Enterprise-Scale icon indicating copy to clipboard operation
Enterprise-Scale copied to clipboard

Bug Report: Policy initiative defines unused and unneeded zoneId for Azure Container Registry

Open juanandmsft opened this issue 7 months ago • 1 comments

Describe the bug The ESLZ policy initiative defines "azureAcrDataPrivateDnsZoneId": "{regionName}.data.privatelink.azurecr.io" in the "dnsZoneNames" parameter, but then is not used.

In fact is not needed, because the zone "{regionName}.data.privatelink.azurecr.io" is a subzone of "privatelink.azurecr.io" already addressed properly by "azureAcrPrivateDnsZoneId".

Steps to reproduce

  1. Create ACR with private Endpoint
  2. The PE contains both entries for "privatelink.azurecr.io" and "{regionName}.data.privatelink.azurecr.io", just with "azureAcrPrivateDnsZoneId", without "azureAcrDataPrivateDnsZoneId".

Screenshots

Image

juanandmsft avatar Jun 29 '25 07:06 juanandmsft

@juanandmsft will add to the backlog.

Springstone avatar Jul 03 '25 09:07 Springstone