Signed-image push and pull on Premium ACR, based on Notary v1. It has been deprecated since 31 March 2025, can't be turned on for new registries after 31 May 2026, and goes away on 31 March 2028.
Also called DCT, Content trust.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Docker Content Trust in context, with comparison tables and the common traps.
Terms in this definition
- Real-time streaming semantic model
Covers live-fed push, streaming and PubNub models, plus streaming dashboard tiles. Microsoft now steers people towards Real-Time Intelligence in Fabric, as these are being retired and new ones can only be made until 31 October 2027.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
- Azure Container Registry
Private Azure registry for container images. Images can be geo-replicated, cleaned up by retention policies and built by ACR Tasks, while webhooks let a push kick off continuous deployment.
- Notary v1
The signing approach underlying Docker Content Trust; Azure Container Registry has replaced it with Notary Project signing.
Related terms
- Azure Container Registry SKUs
Azure Container Registry comes in Basic, Standard and Premium. Every tier includes ACR Tasks and the admin user; private endpoints, content trust, connected registries and dedicated data endpoints are Premium-only.
- Notary Project
Set of cross-industry specifications and tools for signing OCI artifacts and verifying signatures. Azure Container Registry uses it in place of Docker Content Trust.