You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Docker Registry拉取镜像部署Azure容器?求ARM模板示例

Is Your Proposed Solution Feasible?

Absolutely! This approach works perfectly for your scenario. Since Azure Container Registry (ACR) doesn’t support anonymous read access by default, hosting your images in a public Docker Registry (like Docker Hub) and pulling them during Azure container deployment is a valid and common workaround.

Public Docker Registry repositories allow anonymous pull access for public images, so as long as you push your built image to a public repo, Azure’s container services (ACI, AKS, App Service Containers, etc.) can pull it directly without needing extra authentication steps. If you ever need to use a private Docker Registry later, you can still configure authentication credentials in your Azure deployment template—we’ll touch on that too.

Step-by-Step Implementation with ARM Template

First, let’s cover the prerequisites to get your image ready:

  1. Build your Docker image locally (or via a CI/CD pipeline):
    docker build -t your-docker-username/your-public-image:v1 .
    
  2. Push the image to your public Docker Registry (make sure the repo is set to public in Docker Hub):
    docker push your-docker-username/your-public-image:v1
    

Example ARM Template for Azure Container Instances (ACI)

Here’s a complete ARM template that deploys an ACI instance pulling your public Docker image. This is a straightforward way to test the flow:

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "containerGroupName": {
      "type": "string",
      "defaultValue": "my-docker-registry-container-group",
      "metadata": {
        "description": "Name of the container group"
      }
    },
    "imageName": {
      "type": "string",
      "defaultValue": "your-docker-username/your-public-image:v1",
      "metadata": {
        "description": "Full name of your public Docker image (including tag)"
      }
    },
    "containerPort": {
      "type": "int",
      "defaultValue": 80,
      "metadata": {
        "description": "Port the container exposes"
      }
    }
  },
  "resources": [
    {
      "type": "Microsoft.ContainerInstance/containerGroups",
      "apiVersion": "2023-05-01",
      "name": "[parameters('containerGroupName')]",
      "location": "[resourceGroup().location]",
      "properties": {
        "containers": [
          {
            "name": "my-container",
            "properties": {
              "image": "[parameters('imageName')]",
              "ports": [
                {
                  "port": "[parameters('containerPort')]"
                }
              ],
              "resources": {
                "requests": {
                  "cpu": 1.0,
                  "memoryInGB": 1.5
                }
              }
            }
          }
        ],
        "osType": "Linux"
      }
    }
  ],
  "outputs": {
    "containerGroupFQDN": {
      "type": "string",
      "value": "[reference(resourceId('Microsoft.ContainerInstance/containerGroups', parameters('containerGroupName'))).ipAddress.fqdn]"
    }
  }
}

Key Notes for the Template:

  • The image field directly references your public Docker Registry image (e.g., your-docker-username/your-public-image:v1). No authentication is needed here because the repo is public.
  • If you’re using a private Docker Registry, you’ll need to add an imageRegistryCredentials section under properties to include your Docker username and password:
    "imageRegistryCredentials": [
      {
        "server": "docker.io",
        "username": "[parameters('dockerUsername')]",
        "password": "[parameters('dockerPassword')]"
      }
    ]
    
    Just add dockerUsername and dockerPassword as secure parameters to your template.

Extending to Other Azure Services

This logic applies to other Azure container services too:

  • AKS: In your deployment manifest (or ARM template for AKS deployments), specify the Docker image URL in the pod spec. For public images, no secrets are needed; for private, create a Kubernetes Secret with Docker credentials and reference it in the pod.
  • App Service Containers: In the ARM template for App Service, set the linuxFxVersion (for Linux) to DOCKER|your-docker-username/your-public-image:v1. For private repos, configure the dockerRegistryUrl, dockerRegistryUsername, and dockerRegistryPassword app settings.

内容的提问来源于stack exchange,提问作者explorer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:16:57