All Products
Search
Document Center

Cloud Config:cr-repository-tag-expired-check

Last Updated:Jun 23, 2026

Evaluates whether each image version in a Container Registry repository was updated within a specified number of days. If so, the result is Compliant. The default is 180 days.

Scenarios

To ensure business continuity, you must renew each subscription instance before it expires.

Risk level

Default risk level: medium.

You can change the risk level based on your business requirements.

Compliance evaluation logic

  • If each image version in a Container Registry repository was updated within the specified number of days, the evaluation result is Compliant. The default is 180 days.

  • If an image version in a Container Registry repository was not updated within the specified number of days, the evaluation result is Non-compliant.

Rule details

Item

Description

Rule name

cr-repository-tag-expired-check

Rule ID

cr-repository-tag-expired-check

Tag

CR and Repository

Automatic remediation

Not supported

Trigger type

Periodic execution

Evaluation frequency

Every 24 hours

Supported resource type

Container Registry repository

Input parameter

days. Default value: 180, in days