Azure Container Registry (ACR) is Azure's private registry for container images and other OCI (Open Container Initiative) artifacts such as Helm charts. Your build pipeline pushes images to it, and App Service, Container Apps and AKS pull from it. Keeping images in a registry in the same region as your compute makes pulls fast and keeps traffic on Microsoft's network.
A registry has a login server name of the form myregistry.azurecr.io, and image references look like myregistry.azurecr.io/orders-api:1.4.2. The part after the server is the repository, and the part after the colon is the tag. You create one with az acr create --resource-group rg --name myregistry --sku Basic and sign your local Docker client in with az acr login --name myregistry, which uses your Microsoft Entra ID sign-in rather than a stored password.
ACR has three service tiers, and all three support the same core features: pushing and pulling images, Microsoft Entra authentication, ACR Tasks, webhooks and repository-scoped permissions. The tiers differ mainly in included storage, throughput (how many concurrent pulls and pushes perform well) and a set of advanced features. Basic is the cost-optimized entry point for learning and small workloads. Standard adds more storage and throughput and suits most production workloads. Premium has the highest storage and throughput and is the only tier with the enterprise features below.
Geo-replication (Premium only) turns one registry into a multi-region registry. You add replicas with az acr replication create --registry myregistry --location westeurope. You still push once to the same login server name; ACR copies the content to each replica, and clients are routed to the closest one. Benefits: faster, cheaper pulls for compute in several regions (no cross-region egress), and continued pulls if one region has a problem. The alternative on lower tiers, separate registries per region, means pushing several times and managing several names.
Private endpoints (Azure Private Link) are also Premium only. A private endpoint gives the registry a private IP address inside your virtual network, and with a private DNS zone the login server name resolves to that IP from inside the network. You can then disable public network access so the registry cannot be reached from the internet at all. Premium also adds features such as firewall rules for selected networks, customer-managed encryption keys and higher throughput for large clusters.
Changing tiers is simple: az acr update --name myregistry --sku Premium upgrades in place without changing the login server or losing images. That means you can start on Basic in development and move up when you need a Premium-only feature.
Key terms
- Login server
- The registry's DNS name, such as myregistry.azurecr.io, used as the prefix of every image reference.
- Geo-replication
- A Premium ACR feature that keeps copies of one registry in several regions behind a single login server.
- Private endpoint
- A network interface with a private IP in your VNet that connects privately to a service such as a Premium registry.
- Repository
- A named collection of related images in a registry, distinguished by tags and digests.
A retailer runs its API on Container Apps in East US and West Europe. With a Standard registry in East US, the European replicas pulled across the Atlantic on every scale-out. They upgraded the registry to Premium, added a West Europe replica and a private endpoint in each VNet, then turned off public network access. Pushes still go to one login server, and each region now pulls locally over a private IP.
Check yourself
A company needs one registry that serves images to clusters in three regions with local pulls. Which tier and feature?
Premium with geo-replication, because only Premium can replicate one registry to multiple regions behind a single login server.
Can you upgrade a Basic registry to Premium without re-pushing images?
Yes. az acr update --sku Premium changes the tier in place and keeps the login server and all content.