NoReuse". (Unsecure, TenantReuse, SubscriptionReuse, ResourceGroupReuse, NoReuse) |
creationDate | string (date-time) | The creation date of the container registry in ISO8601 format. |
dataEndpointEnabled | boolean | Enable a single data endpoint per region for serving data. |
dataEndpointHostNames | array | List of host names that will serve data when dataEndpointEnabled is true. |
encryption | object | The encryption settings of container registry. |
endpointProtocol | string | The connectivity protocol for the registry, such as IPv4 or dual stack (IPv4 and IPv6). Known values are: "IPv4" and "IPv4AndIPv6". (IPv4, IPv4AndIPv6) |
identity | object | The identity of the container registry. |
location | string | The geo-location where the resource lives. Required. |
loginServer | string | The URL that can be used to log into the container registry. |
metadataSearch | string | Determines whether registry artifacts are indexed for metadata search. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
networkRuleBypassAllowedForTasks | boolean | Whether or not Tasks allowed to bypass the network rules for this container registry. |
networkRuleBypassOptions | string | Whether to allow trusted Azure services to access a network restricted registry. Known values are: "AzureServices" and "None". (AzureServices, None) |
networkRuleSet | object | The network rule set for a container registry. |
policies | object | The policies for a container registry. |
privateEndpointConnections | array | List of private endpoint connections for a container registry. |
provisioningState | string | The provisioning state of the container registry at the time the operation was called. Known values are: "Creating", "Updating", "Deleting", "Succeeded", "Failed", and "Canceled". (Creating, Updating, Deleting, Succeeded, Failed, Canceled) |
publicNetworkAccess | string | Whether or not public network access is allowed for the container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
regionalEndpointHostNames | array | List of host names that will serve registry when RegionalEndpoints is enabled. |
regionalEndpoints | string | Enable per-region endpoints for accessing registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
roleAssignmentMode | string | Determines registry role assignment mode. Known values are: "AbacRepositoryPermissions" and "LegacyRegistryPermissions". (AbacRepositoryPermissions, LegacyRegistryPermissions) |
sku | object | The SKU of the container registry. Required. |
status | object | The status of the container registry at the time the operation was called. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
tags | object | Resource tags. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
zoneRedundancy | string | Whether or not zone redundancy is enabled for this container registry. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_private_link_resource | select | resource_group_name, registry_name, group_name, subscription_id | Gets a private link resource by a specified group name for a container registry. | |
get | select | resource_group_name, registry_name, subscription_id | Gets the properties of the specified container registry. | |
check_name_availability | select | subscription_id | Checks whether the container registry name is available for use. The name must contain only alphanumeric characters, be globally unique, and between 5 and 50 characters in length. | |
list_by_resource_group | select | resource_group_name, subscription_id | Lists all the container registries under the specified resource group. | |
list | select | subscription_id | Lists all the container registries under the specified subscription. | |
create | insert | resource_group_name, registry_name, subscription_id, location, sku | Creates a container registry with the specified parameters. | |
update | update | resource_group_name, registry_name, subscription_id | Updates a container registry with the specified parameters. | |
delete | delete | resource_group_name, registry_name, subscription_id | Deletes a container registry. | |
list_usages | exec | resource_group_name, registry_name, subscription_id | Gets the quota usages for the specified container registry. | |
list_credentials | exec | resource_group_name, registry_name, subscription_id | Lists the login credentials for the specified container registry. | |
list_private_link_resources | exec | resource_group_name, registry_name, subscription_id | Lists the private link resources for a container registry. | |
import_image | exec | resource_group_name, registry_name, subscription_id, source | Copies an image to this container registry from the specified container registry. | |
regenerate_credential | exec | resource_group_name, registry_name, subscription_id, name | Regenerates one of the login credentials for the specified container registry. | |
generate_credentials | exec | resource_group_name, registry_name, subscription_id | Generate keys for a token of a specified container registry. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
group_name | string | The name of the private link associated with the Azure resource. Required. |
registry_name | string | The name of the container registry. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
subscription_id | string |
SELECT examples
- get_private_link_resource
- get
- check_name_availability
- list_by_resource_group
- list
Gets a private link resource by a specified group name for a container registry.
SELECT
id,
name,
groupId,
requiredMembers,
requiredZoneNames,
systemData,
type
FROM azure.container_registry.registries
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND registry_name = '{{ registry_name }}' -- required
AND group_name = '{{ group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets the properties of the specified container registry.
SELECT
id,
name,
adminUserEnabled,
anonymousPullEnabled,
autoGeneratedDomainNameLabelScope,
creationDate,
dataEndpointEnabled,
dataEndpointHostNames,
encryption,
endpointProtocol,
identity,
location,
loginServer,
metadataSearch,
networkRuleBypassAllowedForTasks,
networkRuleBypassOptions,
networkRuleSet,
policies,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regionalEndpointHostNames,
regionalEndpoints,
roleAssignmentMode,
sku,
status,
systemData,
tags,
type,
zoneRedundancy
FROM azure.container_registry.registries
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND registry_name = '{{ registry_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Checks whether the container registry name is available for use. The name must contain only alphanumeric characters, be globally unique, and between 5 and 50 characters in length.
SELECT
availableLoginServerName,
message,
nameAvailable,
reason
FROM azure.container_registry.registries
WHERE subscription_id = '{{ subscription_id }}' -- required
;
Lists all the container registries under the specified resource group.
SELECT
id,
name,
adminUserEnabled,
anonymousPullEnabled,
autoGeneratedDomainNameLabelScope,
creationDate,
dataEndpointEnabled,
dataEndpointHostNames,
encryption,
endpointProtocol,
identity,
location,
loginServer,
metadataSearch,
networkRuleBypassAllowedForTasks,
networkRuleBypassOptions,
networkRuleSet,
policies,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regionalEndpointHostNames,
regionalEndpoints,
roleAssignmentMode,
sku,
status,
systemData,
tags,
type,
zoneRedundancy
FROM azure.container_registry.registries
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Lists all the container registries under the specified subscription.
SELECT
id,
name,
adminUserEnabled,
anonymousPullEnabled,
autoGeneratedDomainNameLabelScope,
creationDate,
dataEndpointEnabled,
dataEndpointHostNames,
encryption,
endpointProtocol,
identity,
location,
loginServer,
metadataSearch,
networkRuleBypassAllowedForTasks,
networkRuleBypassOptions,
networkRuleSet,
policies,
privateEndpointConnections,
provisioningState,
publicNetworkAccess,
regionalEndpointHostNames,
regionalEndpoints,
roleAssignmentMode,
sku,
status,
systemData,
tags,
type,
zoneRedundancy
FROM azure.container_registry.registries
WHERE subscription_id = '{{ subscription_id }}' -- required
;
INSERT examples
- create
- Manifest
Creates a container registry with the specified parameters.
INSERT INTO azure.container_registry.registries (
tags,
location,
properties,
sku,
identity,
resource_group_name,
registry_name,
subscription_id
)
SELECT
'{{ tags }}',
'{{ location }}' /* required */,
'{{ properties }}',
'{{ sku }}' /* required */,
'{{ identity }}',
'{{ resource_group_name }}',
'{{ registry_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
identity,
location,
properties,
sku,
systemData,
tags,
type
;
# Description fields are for documentation purposes
- name: registries
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the registries resource.
- name: registry_name
value: "{{ registry_name }}"
description: Required parameter for the registries resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the registries resource.
- name: tags
value: "{{ tags }}"
description: |
Resource tags.
- name: location
value: "{{ location }}"
description: |
The geo-location where the resource lives. Required.
- name: properties
description: |
The properties of the container registry.
value:
loginServer: "{{ loginServer }}"
creationDate: "{{ creationDate }}"
provisioningState: "{{ provisioningState }}"
status:
displayStatus: "{{ displayStatus }}"
message: "{{ message }}"
timestamp: "{{ timestamp }}"
adminUserEnabled: {{ adminUserEnabled }}
networkRuleSet:
defaultAction: "{{ defaultAction }}"
ipRules:
- action: "{{ action }}"
value: "{{ value }}"
policies:
quarantinePolicy:
status: "{{ status }}"
trustPolicy:
type: "{{ type }}"
status: "{{ status }}"
retentionPolicy:
days: {{ days }}
lastUpdatedTime: "{{ lastUpdatedTime }}"
status: "{{ status }}"
exportPolicy:
status: "{{ status }}"
azureADAuthenticationAsArmPolicy:
status: "{{ status }}"
softDeletePolicy:
retentionDays: {{ retentionDays }}
lastUpdatedTime: "{{ lastUpdatedTime }}"
status: "{{ status }}"
encryption:
status: "{{ status }}"
keyVaultProperties:
keyIdentifier: "{{ keyIdentifier }}"
versionedKeyIdentifier: "{{ versionedKeyIdentifier }}"
identity: "{{ identity }}"
keyRotationEnabled: {{ keyRotationEnabled }}
lastKeyRotationTimestamp: "{{ lastKeyRotationTimestamp }}"
dataEndpointEnabled: {{ dataEndpointEnabled }}
dataEndpointHostNames:
- "{{ dataEndpointHostNames }}"
regionalEndpoints: "{{ regionalEndpoints }}"
regionalEndpointHostNames:
- "{{ regionalEndpointHostNames }}"
endpointProtocol: "{{ endpointProtocol }}"
privateEndpointConnections:
- id: "{{ id }}"
name: "{{ name }}"
type: "{{ type }}"
systemData:
createdBy: "{{ createdBy }}"
createdByType: "{{ createdByType }}"
createdAt: "{{ createdAt }}"
lastModifiedBy: "{{ lastModifiedBy }}"
lastModifiedByType: "{{ lastModifiedByType }}"
lastModifiedAt: "{{ lastModifiedAt }}"
properties:
privateEndpoint:
id: "{{ id }}"
privateLinkServiceConnectionState:
status: "{{ status }}"
description: "{{ description }}"
actionsRequired: "{{ actionsRequired }}"
provisioningState: "{{ provisioningState }}"
publicNetworkAccess: "{{ publicNetworkAccess }}"
networkRuleBypassOptions: "{{ networkRuleBypassOptions }}"
networkRuleBypassAllowedForTasks: {{ networkRuleBypassAllowedForTasks }}
zoneRedundancy: "{{ zoneRedundancy }}"
anonymousPullEnabled: {{ anonymousPullEnabled }}
metadataSearch: "{{ metadataSearch }}"
autoGeneratedDomainNameLabelScope: "{{ autoGeneratedDomainNameLabelScope }}"
roleAssignmentMode: "{{ roleAssignmentMode }}"
- name: sku
description: |
The SKU of the container registry. Required.
value:
name: "{{ name }}"
tier: "{{ tier }}"
- name: identity
description: |
The identity of the container registry.
value:
principalId: "{{ principalId }}"
tenantId: "{{ tenantId }}"
type: "{{ type }}"
userAssignedIdentities: "{{ userAssignedIdentities }}"
UPDATE examples
- update
Updates a container registry with the specified parameters.
UPDATE azure.container_registry.registries
SET
identity = '{{ identity }}',
tags = '{{ tags }}',
sku = '{{ sku }}',
properties = '{{ properties }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND registry_name = '{{ registry_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
identity,
location,
properties,
sku,
systemData,
tags,
type;
DELETE examples
- delete
Deletes a container registry.
DELETE FROM azure.container_registry.registries
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND registry_name = '{{ registry_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Lifecycle Methods
- list_usages
- list_credentials
- list_private_link_resources
- import_image
- regenerate_credential
- generate_credentials
Gets the quota usages for the specified container registry.
EXEC azure.container_registry.registries.list_usages
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Lists the login credentials for the specified container registry.
EXEC azure.container_registry.registries.list_credentials
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Lists the private link resources for a container registry.
EXEC azure.container_registry.registries.list_private_link_resources
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Copies an image to this container registry from the specified container registry.
EXEC azure.container_registry.registries.import_image
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"source": "{{ source }}",
"targetTags": "{{ targetTags }}",
"untaggedTargetRepositories": "{{ untaggedTargetRepositories }}",
"mode": "{{ mode }}"
}'
;
Regenerates one of the login credentials for the specified container registry.
EXEC azure.container_registry.registries.regenerate_credential
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"name": "{{ name }}"
}'
;
Generate keys for a token of a specified container registry.
EXEC azure.container_registry.registries.generate_credentials
@resource_group_name='{{ resource_group_name }}' --required,
@registry_name='{{ registry_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"tokenId": "{{ tokenId }}",
"expiry": "{{ expiry }}",
"name": "{{ name }}"
}'
;