Onboarding Azure Container Registry

To configure container registry scanning of an AzureClosed Collection of integrated cloud services that developers and IT professionals use to build, deploy, and manage applications through a global network of data centers managed by Microsoft®. Container RegistryClosed A collection of repositories used to store and access container images. (ACR), you need to onboard the registry to CloudGuard.

Prerequisites

Before onboarding your ContainerClosed A lightweight and portable executable image that contains software and all of its dependencies. Containers decouple applications from underlying host infrastructure to make deployment easier in different cloud or OS environments, and for easier scaling. Registry for scanning with a KubernetesClosed Kubernetes, often abbreviated as “K8s”, orchestrates containerized applications to run on a cluster of hosts. scanner, select an authentication method:

  • Service Principal - A user identity for applications, hosted services, and automated tools to access Azure resources. This option lets CloudGuard scan Azure Container Registries from linked clusters not necessarily in Azure.

  • Managed Identity - An identity for applications to access resources that support Microsoft Entra ID authentication. This option allows CloudGuard to scan Azure Container Registries from Azure clusters in the same tenant.

Note - Only Azure Service Principal authentication is available for onboarding with an ECSClosed Amazon Elastic Container Service (ECS) - a fully managed container orchestration service that helps you deploy, manage, and scale Docker containers running applications, services, and batch processes. scanner.

Onboarding

To onboard a Container Registry to CloudGuard:

CloudGuard opens the onboarded registry. For onboarding validation, see the Scanners tab that shows the status of the registry and its scanning environment (cluster or AWS ECS).

For registries with the Kubernetes scanner, the related Kubernetes cluster page shows information about the registries that the cluster scans, in the list on Blades > Image Assurance > Image Scan Engine agent.

More Links