Ein Azure-Dienst, der eine universelle, serverlose Containerplattform bereitstellt.
Hey @Turic, Mario,
Please double-check below steps:
- Make sure you've created both ACR private endpoints:
- Registry (login) endpoint for
<yourRegistry>.azurecr.io - Data (content) endpoint for
<yourRegistry>.data.azurecr.io
- Registry (login) endpoint for
- Verify your Private DNS zones and VNet links:
- You need one zone for
privatelink.azurecr.ioand another forprivatelink.data.azurecr.io. - Each zone must have an A record for your registry and must be linked to the same VNet that your Container Apps environment uses.
- You need one zone for
- Firewall / network rules:
- If you’re using Azure Firewall, ensure you allow outbound HTTPS (443) to the private IPs of both endpoints.
- You can simplify this by allowing the AzureContainerRegistry and AzureStorage service tags in your network rules.
- Container Apps environment settings:
- In the Container Apps environment, confirm “Pull image over VNet” aka
vnetImagePullEnabledis enabled so that the runtime uses your private network rather than the public internet.
- In the Container Apps environment, confirm “Pull image over VNet” aka
- Test connectivity from your CA environment subnet:
- Use Azure Network Watcher’s Connection troubleshoot against the private IP of your data endpoint on port 443.
- Do a
nslookup <registry>.data.azurecr.iofrom a VM in the same subnet, you should get the private‐link IP, not a public one.
Hope this helps!
If the resolution was helpful, kindly take a moment to click on and click on Yes for was this answer helpful. And, if you have any further query do let us know.