Hub spoket private network setup - azure container app can not pull image from azure container registry

Turic, Mario 0 Zuverlässigkeitspunkte
2026-02-27T14:33:26.56+00:00

Hello dear IT support,

we have an azure container app inside of our azure container environment, that can not pull an image from our azure container registry also in our same resource group and same private virtual network.

We have an hub-spoke architecture and azure firewall set up.

We checked that the image exists in the Azure container registry.

We checked that the necessary private DNS zones, private virtual links and etc. are existing and configured correctly.

When doing the "nslookup" for the 2 private endpoints of the Azure container registry we get:

  1. C:>nslookup [REGISTRY_NAME_REDACTED].azurecr.io Server: UnKnown Address: [REDACTED_IP] Non-authoritative answer: Name: acrandersendev001-dsb0e3gmh9g4atfa.privatelink.azurecr.io Address: [REDACTED_IP] Aliases: acrandersendev001-dsb0e3gmh9g4atfa.azurecr.io
  2. C:>nslookup acrandersendev001-dsb0e3gmh9g4atfa.germanywestcentral.data.azurecr.io Server: UnKnown Address: [REDACTED_IP] Non-authoritative answer: Name: d0125dewc-1-az.germanywestcentral.cloudapp.azure.com Address: [REDACTED_IP] Aliases: acrandersendev001-dsb0e3gmh9g4atfa.germanywestcentral.data.azurecr.io
             acrandersendev001-dsb0e3gmh9g4atfa.germanywestcentral.data.privatelink.azurecr.io
          
             dewc-1-az.data.azcr.io
          
             dewc-1-acr-az-dp.trafficmanager.net
    

When trying to create a Azure container app (container app 'test-andersen-dev01') with the Azure container registry, we are receiving this issue right now:

Failed to provision revision for container app 'test-andersen-dev01'. Error details: The following field(s) are either invalid or missing. Field 'template.containers.test-andersen-dev01.image' is invalid with details: 'Invalid value: "acrandersendev001-dsb0e3gmh9g4atfa.azurecr.io/streamlit-app:latest": Get "https://acrandersendev001-dsb0e3gmh9g4atfa.germanywestcentral.data.azurecr.io?c=REDACTED&d=REDACTED&h=REDACTED&l=REDACTED&p=REDACTED&r=REDACTED&s=REDACTED&t=REDACTED&v=REDACTED": EOF';.. (Code: ContainerAppOperationError)

Can you please support us in understand what else we should check or if this is wrong technical issue/behaviour of any of the Azure services involved ?

Thank you and kind regards,

Mario Turic

Azure Container Apps
Azure Container Apps

Ein Azure-Dienst, der eine universelle, serverlose Containerplattform bereitstellt.

0 Kommentare Keine Kommentare

1 Antwort

Sortieren nach: Am hilfreichsten
  1. Pravallika KV 18,855 Zuverlässigkeitspunkte Externe Microsoft-Mitarbeiter Moderator
    2026-02-27T15:44:37.4566667+00:00

    Hey @Turic, Mario,

    Please double-check below steps:

    1. Make sure you've created both ACR private endpoints:
      • Registry (login) endpoint for <yourRegistry>.azurecr.io
      • Data (content) endpoint for <yourRegistry>.data.azurecr.io
    2. Verify your Private DNS zones and VNet links:
      • You need one zone for privatelink.azurecr.io and another for privatelink.data.azurecr.io.
      • Each zone must have an A record for your registry and must be linked to the same VNet that your Container Apps environment uses.
    3. Firewall / network rules:
      • If you’re using Azure Firewall, ensure you allow outbound HTTPS (443) to the private IPs of both endpoints.
      • You can simplify this by allowing the AzureContainerRegistry and AzureStorage service tags in your network rules.
    4. Container Apps environment settings:
      • In the Container Apps environment, confirm “Pull image over VNet” aka vnetImagePullEnabled is enabled so that the runtime uses your private network rather than the public internet.
    5. Test connectivity from your CA environment subnet:
      • Use Azure Network Watcher’s Connection troubleshoot against the private IP of your data endpoint on port 443.
      • Do a nslookup <registry>.data.azurecr.io from a VM in the same subnet, you should get the private‐link IP, not a public one.

    Hope this helps!


    If the resolution was helpful, kindly take a moment to click on User's imageand click on Yes for was this answer helpful. And, if you have any further query do let us know.

    War diese Antwort hilfreich?

    0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.