Last Updated: 2025-04-01
Purpose
This article describes how to create access on Azure portal that can be configured in HIAB to discover and scan container images that resides in an Azure Container Registry.
Introduction
The Azure Portal is a single portal where applications can be accessed and managed in one place. Access on the Azure portal can be created so that it can be configured in HIAB to discover and scan container images that resides in an Azure Container Registry. The current implementation does not support the Microsoft Azure RBAC model, and instead requires the use of admin access as detailed in the Microsoft documentation. Steps include accessing the Azure portal to configure the container registry, enabling the admin user, and then setting up credentials in the HIAB portal. Finally, the document provides references to additional Microsoft documentation for further guidance on using the Azure container registry.
Requirements
The current implementation of discovering and scanning an Azure container registry does NOT yet support Microsoft Azure RBAC model as described in the following Microsoft documentation https://docs.microsoft.com/en-us/azure/container-registry/container-registry-roles.
The only supported method is to configure and use admin access in the container registry as described in Microsoft documentation: https://docs.microsoft.com/en-us/azure/container-registry/container-registry-authentication#admin-account
Configuring Azure Container Registry
To run Container Inspection on an Azure container registry, the Azure registry must be configured to provide access that later can be configured on the Outpost24 HIAB.
-
Enter Azure portal and open Container registries service.
-
Select the registry you want to enable Container Inspection for and click on it to open the specific registry information.
-
Click on the Access Keys entry in the Settings sub section to access the configuration and enable the Admin user to be reused later in the HIAB configuration.
-
Enable the Admin user by setting it to Enabled. This generates user/password access as follow:
Configuring HIAB
-
To configure Azure registry access, open HIAB Portal from the HIAB Main Menu, by clicking on Portal entry.
-
In the HIAB Portal, click on the green Account button with your initials in the top right corner to display the Account view.
-
Then click on the Credentials card to open the Credentials configuration page, which allows you to create new Docker Credentials.
-
Click on the green Add credentials button on the bottom right corner to open the Add credentials panel..
-
The Add Credentials panel allow you to create Docker credentials.
-
Fill the empty field with all information from Azure portal as follow:
Do not forget to add https:// in front of the Azure Login server field to obtain a valid URL
Scanning Azure Container Registries
The discovery and the scanning works as any other container inspection discovery or scanning. For example the discovery can be done as follows:
Reference
-
Microsoft documentation on Admin account for Azure container registry: https://docs.microsoft.com/en-us/azure/container-registry/container-registry-authentication#admin-account
-
Microsoft Quickstart guide for Azure container registry: https://docs.microsoft.com/en-us/azure/container-registry/container-registry-get-started-portal
Related Articles
- Docker Image Assessment
- How to Scan AWS ECR Images
- Generate Azure Credentials
- Container Inspection - Azure
- Import Cloud Image on AWS
- Google Cloud Platform Credentials
- Microsoft Azure Credentials
- Azure Cloud Discovery
- Docker Credentials
- Amazon
- Cloud Discovery
- Scan a Docker Image
- Configure Application Gateway for HIAB on Azure
- Amazon Web Services Credentials
- Change Hard Drive Size on HIAB in Amazon Web Services
- Change Instance Type on HIAB on Amazon Web Services
- Cloud Discovery on HIAB
- Generate AWS Credentials
- Extend HIAB Disk Space on Azure
- AWS Scanning with OUTSCAN
- Cloud Assessment
- Generate GCP Credentials
- Google Registries Scanning with Container Inspection
- Deploy HIAB on Amazon Web Services
- Cloudsec Scan Configuration
- Docker Image Discovery
- Importing Tags for AWS Discovery
- Deploy HIAB on Microsoft Azure
- Vulnerabilities