Evaluates whether each image version in a Container Registry repository was updated within a specified number of days. If so, the result is Compliant. The default is 180 days.
Scenarios
To ensure business continuity, you must renew each subscription instance before it expires.
Risk level
Default risk level: medium.
You can change the risk level based on your business requirements.
Compliance evaluation logic
-
If each image version in a Container Registry repository was updated within the specified number of days, the evaluation result is Compliant. The default is 180 days.
-
If an image version in a Container Registry repository was not updated within the specified number of days, the evaluation result is Non-compliant.
Rule details
|
Item |
Description |
|
Rule name |
cr-repository-tag-expired-check |
|
Rule ID |
|
|
Tag |
CR and Repository |
|
Automatic remediation |
Not supported |
|
Trigger type |
Periodic execution |
|
Evaluation frequency |
Every 24 hours |
|
Supported resource type |
Container Registry repository |
|
Input parameter |
days. Default value: 180, in days |