Skip to content

Azure ACR enables anonymous image pulling

Description

Disabling anonymous image pulling for your Azure Container Registry (ACR) can help improve the security of your registry. When anonymous image pulling is enabled, anyone can pull images from your registry without needing to authenticate or have authorization.

Code Example

go
resource "azurerm_container_registry" "ckv_unittest_pass_1" {
  name                   = "containerRegistry1"
  resource_group_name    = azurerm_resource_group.rg.name
  location               = azurerm_resource_group.rg.location
  sku                    = "Premium"
  anonymous_pull_enabled = false
}

Remediation

Terraform

  • Resource: azurerm_container_registry
  • Arguments: anonymous_pull_enabled

Rule Details

FieldValue
IDIAC-0645
SeverityLOW
IaC Typearm
FrameworksTerraform
Checkov IDCKV_AZURE_138

References