Container image store (container registry): what it is and how it is attacked
The library of packaged applications that machines fetch from whenever they start something.
Also known as
- container registry
- image registry
- ECR
- ACR
- artefact store
Typing any of them into the editor finds this object.
Why it matters on a security diagram
Everything in it is trusted and run automatically, so changing what it holds changes what runs everywhere, without touching a single server.
How it gets attacked, and what reduces it
How it gets attacked
- Permission to publish held far more widely than the few systems that actually publish
- A label reused, so the same name quietly begins to mean different contents
- Packages pulled from outside stores with no check on who produced them
What reduces it
- Restrict publish rights to the pipeline, not to people
- Refer to images by their content rather than by a label that can be moved
- Verify the publisher of anything pulled from outside
Where it sits
- Group
- Cloud and subscribed services · Things that only exist because somebody else runs the platform underneath them.
- Whose side, by default
- Ours · Belongs to the organisation the diagram is about.
- Catalogue identifier
- container-registry
Reviewed . CC BY 4.0.
Others in cloud and subscribed services
- Cloud platformAWS · Azure · GCP · Google Cloud · public cloud · hyperscaler · IaaSA supplier's computing platform, rented by the hour, where a setting made on a website creates or removes a whole system.
- AI model endpointLLM API · inference endpoint · model service · AI serviceWhere an application sends a question, along with documents, images or data, to an AI model and gets an answer back.
- Cloud accountsubscription · project · AWS account · Azure subscription · Google Cloud project · cloud environmentOne named compartment of a cloud platform, with its own bill and its own list of who may change what.
- Cloud account groupmanagement group · AWS Organizations · GCP folder · landing zone · account structureThe parent that owns all of an organisation's cloud accounts and can set rules over every one of them.
- Cloud control panelcontrol plane · management console · cloud portal · cloud API · management planeThe website and commands used to configure the cloud itself, as opposed to the systems running inside it.
- Supplier-run applicationSaaS · software as a service · cloud application · business applicationAn application a supplier runs entirely, which the organisation subscribes to and puts its data into.
- Connected appOAuth application · app registration · enterprise application · app consent · add-inAn outside program that somebody has allowed to reach company data on their behalf.
- Managed databaseRDS · Azure SQL · Cloud SQL · database as a service · DBaaSA database the cloud provider runs, where the data and the settings are yours but the machine is never touched.
- On-demand functionserverless · Lambda · Azure Functions · Cloud Run · FaaSA small piece of code that runs only when something asks for it, with no server to look after.
- Container platformKubernetes · K8s · cluster · EKS · AKS · GKE · OpenShiftThe system that decides where each packaged application runs, and starts it again when it stops.
- Infrastructure blueprintinfrastructure as code · IaC · Terraform · state file · CloudFormation · BicepThe written description of what the cloud should contain, together with the record of what was actually built.
The cloud and subscribed services group lists all 12 of them side by side.
Container image store on your own diagram
Open the editor, press N, and type container registry. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker