mattcowen / forefront-lz

A landing zone for secure deployments
Apache License 2.0
5 stars 1 forks source link

A central Azure Container Registry #36

Open mattcowen opened 2 years ago

mattcowen commented 2 years ago

A premium ACR should exist in the hub vnet and accessed via a private endpoint. This should make use of the private dns zone created in the connectivity subscription. Ensure there is a vnet link to the zone. It should have quarantined containers configured. Admin access should be disabled in favour of RBAC access.