是否有VSTS构建任务可移除容器注册表中未使用的Docker镜像标签?
Got it, this is such a common pain point when pairing Azure DevOps (formerly VSTS) with Azure Container Registry—those unused build tags can eat up storage way faster than you’d expect! Since you mentioned these tags are safe to delete (and can be regenerated anytime), here are three solid ways to clean them up:
1. Manual Cleanup with Azure CLI
Great for one-time sweeps or ad-hoc deletions.
First, list all tags for your repository sorted by creation date (newest first) to see what you’re working with:
az acr repository show-tags --name your-acr-name --repository your-repo-name --orderby time_desc
To delete a single unused tag:
az acr repository delete --name your-acr-name --image your-repo-name:unused-tag --yes
For bulk deletion (e.g., delete all tags older than 30 days), combine the CLI with jq to filter and automate:
# Fetch tags created more than 30 days ago OLD_TAGS=$(az acr repository show-tags --name your-acr-name --repository your-repo-name --orderby time_desc --query "[?createdTime < '$(date -d '30 days ago' +%Y-%m-%dT%H:%M:%SZ)']" -o tsv) # Loop through and delete each tag for TAG in $OLD_TAGS; do az acr repository delete --name your-acr-name --image your-repo-name:$TAG --yes done
2. Automatic Retention Policies (Recommended)
Skip manual work entirely by setting up built-in ACR retention rules. You can auto-delete tagged images after a set number of days, or keep only the latest N tags.
Set via CLI:
# Keep only the latest 10 tagged images, delete the rest az acr config retention update --name your-acr-name --repository your-repo-name --count 10 --type tagged # Or delete tagged images older than 14 days az acr config retention update --name your-acr-name --repository your-repo-name --days 14 --type tagged
Set via Azure Portal:
- Navigate to your ACR resource → Repositories → Select your repo → Retention policy
- Choose the rule type (tagged/untagged), set your retention period or count, and save.
3. Integrate Cleanup into Your Azure DevOps Pipeline
Prevent tag bloat from the start by adding a cleanup step directly to your build pipeline. This way, old unused tags get removed automatically after each build.
Add an Azure CLI task to your pipeline with a script like this (adjust the TAGS_TO_KEEP value to fit your needs):
TAGS_TO_KEEP=5 # Get all tags sorted from newest to oldest ALL_TAGS=$(az acr repository show-tags --name your-acr-name --repository your-repo-name --orderby time_desc -o tsv) # Skip the latest N tags, delete the rest TAGS_TO_DELETE=$(echo "$ALL_TAGS" | tail -n +$((TAGS_TO_KEEP + 1))) for TAG in $TAGS_TO_DELETE; do az acr repository delete --name your-acr-name --image your-repo-name:$TAG --yes done
Key Notes
- Permissions: Ensure the service principal used by your pipeline or CLI has the
AcrDeleterole (or broaderContributorrole) assigned to your ACR. - Garbage Collection: Deleting tags marks the underlying manifest for deletion, but storage isn’t freed until garbage collection runs. Trigger it manually with:
az acr repository garbage-collect --name your-acr-name --yes - Test First: Before bulk deleting, run the tag list command alone to confirm you’re not targeting any critical tags.
内容的提问来源于stack exchange,提问作者Kevin Ghadyani

