Loading controls...
Benchmark: Container Registry
Description
This benchmark provides a set of controls that detect Terraform Azure Container Registry resources deviating from security best practices.
Usage
Browse dashboards and select Container Registry:
steampipe dashboard
Or run the benchmarks in your terminal:
steampipe check terraform_azure_compliance.benchmark.containerregistry
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share terraform_azure_compliance.benchmark.containerregistry
Controls
- Azure Defender for container registries should be enabled
- Container registries should be encrypted with a customer-managed key
- Container registries should not allow unrestricted network access
- Container Registry should use a virtual network service endpoint