Evaluates whether each Container Registry instance has a namespace and an image repository created. If both exist, the instance is considered compliant.
Scenarios
Identify and manage idle Container Registry instances to optimize costs.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
-
If a namespace and an image repository are created for a Container Registry instance, the evaluation result is Compliant.
-
If no namespace or image repository is created for a Container Registry instance, the evaluation result is Non-compliant.
-
If a Container Registry instance was created within the specified number of days (default: 7), the evaluation result is Not Applicable.
Rule details
|
Item |
Description |
|
Rule name |
cr-instance-idle-check |
|
Rule ID |
|
|
Tag |
CR and Repository |
|
Automatic remediation |
Not supported |
|
Trigger type |
Configuration change |
|
Supported resource type |
Container Registry instance |
|
Input parameter |
allocateDays. Default value: 7, in days |
Non-compliance remediation
Create a namespace and an image repository for each Container Registry instance. For more information, see Configure access over the Internet.