DevOps Classroom notes 28/Sep/2026

Azure container registry

  1. it will supourt multiple image and tags in single repos
  2. path base storage images

steps to create Container registries

  1. need resource group
  2. cerate Registry with name required number+alpha
  3. registry domain is automatcally created with registry name + .azurecr.io
  4. note:Private access (Recommended) is only available for Premium pricing plans.
  5. review and create

To access Container registries

  1. azure cli and docker need to install
  2. need to create service-principal
  3. need provide access to service-principal (RBAC)- attach role
  4. MSYS_NO_PATHCONV=1 add this to fix sytax issue for azurecli cmds

Azure Service Principal with Contributor Role

Overview

An Azure Service Principal is an identity used by applications, automation tools, CI/CD pipelines, scripts, and services to authenticate with Azure without using a personal user account.

Note (Git Bash / MINGW64 users): Git Bash auto-converts any string starting with / (like /subscriptions/...) into a Windows filesystem path, which breaks commands using scopes. Prefix such commands with MSYS_NO_PATHCONV=1 to disable this behavior. This is already added to the relevant commands below.

In this example, we will:

  1. Create an Azure Service Principal.
  2. Assign the Contributor role.
  3. Get the required credentials.
  4. Log in to Azure CLI using the Service Principal.
  5. Verify the login and permissions.

Prerequisites

Make sure you have:

  • An Azure subscription.
  • Azure CLI installed.
  • Permission to create service principals and assign roles.

Check Azure CLI:

az version

Log in to Azure using your normal Azure account first:

az login

Check your subscriptions:

az account list --output table

Set the subscription you want to use:

az account set --subscription "<SUBSCRIPTION_ID>"

Verify the current subscription:

az account show --output table

Step 1: Create a Service Principal

Run the following command:

MSYS_NO_PATHCONV=1 az ad sp create-for-rbac \
  --name "my-demo-service-principal" \
  --role "Contributor" \
  --scopes "/subscriptions/<SUBSCRIPTION_ID>"

Replace:

<SUBSCRIPTION_ID>

with your Azure subscription ID.

Example

MSYS_NO_PATHCONV=1 az ad sp create-for-rbac \
  --name "my-demo-service-principal" \
  --role "Contributor" \
  --scopes "/subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"

The command returns JSON similar to:

{
  "appId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
  "displayName": "my-demo-service-principal",
  "password": "xxxxxxxxxxxxxxxxxxxxxxxx",
  "tenant": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
}

Important: The password (client secret) is sensitive. Save it securely. Azure does not display the same secret again after creation.


Step 2: Understand the Service Principal Credentials

The output contains the values required for Azure CLI authentication:

Value Meaning
appId Client ID / Application ID
password Client secret
tenant Microsoft Entra tenant ID
Subscription ID Azure subscription where the role is assigned

You can use these values with:

az login --service-principal \
  --username "<APP_ID>" \
  --password "<CLIENT_SECRET>" \
  --tenant "<TENANT_ID>"

Step 3: Assign the Contributor Role

If you did not assign the role while creating the Service Principal, you can assign it separately.

First get the Service Principal object ID:

az ad sp list \
  --display-name "my-demo-service-principal" \
  --query "[0].id" \
  --output tsv

Store the returned object ID.

Then assign the Contributor role:

MSYS_NO_PATHCONV=1 az role assignment create \
  --assignee-object-id "<SERVICE_PRINCIPAL_OBJECT_ID>" \
  --assignee-principal-type ServicePrincipal \
  --role "Contributor" \
  --scope "/subscriptions/<SUBSCRIPTION_ID>"

Verify the Role Assignment

MSYS_NO_PATHCONV=1 az role assignment list \
  --assignee "<APP_ID>" \
  --scope "/subscriptions/<SUBSCRIPTION_ID>" \
  --output table

You should see:

Role          Scope
------------  -----------------------------------------------
Contributor   /subscriptions/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

Step 4: Login to Azure CLI Using the Service Principal

Log out of the current Azure CLI session:

az logout

Now log in using the Service Principal:

az login --service-principal \
  --username "<APP_ID>" \
  --password "<CLIENT_SECRET>" \
  --tenant "<TENANT_ID>"

Example:

az login --service-principal \
  --username "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" \
  --password "YOUR_CLIENT_SECRET" \
  --tenant "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"

Step 5: Verify the Azure CLI Login

Check the currently logged-in account:

az account show --output table

You can also check the subscription:

az account show \
  --query "{Subscription:name, SubscriptionId:id, TenantId:tenantId}" \
  --output table

Step 6: Test Contributor Permissions

For example, list resource groups:

az group list --output table

You can also test resource creation if you have a suitable test resource group.

For example:

az group create \
  --name "sp-demo-rg" \
  --location "eastus"

If the Service Principal has Contributor access at the subscription scope, it can manage resources within that subscription.


Role Scope

The Contributor role can be assigned at different scopes.

Subscription Scope

--scope "/subscriptions/<SUBSCRIPTION_ID>"

This gives Contributor access across the subscription.

Resource Group Scope

--scope "/subscriptions/<SUBSCRIPTION_ID>/resourceGroups/<RESOURCE_GROUP_NAME>"

This limits access to a specific resource group.

Resource Scope

You can also assign a role to an individual resource:

--scope "/subscriptions/<SUBSCRIPTION_ID>/resourceGroups/<RESOURCE_GROUP_NAME>/providers/<RESOURCE_PROVIDER>/<RESOURCE_TYPE>/<RESOURCE_NAME>"

Using the smallest required scope is generally preferable for automation.

On Git Bash, prefix any command using a --scope or --scopes value with MSYS_NO_PATHCONV=1 to prevent path mangling.


Complete Example

1. Login

az login

2. Select Subscription

az account set --subscription "<SUBSCRIPTION_ID>"

3. Create Service Principal + Contributor Role

MSYS_NO_PATHCONV=1 az ad sp create-for-rbac \
  --name "my-demo-service-principal" \
  --role "Contributor" \
  --scopes "/subscriptions/<SUBSCRIPTION_ID>"

4. Logout

az logout

5. Login Using Service Principal

az login --service-principal \
  --username "<APP_ID>" \
  --password "<CLIENT_SECRET>" \
  --tenant "<TENANT_ID>"

6. Verify

az account show --output table

7. Test

az group list --output table

Environment Variables

For scripts and CI/CD pipelines, you can store the credentials in environment variables instead of putting them directly into commands.

Linux / macOS

export AZURE_CLIENT_ID="<APP_ID>"
export AZURE_CLIENT_SECRET="<CLIENT_SECRET>"
export AZURE_TENANT_ID="<TENANT_ID>"
export AZURE_SUBSCRIPTION_ID="<SUBSCRIPTION_ID>"

Then:

az login \
  --service-principal \
  --username "$AZURE_CLIENT_ID" \
  --password "$AZURE_CLIENT_SECRET" \
  --tenant "$AZURE_TENANT_ID"

Windows PowerShell

$env:AZURE_CLIENT_ID="<APP_ID>"
$env:AZURE_CLIENT_SECRET="<CLIENT_SECRET>"
$env:AZURE_TENANT_ID="<TENANT_ID>"
$env:AZURE_SUBSCRIPTION_ID="<SUBSCRIPTION_ID>"

Then:

az login `
  --service-principal `
  --username $env:AZURE_CLIENT_ID `
  --password $env:AZURE_CLIENT_SECRET `
  --tenant $env:AZURE_TENANT_ID

Note: PowerShell does not have the Git Bash path-mangling issue, so MSYS_NO_PATHCONV=1 is not needed there.


Important Security Notes

  • Do not commit the Service Principal secret to Git.
  • Do not put the client secret directly into source code.
  • Do not share the client secret in screenshots or chat.
  • Store secrets in a secure secret-management system.
  • Use the smallest practical RBAC scope.
  • For Azure-hosted workloads, consider using Managed Identity instead of a client secret where possible.
  • Rotate or remove credentials that are no longer required.

Useful Commands

List Service Principals

az ad sp list --all --output table

Find a Service Principal

az ad sp list \
  --display-name "my-demo-service-principal" \
  --output table

List Role Assignments

az role assignment list \
  --assignee "<APP_ID>" \
  --output table

Remove the Role Assignment

MSYS_NO_PATHCONV=1 az role assignment delete \
  --assignee "<APP_ID>" \
  --role "Contributor" \
  --scope "/subscriptions/<SUBSCRIPTION_ID>"

Delete the Service Principal

az ad sp delete --id "<APP_ID>"

Summary

The main workflow is:

Azure Account
     |
     v
az login
     |
     v
Create Service Principal
     |
     v
Assign Contributor Role
     |
     v
Get App ID + Client Secret + Tenant ID
     |
     v
az logout
     |
     v
az login --service-principal
     |
     v
Verify Azure Subscription

The key login command is:

az login --service-principal \
  --username "<APP_ID>" \
  --password "<CLIENT_SECRET>" \
  --tenant "<TENANT_ID>"

Reminder: On Git Bash (MINGW64), any command with a --scope/--scopes value starting with /subscriptions/... needs the MSYS_NO_PATHCONV=1 prefix to avoid the path being rewritten to a Windows filesystem path.

install azure-cli

curl -fsSL 'https://azurecliprod.blob.core.windows.net/$root/deb_install.sh' | sudo bash

step to login

az login
az acr login --name qt2205

Task

  1. create sp and assign role sp in azure
  2. create container registry
  3. az login with sp & login to docker registry
  4. pull sample images like httpd, nginx, alpine and push to acr

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please turn AdBlock off
Social Media Icons Powered by Acurax Web Design Company

Discover more from Direct DevOps from Quality Thought

Subscribe now to keep reading and get access to the full archive.

Continue reading

Exit mobile version
%%footer%%