Posts

Showing posts with the label ACR
GitHub Copilot Customization Explained for Beginners: Instructions, Prompt Files, Skills, Agents, and Hooks  Introduction If you've recently started using GitHub Copilot, you've probably come across terms like Instructions , Prompt Files , Skills , Agents , and Hooks . At first glance, they all seem to do the same thing—they tell Copilot what to do. So why does GitHub have five different customization features? The answer is simple: each feature solves a different problem. Think of GitHub Copilot as a new developer joining your team. On their first day, you don't just hand them code. You explain your coding standards, give them reusable templates, teach them specialized knowledge, assign them a role, and automate repetitive tasks. That's exactly how GitHub Copilot customization works. In this article, you'll learn what each feature does, when to use it, and how they all work together. By the end, you'll know which feature to start with and which ones can wait un...

Cleaning Azure Container Registry (ACR) on demand or schedule

Image
In this blog post, we will see how to purge container images from Azure Container Registry (ACR). Till recent time most of them would have written custom PowerShell or bash script and run it to clean (purge) ACR container images. Recently Microsoft introduced a new preview feature to automatically purge images based on filters, duration, and untagged manifests. Additionally, this new preview feature supports to run on-demand or on a schedule using CRON expression. In my current project, our delivery team is committing code several times a day. This automatically triggers a CI pipeline from which images are automatically built and pushed into ACR. Most of them would be going through the same journey. In this situation using this new preview feature, helps to keep ACR clean and not worrying about the Container registry getting bloated with images.  Both on-demand or schedule will make use of acr purge command. ACR purge is designed to run as a container command in ...

Azure Function in a Docker Container - Part 2

Image
In my previous blog post , we looked at how to run Azure Function in a Docker Container locally using Docker desktop. In this blog post, we will see how to run the Azure Function container in Azure. Steps to run Azure Function in Container Create an Azure Function by choosing the right resource plan, resource group, a region with a storage account, and Application Insights for monitoring support. As part of the provisioning key things to support containerization, you need to choose the " Publish " option with " Docker Container " as shown below. Choose the hosting options based on your requirements like App-service plan or Premium. Once the Azure Function is provisioned navigate to the overview tab then you will be seeing a warning to configure container settings as shown below. Clicking on "Configure container settings" provides options to choose container image from Image source like  Azure Container Registry Docker hub Private Registry For our demo, I h...

Azure Container Registry Image Scanning With Azure Security Center

Image
Just to recap in the previous blog post we looked into how to secure Azure Container Registry and in this post will see the offering from Azure Security Center. Azure Container Registry (ACR) is a manged, private container registry service in Azure to build, store, and manage container images and artifacts. ACR service based on the open-source Docker Registry 2.0. This post explains, what you get from Azure Security Center in the context of ACR. Image scanning is important for any Docker registry. Vulnerability scanning for images stored in Azure Container Registry is now generally available in Azure Security Center (March 2020). This capability is powered by Qualys and seamlessly integrated into the Azure Security Center. ACR image scanning requires Azure Security Center Standard tier . When you push an image to Container Registry, Security Center automatically scans it, then checks for known vulnerabilities in packages or dependencies defined in the file. Each scan tak...

How to secure Azure Container Registry?

Azure Container Registry (ACR) is a managed, private Docker registry service that stores and manages your container images in Azure. Below are the few recommendations for using Azure Container Registry. Image scanning with Azure Security Center With Azure Security Center, you can get automatic scans of your registries for any threats and vulnerabilities of the images. Note if you're on Azure Security Center's standard tier, you can add the Container Registries bundle. This feature is charged per image scan. Whenever an new image is pushed to your registry, Security Center automatically scans that image. Azure Security Center also provide options or recommendations for resolving those vulnerabilities. Enable Content Trust Azure Container Registry implements Docker's content trust model, enabling pushing and pulling of signed images. Content trust helps to verify the source and integrity of the images, ensuring that they are the images we expect. As an im...

Customer-Managed Keys for Azure CosmosDB & Container Registry

Image
In May 2020, as part of Microsoft Build conference few key announcements were made for Microsoft Azure service. In this blog post, I will be covering updates related to Customer-managed keys which were made GA for Azure service - CosmosDB and Azure Container Registry. What is Customer-managed key? By default various resource provider in Azure implement encryption at Rest. Implementation of this encryption at Rest by default will be using Service-Managed keys which Microsoft manages internally. But in few scenarios users/customers want to control this keys that's where customer-managed key comes into picture. Two Azure service which we are talking in this post now have this capability (GA).  Note : You must store customer-managed keys in Azure Key Vault  Customer-managed key for CosmosDB Customer-managed keys enables users to take total control over the keys used by Azure Cosmos DB to encrypt their data at rest. With CosmosDB your data is always encrypted with service-managed-k...

Building a CI pipeline for Containerized Asp.NET Core 3.1 using ACR Registry

Image
This is continuation   of a series of posts on using Docker and containerization with .Net Core. If you are new to this series its recommend to look at  Getting started with Docker and Containers In this post will show how to setup a pipeline that continuously builds a repository that contains a Docker file. Every time you change your code and commit, the image is pushed to ACR Registry. Pre requisites 1.       Github account 2.       Azure DevOps Organisation if you don’t have one, you can create for  free 3.       Ensure you’re administrator of the Azure DevOps project 4.       Azure Container Registry – more details can be found  here 5.       Azure Project to be created in Azure DevOps 6.       Service Principal created in Azure – Creation process can be found  here Get the co...