Data-plane role built into Azure Container Registry that allows reading tags and pulling images. Assign it to whichever identity performs the pull.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AcrPull in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Azure Container Registry
Private Azure registry for container images. Images can be geo-replicated, cleaned up by retention policies and built by ACR Tasks, while webhooks let a push kick off continuous deployment.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- IDENTITY
A column property, written IDENTITY(seed, increment), that gives each new row the next number in a rising sequence. SCOPE_IDENTITY reports the latest value created in the current scope, and a rolled-back transaction still uses up the numbers it took.
Related terms
- --attach-acr
Option on
az aks createoraz aks updatethat links a container registry to an AKS cluster by assigning AcrPull to the kubelet identity, so nodes can pull its images. - AKS-ACR integration
Running az aks create or az aks update with --attach-acr grants AcrPull to a cluster's kubelet managed identity, letting nodes fetch images with no pull secrets. Registries using ABAC can't use this; grant Container Registry Repository Reader manually there.
- Container Registry Repository Reader
A role for ACR registries with ABAC enabled that allows pulling and reading images, tags and metadata across the registry or only for repositories picked by ABAC conditions. It plays the part of AcrPull in ABAC mode but can't list the catalogue.
- Image pull secret
A Kubernetes secret containing credentials for a registry, for example a service principal, used when pulling images. It is not needed if the kubelet identity holds AcrPull.
- Kubelet identity
AKS nodes pull container images using this user-assigned managed identity, so AcrPull on the registry must be granted to it rather than to the control plane identity.
- Role assignment permissions mode
An ACR registry option that picks between RBAC Registry Permissions, using the classic AcrPull and AcrPush roles, and RBAC Registry + ABAC Repository Permissions, which adds roles scoped to repositories with ABAC conditions.